Skip to main content

Cyberattacks On Mortgage Servicers And Lenders Continue To Rise: Expert Offers Solutions

Jan 09, 2024
cybersecurity
News Director

Financial services companies grappling with growing cyber threats seek backup loss mitigation and enhanced security measures, says industry expert.

The number of mortgage servicers and lenders who have been the target of cyberattacks seems to be growing by the day and while there’s no indication as to why they have a target on their backs one expert is offering some advice. 

Donna Schmidt, a default servicing expert and founder of WaterfallCalc, said it’s clear that the hackers are winning and forcing these companies to shut down their services in order to address the issues.

In recent weeks, three financial services companies — First American, Fidelity National Financial, and Mr. Cooper — have each disclosed separate incidents involving cybersecurity breaches and ransomware attacks. All three companies have notified government authorities and impacted parties.

“The mortgage industry is ripe,” Schmidt said.

She said mortgage servicers are in dire need of backup loss mitigation. She suggested two property preservation companies and better vendor control.

“Servicers that establish a backup loss mitigation service provider can more easily and swiftly move their loss mitigation activities to another platform when their primary provider is attacked,” Schmidt said.

The data breaches have exposed gaping vulnerabilities among residential loan servicers when their own system or a third-party vendor’s system is under attack, said Schmidt.

“There is no reason why loss mitigation activities cannot continue unobstructed even when a servicer or one of their partners encounters a serious data breach,” she added.

In each of the recent breaches the companies were forced to shut down some of their services in order to figure out how the breach happened and what - if any - information was taken. As a result, many lost business.

Schmidt said companies need to focus on their security as much as their finances, while increasing their redundancy and training practices.

Remote work presents an additional challenge to training, but in most instances these breaches happen because someone opens an email and clicks on a link, she added. However, the public is becoming aware of these incidents much more quickly than in the past.

The SEC’s new rules for public companies’ cybersecurity disclosures, effective as of Sept. 5, 2023, include “a requirement to disclose material cybersecurity incidents four business days after a public company determines the incident is material and a requirement to annually disclose information regarding cybersecurity risk management, strategy, and governance,” according to the SEC’s website.

About the author
Christine Stuart is the news director at NMP.
Published
Jan 09, 2024
U.S. Private Sector Adds 192,000 Jobs In April

Annual pay for people changing jobs fell from last month's 10.1% to 9.3%

May 02, 2024
BMO Will Issue 15 Grants To Women-Owned Businesses

Entrepreneurs invited to share their business growth plans that involve new hires, offering new products and services or expanding to new markets.

May 02, 2024
Redfin: Median Monthly Payments Reach $2,890 In April

Rising home prices and mortgage rates pushed monthly payments up 15% last month, year over year.

May 02, 2024
ARM Applications At Year's Highest So Far, As Rates Fail To Budge

Weekly survey from Mortgage Bankers Association shows decrease in purchase and refinance applications.

May 01, 2024
Home Price Appreciation Accelerates In February

The latest CoreLogic S&P Case-Schiller Index shows home prices remain resilient amid higher borrowing costs.

May 01, 2024
Consumer Confidence Drops To Lowest Level Since 2022

The consumer confidence index fell to 97 in April from March’s 103.1 reading.

Apr 30, 2024