FHA Enacts New Cybersecurity Reporting Requirements – NMP Skip to main content

FHA Enacts New Cybersecurity Reporting Requirements

May 29, 2024
cybesecurity
Associate Editor

FHA mortgagees experiencing a potential or actual cyberattack must notify HUD within 12 hours.

The Federal Housing Administration (FHA) recently published new Cybersecurity Incident Reporting Requirements, significantly enhancing reporting regime for incidents of cyber breaches. According to its Mortgagee Letter (ML) 2024-10, published May 23, FHA-approved mortgagees are to notify the Department of Housing and Urban Development’s (HUD) within 12 hours of detecting a cyber incident. 

The new section detailing a Significant Cybersecurity Incident (V.A.2.b.viii), states FHA-approved mortgagees that experience a potential or actual cyber incident must notify HUD via the FHA Resource Center and HUD’s Security Operations Center within 12 hours of detection with required information as outlined in the ML. Once notified of an incident, representatives from HUD will contact the designated representative from the institution reporting the incident to determine the appropriate mitigation steps.

The requirements, which are effective immediately, are part of HUD’s commitment to the security and integrity of all its systems and technology supporting FHA operations.

Mortgage servicers have increasingly been targeted for cyberattacks, causing borrowers' personal information to be compromised. In late 2023 and early 2024, four major mortgage servicers, Mr. Cooper Group, Fidelity National Financial, First American Financial and loanDepot, were targeted in cyberattacks. Other than having consumer and corporate data compromised, the attacks delayed closing times on new loans and prevented customers from making payments.

The breaches have also led to a number of class action lawsuits against lenders that are being scrutinized for how those data breaches were handled. loanDepot Inc. is facing a class action lawsuit alleging its “willful failure” to prevent a data breach. Mr. Cooper Group also faces a class action lawsuit after suffering a major data breach, and is accused of failing to implement safeguards and not being timely and transparent in communicating with customers. 

About the author
Associate Editor
Katie Jensen is a mortgage news reporter at NMP.
Published
May 29, 2024
Jobs Report Comes In Weak After Mortgage Rates Surge

Employers added just 29,000 jobs in September, sending Treasury yields lower and offering a potential counterweight to the recent rise in mortgage rates

Oct 02, 2026
Price Cuts Hit Four-Year High As Mortgage Rates Top 7%

More than one in five listings took a price cut in September, but pending sales still posted their sharpest annual decline since March 2025

Oct 01, 2026
Serious Mortgage Delinquencies Rise 19% After Five Months Of Improvement

ICE data shows 574,000 mortgages were at least 90 days past due in August, while early-stage delinquencies remained below year-ago levels

Sep 29, 2026
Smaller Down Payments Give Buyers More Room, But Rates Limit The Savings

The typical down payment fell 9% from a year ago, while shifting market conditions are giving originators different affordability conversations across the country

Sep 25, 2026
Mortgage Rates Break 7% Just As Builders Find A Way To Move Buyers

New-home sales rose 6.4% in August as builders cut prices, offered incentives, and sold more lower-priced homes. Now mortgage rates are moving against buyers again

Sep 25, 2026
Borrowers Want Digital Closings, But Some Originators Remain Hesitant

ServiceLink finds 45% of surveyed LOs cite borrower reluctance as a barrier, even though most recent buyers say digital options would influence their choice of mortgage provider

Sep 23, 2026