loanDepot Faces Class Actions Over Cybersecurity Breach – NMP Skip to main content

loanDepot Faces Class Actions Over Cybersecurity Breach

Jan 26, 2024
court and gavel
News Director

Lawsuits allege failure to prevent data breach and seek class status, while customers worry about potential misuse of stolen information.

The California-based mortgage lender loanDepot is facing at least two class actions for a cybersecurity incident that impacted 16.6 million customers

The first lawsuit was filed Jan. 19 by Daroya Isaiah of Adelanto, California. It says since the data breach, she has "experienced a significant increase in SPAM phone calls or text messages; and noticed strange information or
accounts on her credit report, which plaintiff believes could be attributed to the data breach." 

In the lawsuit filed earlier this week in federal court in California, plaintiff Jonathan Rosas of Passaic County, New Jersey applied for and obtained a loan from loanDepot during the summer of 2021. 

loanDepot does not comment on pending litigation-- however, it has said it is offering credit monitoring and identity protection services to affected customers.

Both lawsuits are seeking class status and point to another cyberattack in August 2022 that loanDepot didn't disclose until May 2023. 

The lawsuits claim loanDepot failed to "prevent the data breach," in the first place. 

"loanDepot has not yet shared what type of customer personal information was accessed and stolen from its systems," one of the complaints states. 

The risk for customers of having their personally identifiable information (PII) stolen is that "hackers can sell the PII to other thieves or misuse themselves to commit a variety of crimes that harm victims of the Data Breach," the complaint states. "For instance, they can take out loans, mortgage property, open financial accounts, and open credit cards in a victim’s name; use a victim’s information to obtain government benefits or file fraudulent returns to obtain a tax refund; obtain a driver’s license or identification card in a victim’s name; gain employment in another person’s name; or give false information to police during an arrest."

The complaint cites loanDepot's security policy which says "loanDepot takes steps to safeguard your personal and sensitive information through industry standard physical, electronic, and operational policies and practices. All data that is considered highly confidential data can only be read or written through defined service access points, the use of which is password protected."

The cyber incident was only the latest in a series of attacks on financial institutions. Several notable mortgage industry companies have faced cyberattacks in recent months, underscoring the growing cybersecurity challenges in the financial sector. The cyberattack of loanDepot follows recent breaches at First AmericanFidelity National Financial, and Mr. Cooper Group.

About the author
Christine Stuart is the news director at NMP.
Published
Jan 26, 2024
More from
Courts
AI Errors Leave Mortgage Trustee Without Brief In Foreclosure Appeal

Outside counsel’s fabricated citations expose a third-party oversight risk for mortgage servicers, trustees, and investors

Sep 10, 2026
Garg Pitches $2 Billion Better Turnaround; Board Calls Plan ‘Unworkable’

Former CEO targets zero monthly cash burn through higher mortgage volume, AI-driven operating changes, and $2 million in monthly savings

Sep 04, 2026
UWM’s $603 Million Hedge Loss Has Drawn Three Shareholder Lawsuits — So Far

One securities class action challenges UWM’s disclosures, while two newer stockholder suits target board oversight of the $27.5 billion derivatives position

Sep 03, 2026
Rocket Adds New Broker Allegations, Refinance Data To UWM Lawsuit

Amended complaint adds a named broker, new loan-level figures and a claim that damages have climbed to at least $100 million

Sep 01, 2026
Better’s $15 Million Offer To Garg Complicates Its Case Against Him

The mortgage lender portrayed its founder as unfit to lead, but Garg says it offered him a lucrative advisory role three days after firing him

Aug 26, 2026
Veterans United Fails To Knock Out Core RESPA Theory

The latest court order represents a significant 'mixed bag' for both sides

Aug 24, 2026