Skip to content
Weekly Real Estate News
Mortgage Information

NFM Lending Faces Multiple Federal Lawsuits Following Alleged Ransomware Data Breach

NFM Lending faces multiple federal lawsuits following an alleged ransomware incident. Court records confirm the litigation, while claims that more than 2.5 terabytes of data were stolen remain unverified. Continue Reading NFM Lending Faces Multiple Federal Lawsuits Following Alleged Ransomware Data Breach

Padlock on a computer keyboard representing the alleged NFM Lending ransomware incident and federal lawsuits

Share this article!

NFM Lending is facing a growing series of federal lawsuits following allegations that the mortgage lender was targeted in a ransomware incident that may have exposed sensitive borrower information.

At least five lawsuits were filed against NFM Lending LLC in the U.S. District Court for the District of Maryland between Sept. 11 and Sept. 17, according to federal docket records. The cases include actions brought by Joshua Koppenhaver, Denise Romancik, Karen Clark, Sheneka Smith and Raymond Richardson.

The complaints follow a Sept. 7 claim by the Interlock ransomware group that it compromised NFM Lending and obtained more than 2.5 terabytes of data. That claim has not been independently verified, and NFM Lending had not publicly confirmed the scope of the alleged incident in the sources reviewed by WRE News.

Cybersecurity researchers tracking ransomware activity have reported that Interlock listed NFM Lending on its leak site and claimed the material included customer names, Social Security numbers, banking and credit information, loan information, addresses and other records. Those descriptions originate with the ransomware group’s assertions and should not be treated as confirmed descriptions of information actually taken from NFM’s systems.

Federal lawsuits begin to accumulate

Federal court records confirm that Smith v. NFM Lending LLC, case No. 1:26-cv-03661, was filed Sept. 16 in the District of Maryland. The complaint alleges that NFM failed to adequately protect customers’ private information and seeks to represent people whose information was allegedly exposed.

The Smith complaint asserts claims including negligence, breach of implied contract, unjust enrichment and violations of Maryland consumer-protection law. Those allegations have not been adjudicated, and the filing of a complaint does not establish liability.

Separate docket records show Romancik v. NFM Lending LLC, No. 1:26-cv-03627, and Clark v. NFM Lending LLC, No. 1:26-cv-03632, were filed Sept. 14. Richardson v. NFM Lending LLC, No. 1:26-cv-03677, was filed Sept. 17. A fifth action, Koppenhaver v. NFM Lending LLC, was filed Sept. 11.

The cases remain at an early stage. WRE News found no court determination establishing that NFM was negligent, that the alleged ransomware incident occurred as Interlock describes it, or that the ransomware group’s claimed 2.5-terabyte figure is accurate.

Why the allegations matter to mortgage lenders

Mortgage companies routinely handle information that can include Social Security numbers, income documentation, bank records, credit information, tax documents and detailed property and loan data. That makes cybersecurity and data protection a significant operational and compliance issue for the industry.

NFM Lending is a Maryland-based residential mortgage lender. Public HUD records identify the company as an FHA-approved mortgage lender.

The distinction between what is confirmed and what is alleged remains important. The federal lawsuits are confirmed through court docket records. Interlock’s claim that it compromised NFM and obtained more than 2.5 terabytes of information is also publicly documented as a claim by the ransomware group. The accuracy and scope of that claim have not been independently established.

WRE News will update this report if NFM Lending, regulators or the federal courts provide material new information about the incident or litigation.

Sources: U.S. District Court for the District of Maryland docket records; HUD lender records; cybersecurity threat-intelligence reporting. Allegations contained in complaints and ransomware-group statements have not been established as fact.

Photo: Towfiqu barbhuiya/Unsplash.

WRE NEWS  •  READER SUPPORT
Help support the news that keeps you ahead.
If WRE News brings value to your day, consider supporting the reporting that keeps our industry informed.

Submit a Comment

Your email address will not be published. Required fields are marked *