Back to homepage

California DFPI orders mortgage company to pay $825K for alleged cybersecurity failures preceding ransomware attack

August 21, 2026

On August 13, the California DFPI announced a consent order requiring a Utah-based mortgage company to pay $825,000 for allegedly failing to adequately protect the personal information of more than 284,000 individuals, including over 34,000 California residents. According to the consent order, a threat actor breached the company’s network in March 2023, installed malware, stole employee credentials, and used them to disable network security systems before initiating a ransomware attack.

Following an examination, the DFPI found that the company had cybersecurity, governance and recordkeeping deficiencies that predated the attack. Specifically, the DFPI said it identified: (i) inadequate information security risk assessments from 2021 through 2023; (ii) a failure to conduct a full formal audit between 2017 and 2023; (iii) deficient vulnerability and patch management practices, deficient access controls, a lack of a comprehensive asset inventory, and an apparent failure to document correction of deficiencies identified through penetration testing; and (iv) deficiencies in board of directors-level oversight and planning. The examination also found that the company did not obtain a written forensic report documenting the breach’s root cause, contributing factors, or remediation measures. DFPI concluded that the company: (i) failed to comply with information-security requirements under the GLBA, and its implementing Safeguards Rule, and California Civil Code section 1798.100(e); (ii) failed to exercise due care and competence in performing licensed activities; and (iii) failed to maintain records sufficient for the DFPI to assess compliance with the California Residential Mortgage Lending Act.

Under the consent order, which the company entered without admitting or denying the DFPI’s findings, the company must pay an $825,000 administrative penalty and provide all affected California borrowers with 12 months of free identity theft insurance coverage. The order also requires the company to immediately correct its recordkeeping obligations and cease unsafe and injurious cybersecurity practices.