Key facts
- Ransomware group Interlock claims to have obtained over 2.5 terabytes of data from NFM Lending.
- The alleged breach occurred around September 7, 2026.
- A proposed class-action lawsuit was filed against NFM Lending by Sheneka Smith on September 16.
- The lawsuit alleges NFM Lending failed to implement adequate cybersecurity safeguards and employee training.
- NFM Lending had not notified customers of the incident as of the lawsuit's filing date.
- The lawsuit seeks damages, restitution, injunctive relief, and attorneys' fees.
The ransomware group Interlock has claimed responsibility for a data breach at NFM Lending, alleging the theft of more than 2.5 terabytes of sensitive information around September 7, 2026. The stolen data reportedly includes customer Social Security numbers, financial account information, and employee personal information.
Following the alleged breach, a proposed class-action lawsuit was filed against NFM Lending on September 16 in the U.S. District Court for the District of Maryland by Sheneka Smith. The lawsuit, reviewed by HousingWire, asserts that NFM Lending failed to implement adequate cybersecurity safeguards and provide sufficient training to its employees, which allegedly allowed cybercriminals to access the company's systems.
As of the filing date, NFM Lending had not publicly confirmed the scope of the breach or notified affected customers, leaving them without the opportunity to take protective measures such as freezing their credit. Smith, the plaintiff, is seeking damages, restitution, injunctive relief, and attorneys' fees, citing negligence, breach of implied contract, unjust enrichment, and violations of the Maryland Consumer Protection Act.
