NFM LENDING, LLC
ent_019fcc448eb9d808dc3e6cc2eeac5c29
Disclosures
4
Leak Site · State AG · 4 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
249
as filed · State AG MA
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- NFM LENDING, LLC
- Normalized
- nfm lending— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 254900KZW4PBV58BWL39
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- GLOBALLeak Siteas victim2026-09-07
NFM Lending is a national mortgage lender with over 1,000 employees that originated approximately $7.15 billion in mortgages in the past 12 months. The data breach exposed over 2.5 TB of sensitive personal customer information (names, Social Security numbers, bank accounts, credit information, loan terms, addresses, phone numbers, email addresses, borrower and loan identifiers, loan pricing, and itemized loan expense reports), as well as proprietary pricing/profit formulas, in violation of federal GLBA/FCRA, state privacy laws, and the CFPB's data breach reporting rules. You also have access to data from the Encompass database, which contains information on more than 1 million clients, as well as internal databases, an extensive database of tax forms, and employees' personal information.
- Indiana State AGas victim2023-03-28
NFM Lending reported a data breach to the Indiana Attorney General. 1 Indiana residents were affected. 13 individuals affected in total.
- Massachusetts State AGas victim2018-12-17
NFM Lending reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2018-12-17. 249 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2018-12-17
NFM Lending notified the NH Attorney General of a data breach affecting 15 NH residents. Unauthorized individuals accessed the email accounts of seven employees between late May and early August 2018, potentially exposing customer names and Social Security numbers. NFM discovered the access in early August 2018, secured accounts, and notified law enforcement. Affected individuals received 24 months of credit monitoring and identity theft protection.