Ransomware victim disclosure
← All victimsNFM Lending
Claimed by Interlock · listed 6 days ago
Status timeline
- ListedSep 7, 2026
- Data leakeddate unknown
At a glance
- Group
- Interlock
- Status
- Data leaked
- Country
- United States
- Sector
- Financial Services
- Listed on leak site
- Sep 7, 2026
About the victim
AI dossier — public-source company profileNFM Lending is a national mortgage lender that originated approximately $7.15 billion in mortgages over a 12-month period, serving over 1 million clients through its Encompass loan origination platform.
- Industry
- Mortgage Lending
- Employees
- 1000
Attack summary
Severity: critical — Confirmed large-scale exfiltration of highly regulated financial PII (SSNs, bank accounts, credit data) affecting 1M+ customers; violation of GLBA/FCRA; exposure of proprietary business data and employee records; data size (2.5 TB) and scope indicate systematic access to core lending infrastructure.The interlock group claims to have exfiltrated over 2.5 TB of sensitive data including customer PII (names, Social Security numbers, bank accounts, credit information, addresses, contact details), loan details, proprietary pricing and profit formulas, tax records, and employee personal information from NFM Lending and its Encompass database.
Data the group says was taken
AI dossier — extracted from the leak post- Customer names and Social Security numbers
- Bank account information
- Credit information and loan terms
- Customer addresses and contact details
- Borrower and loan identifiers
- Loan pricing data
- Itemized loan expense reports
- Proprietary pricing and profit formulas
- Encompass database records (1M+ clients)
- Tax forms database
- Employee personal information
What the group claims
NFM Lending is a national mortgage lender with over 1,000 employees that originated approximately $7.15 billion in mortgages in the past 12 months. The data breach exposed over 2.5 TB of sensitive personal customer information (names, Social Security numbers, bank accounts, credit information, loan terms, addresses, phone numbers, email addresses, borrower and loan identifiers, loan pricing, and itemized loan expense reports), as well as proprietary pricing/profit formulas, in violation of federal GLBA/FCRA, state privacy laws, and the CFPB's data breach reporting rules. You also have access to data from the Encompass database, which contains information on more than 1 million clients, as well as internal databases, an extensive database of tax forms, and employees' personal information.
Sources
Source
Indexed 6 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

