Ransomware victim disclosure
← All victimsFinance of America Companies Inc.
Claimed by worldleaks · listed 2 months ago
Status timeline
- Listed
Mar 20, 2026
- Data leaked
At a glance
- Group
- worldleaks
- Status
- Data leaked
- Country
- United States
- Sector
- Financial Services
- Listed on leak site
- Mar 20, 2026
About the victim
AI dossier — public-source company profileFinance of America Companies Inc. is a publicly traded, end-to-end lending and financial services platform headquartered in the United States. The company operates across multiple brands offering reverse mortgages, retail lending, commercial real estate financing, and fixed income asset management. It is recognized as a top reverse mortgage lender and serves clients through a national network of offices and online platforms.
- Industry
- Mortgage Lending & Financial Services
Attack summary
Severity: critical — Finance of America is a large financial services and mortgage lending firm handling regulated consumer financial data (PII, loan applications, mortgage records) at scale. The disclosed status is 'data_published', indicating confirmed exfiltration and public release of likely highly sensitive regulated financial and personal data.The worldleaks group claims to have exfiltrated data from Finance of America Companies Inc. and has published the data; no ransom amount was stated and no specific data volume was disclosed.
Data the group says was taken
AI dossier — extracted from the leak post- Financial records
- Lending and mortgage data
- Customer PII
- Internal business documents
Original description
AI-summarised, not from the leak postFinance of America Companies Inc. is an end-to-end lending and services platform operating in the United States. The company offers a wide range of financial products across various brands, focusing on fixed income asset management, commercial real estate, reverse mortgages, and retail lending. It serves clients through online platforms and its extensive national network of offices.
Sources
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
