Ransomware victim disclosure
← All victimsintelliloan.com
Claimed by lockbit3 · listed 1 year ago
Status timeline
- Listed
Apr 13, 2025
- Data leaked
At a glance
- Group
- lockbit3
- Status
- Data leaked
- Country
- United States
- Sector
- Financial Services
- Listed on leak site
- Apr 13, 2025
About the victim
AI dossier — public-source company profileIntelliloan is a mortgage lender offering home purchase loans, refinancing, home equity lines of credit (HELOC), VA loans, FHA loans, and reverse mortgages. The company claims over 3 decades of experience and operates a transparent loan process with customer service focus.
- Industry
- Mortgage & Home Lending
Attack summary
Severity: medium — Financial services company with likely access to customer PII and financial data; however, the leak post excerpt contains only generic marketing language with no proof files, screenshots, or explicit exfiltration claims visible. Classified as medium due to the sensitivity of mortgage/lending data at scale, but lack of published proof or operational impact details.LockBit3 claims to have compromised Intelliloan. The leak post provides no explicit detail on whether data was exfiltrated, encrypted, or both, nor does it specify what data classes are at stake.
Data the group says was taken
AI dossier — extracted from the leak post- Customer loan applications
- Financial information
- Personal identification data
- Credit scores
- Mortgage documents
What the group claims
Experience the Intelliloan difference! Get expert guidance on home loans, refinancing, and mortgage solutions. Learn how our innovative approach and dedicated team can help you achieve your financial goals. Announcements. Login. Make a payment. 833 9...
Sources
Source
Indexed 1 year agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.
