Ransomware victim disclosure
← All victimsThe Mortgage Firm
listed as THEMORTGAGEFIRM.COM · Claimed by Clop · listed 4 months ago
Status timeline
- ListedFeb 14, 2026
- Data leakeddate unknown
At a glance
- Group
- Clop
- Status
- Data leaked
- Country
- United States
- Sector
- Financial Services
- Listed on leak site
- Feb 14, 2026
About the victim
AI dossier — public-source company profileThe Mortgage Firm is a mortgage lender providing home purchase, refinance, and loan assistance services. Based in Altamonte Springs, Florida, they operate across multiple states including Florida and Texas, offering digital mortgage processing, loan officer services, and various down payment assistance programs.
- Industry
- Mortgage & Lending Services
- Address
- 921 Douglas Ave., Ste. 200, Altamonte Springs, FL 32714
Attack summary
Severity: high — Financial services company with confirmed data exfiltration by a known ransomware operator (Clop). Mortgage and lending data involving PII and financial information represents sensitive regulated data. Disclosed status indicates data has been or will be published.Clop group claims to have compromised The Mortgage Firm and placed it in a queue for data forwarding/publication. The specific data stolen and operational impact are not detailed in the available leak post excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- Customer loan applications
- Financial information
- Personal identification data
- Mortgage documentation
Original description
AI-summarised, not from the leak postTheMortageFirm.com is a digital platform for The Mortgage Firm, Inc., a provider of mortgage finance services. Founded in 1995 and headquartered in Altamonte Springs, Florida, this company offers direct residential lending services to clients. Services include home loans, refinancing, and loan consultation. The online platform allows clients to apply for loans, make payments, and access information about mortgage processes.
The leak post
captured from the group's siteYou have been placed in a queue, awaiting forwarding to the platform. Please do not refresh the page, you will be automatically redirected.
Sources
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

