Ransomware victim disclosure
← All victimsUnisource National Lender Services
listed as Unisource Information Services · Claimed by Hunters · listed 2 years ago
Status timeline
- ListedJan 11, 2025
- Data leakeddate unknown
At a glance
- Group
- Hunters
- Status
- Data leaked
- Country
- United States
- Sector
- Technology
- Listed on leak site
- Jan 11, 2025
About the victim
AI dossier — public-source company profileUnisource National Lender Services is a national provider of title insurance, escrow, and property-related services to the mortgage and real estate industries. Operating through multiple offices across the US (California, Texas, Nevada, Alabama, Washington) with centralized processing centers, the company utilizes proprietary technology to automate and streamline client operations.
- Industry
- Title Insurance & Escrow Services
- Address
- 2530 Red Hill Avenue, Suite 110, Santa Ana, CA 92705 (primary); multiple offices nationwide
Attack summary
Severity: high — Confirmed exfiltration of data from a financial services company handling sensitive real estate and mortgage-related information. Title insurance and escrow services involve PII, financial records, and property details affecting mortgage borrowers and real estate transactions at scale.The hunters group claims to have exfiltrated data from Unisource. No encryption is mentioned; the attack appears to be data theft only. Specific details on what data was stolen are not provided in the leaked post excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- Title insurance records
- Escrow service documentation
- Client financial information
- Real estate transaction data
- Property reports
- Customer account details
What the group claims
Exfiltraded data : yes - Encrypted data : no
Sources
Source
Indexed 2 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

