Ransomware victim disclosure
← All victimstheLender
Claimed by Termite · listed 4 hours ago
Status timeline
- ListedSep 22, 2026
- Data leakeddate unknown
At a glance
- Group
- Termite
- Status
- Data leaked
- Country
- United States
- Sector
- Financial Services
- Listed on leak site
- Sep 22, 2026
About the victim
AI dossier — public-source company profiletheLender is a national mortgage lender offering non-QM, DSCR, bank statement, and alternative documentation loan products to borrowers and brokers across 48 states. Founded by industry veterans, the company has funded $15.4B in loans, served 40,000+ clients, and was ranked Inc. 5000 No. 1 Fastest Growing Real Estate Company in 2022.
- Industry
- Mortgage Lending & Real Estate Finance
- Founded
- 2014
Attack summary
Severity: low — Only a company description announcement is included in the leak post; no proof files, screenshots, or specific claims of data exfiltration or encryption are documented.The termite group claims to have breached theLender but the leak post excerpt provided contains only marketing copy about the company's loan products and does not describe what data was exfiltrated, encrypted, or compromised.
What the group claims
theLender was created to make a difference. As a group of proven industry leaders who recently founded one of the largest and fastest growing Wholesale mortgage companies in the United States, the company aims to change the stagnant landscape of Wholesale mortgage - one partnership, one loan, and one day at a time.
Sources
Source
Indexed 4 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

