Incident Report

Mortgage Meltdown: loanDepot’s IT systems Shut Down in Cyber Attack

By

By

Access Point Consulting

Overview

loanDepot, a cornerstone in the U.S. mortgage lending sector, finds itself at the center of a cybersecurity incident for the second time since 2022. A recent cyberattack has forced the company to enact a temporary shutdown of its IT systems, causing significant disruptions to its online payment-processing capabilities and customer service operations. Customers attempting to access loanDepot's payment portal or contact the company by phone encountered issues, prompting an inquiry. loanDepot has publicly acknowledged the cyber incident and is working to resolve the situation.

The cyberattack has immediate repercussions for loanDepot. The full extent of the impact, including potential data breaches, has not yet been determined.

The cyber incident at loanDepot stems from a compromise in the organization's network, leading to disruptions in critical services. The specific method of compromise has not been undisclosed.

The cyberattack has had a profound impact on loanDepot's operations, affecting various aspects of the organization. Despite the details of the attack remaining undisclosed, the nature of the attack raises concerns about the potential compromise of sensitive financial and bank account information. This incident follows a data breach disclosed by loanDepot in August 2022, adding to the organization's challenges in safeguarding customer data. A reminder that recent victims of cyberattacks are more likely to be targeted again for another attack in the near future.

Response and Recovery

In collaboration with law enforcement agencies and forensics experts, loanDepot has launched an investigation to determine the full extent of the breach. Certain systems have been taken offline as a proactive measure to contain the impact and prevent further spread of the attackers’ access. The incident has been communicated to stakeholders, including executives, employees, and customers. Transparency in communication is crucial to maintaining trust during such incidents.

Efforts are underway to restore affected systems and services. The timeline for recovery and the potential impact on business operations remain uncertain. The company acknowledges the potential inconvenience to customers and is working to minimize downtime and disruptions.

Mitigation

To prevent future cyberattacks and enhance overall cybersecurity, loanDepot is implementing mitigation measures. This includes a focus on enhancing security measures across its IT infrastructure. In addition, it may include upgrading security protocols, implementing advanced threat detection systems, and conducting regular security audits.

Hopefully, insights gained from the incident will inform future security practices. Identifying vulnerabilities and weaknesses in existing systems will be crucial in developing a more robust cybersecurity posture.

Recommendations

Access Point urges organizations to take proactive measures to enhance cybersecurity resilience. The key recommendation is to evaluate your company’s defenses against cyber threats. We encourage businesses to upgrade their security infrastructure and enhance their staff’s cybersecurity training––especially on recognizing and preventing phishing attempts, and to deploy advanced threat detection tools.

In addition, it’s essential to conduct a thorough review of organizations’ incident response plans to ensure they are up-to-date and effective. This includes scenario-based simulations to identify gaps in decision making and communication, incident drills/fire drills, runbook testing, assessing tools, assessing a plan's readiness to address various types of cyberattacks, and rigorous after-action reviews of each test or simulation done to identify areas of improvement.

Finally, the clear communication channels with customers should be established to inform them of any incidents, the steps being taken to address them, and any actions they should take to safeguard their information.

Resources

CyberWatch

April 2, 2025

Scott "Monty" Montgomery (Island) | Navigating CMMC compliance for organizations of every size

Scott Montgomery, known as Monty, joined the CyberWatch Expert Series podcast to discuss his extensive background in cybersecurity, particularly in building and designing network security tools for high-assurance environments like the Department of Defense (DoD) and the intelligence community. His experience includes significant tenure at McAfee (now Trellix), which led him to his current role at Island, where he focuses on innovative approaches to cybersecurity compliance.

Find out more
March 19, 2025

Michael Sviben (DomainGuard) | Defending against phishing and building proactive security awareness

Cybersecurity threats evolve rapidly, and one tactic consistently rises above the rest: phishing. In this episode of CyberWatch, Michael Sviben, co-founder of DomainGuard, discusses why phishing remains so effective, how businesses and individuals become targets, and what you can do to stay vigilant.

Find out more
March 5, 2025

David Habib (Brightspot) | Building a culture of cybersecurity awareness

Cybersecurity awareness is often reduced to check-the-box training, but David Habib, CIO at Brightspot, argues that real security awareness isn’t about formal programs—it’s about making security part of a company’s culture. In this episode, he shares practical insights on how organizations can move beyond stale training sessions to create an engaged and security-conscious workforce.

Find out more