Industry - Data Breach
Executive Summary
Bayview Asset Management and its mortgage servicing subsidiaries are facing class action lawsuits after a 2021 data breach compromised the sensitive information of over 5 million consumers. Plaintiffs allege the companies failed to follow standard security practices, including not encrypting personally identifiable information and failing to detect that a hacker accessed their systems for 41 days after an employee clicked a malicious link. The companies are now objecting to a proposed amended...
What Happened
In late 2021, Bayview Asset Management and its mortgage servicing subsidiaries suffered a data breach that compromised the sensitive information of over 5 million consumers. The breach originated when an employee clicked a malicious link in a work-related search result, allowing a hacker to remain undetected in the company's systems for 41 days. Dozens of affected consumers filed class action lawsuits in federal court, and in December 2023, a judge dismissed all but one of their claims before plaintiffs filed a proposed amended complaint in January 2024.
Who Is Affected
Over 5 million consumers who had mortgage accounts or relationships with Bayview Asset Management's servicing subsidiaries - Community Loan Servicing, Lakeview Loan Servicing, and Pingora Loan Servicing - are affected. The breach exposed personally identifiable information that the companies allegedly stored in internet-accessible environments without proper encryption or deletion protocols.
Why It Matters
This case illustrates widespread vulnerabilities in the mortgage servicing industry, where millions of consumers' financial and personal data may be stored without adequate security measures such as encryption or regular threat detection. The 41-day window during which the hacker remained undetected highlights significant gaps in system monitoring, and the legal proceedings reveal how companies may resist transparency about their security failures even after breaches occur.
What You Should Do
If you are or were a customer of Bayview Asset Management, Community Loan Servicing, Lakeview Loan Servicing, or Pingora Loan Servicing around 2021, monitor your credit reports for unauthorized accounts or inquiries and consider placing a fraud alert or credit freeze with the major credit bureaus. Review your financial statements regularly for suspicious activity and change passwords for any accounts associated with these servicers. Watch for official breach notifications that may provide access to free credit monitoring services or instructions for joining the class action lawsuit.
Summary generated from verified sources and reviewed before publication. How we summarize.