Attorneys at Almeida Law Group are investigating whether a class action lawsuit can be filed on behalf of individuals affected by a possible Sales Boomerang data breach. According to dark web monitoring sources, a hacker group calling itself direwolf claimed responsibility for a cyberattack on Sales Boomerang in a post first observed in September 2026, alleging it had gained access to internal company systems. As of this writing, Sales Boomerang has not issued a public confirmation of the incident, and the exact scope of any exposed data remains unknown. If you believe you were affected, contact Almeida Law Group.
About Sales Boomerang
Sales Boomerang is an automated borrower intelligence platform for the mortgage lending industry, founded in 2017 and headquartered in Owings Mills, Maryland. The platform monitors lender contact databases to identify when borrowers may be ready for a new loan, combining market intelligence such as interest rate changes, credit scores, and home listings with lenders’ underwriting preferences to generate real-time alerts for loan officers. The company serves over 300 independent mortgage banks, depository banks, and credit union customers. In 2023, Sales Boomerang merged with Mortgage Coach and the combined entity rebranded under the parent name TrustEngine.
What Happened?
On September 8th, 2026, Ransomware.live reported that the Direwolf ransomware group listed Sales Boomerang as a claimed victim on its dark-web leak site. The attacker-side listing describes the affected areas as “Accounting/Finance Software, Analytics & Performance Software, Customer Relationship Management,” which appears to characterize the victim’s business categories rather than identify specific data types that were exfiltrated. Direwolf has also claimed responsibility for attacks against Wolfram Research, Lightcast, and Arizona State University, among others. No official notification, regulatory filing, or law enforcement statement regarding this incident has been located, and no independent corroborating sources confirm the claim.
Direwolf is a double-extortion ransomware group that first appeared around May 2025. It is written in Go and uses Curve25519 and ChaCha20 encryption. No prior breaches involving Sales Boomerang or its parent entity TrustEngine have been identified, and no litigation related to this incident has been found. A third-party security blog noted the Direwolf claim against Sales Boomerang but explicitly disclaimed any confirmation of its accuracy.
Key Facts at a Glance
- Company or Organization: Sales Boomerang (operating under parent TrustEngine since 2023)
- Industry: Mortgage Technology / Financial Services Software (SaaS)
- Location: Owings Mills, Maryland, US
- Incident type: Ransomware claim (dark-web allegation; unconfirmed)
- Claim first observed: September 8th, 2026
- Source: Ransomware.live – Sales Boomerang; RansomLook – Direwolf group profile; National Mortgage Professional – Sales Boomerang and Mortgage Coach Merge; TrustEngine Launch – LLR Partners
What Should You Do?
Because the incident has not been confirmed by Sales Boomerang or TrustEngine, no formal identity protection enrollment has been announced. Even so, it is a good idea to place a fraud alert or credit freeze with the three major credit bureaus—Equifax, Experian, and TransUnion—and to monitor your financial accounts and credit reports closely for any unusual activity. You can request free annual credit reports at AnnualCreditReport.com. If you suspect your information has been misused, visit IdentityTheft.gov for step-by-step guidance from the Federal Trade Commission.
Your Legal Rights
If your personal information was involved in this breach, you may have legal rights depending on the facts of the incident and the law in your state. Almeida Law Group represents consumers in data breach and privacy litigation and can help you evaluate whether you may have a claim. Contact us at (708) 529-5418 or through our contact page for a free case evaluation.