Attorneys at Almeida Law Group are investigating whether a class action lawsuit can be filed on behalf of individuals affected by a possible The Money Store data breach. According to dark web monitoring sources, a hacker group calling itself Storm claimed responsibility for a cyberattack on The Money Store in a post first observed in September 2026, alleging it had gained access to internal company systems. As of this writing, The Money Store has not issued a public confirmation of the incident, and the exact scope of any exposed data remains unknown. If you believe you were affected, contact Almeida Law Group.
About The Money Store
The Money Store is a trade name operated by MLD Mortgage, Inc., a privately held, family-owned residential mortgage lender that has operated under The Money Store brand since 1972. The company is headquartered at 30B Vreeland Road, Suite 200, Florham Park, New Jersey, and is licensed in 47 states plus the District of Columbia, with more than 25 branches nationwide. It offers home purchase, refinance, construction, renovation, home equity, FHA, VA, USDA, and jumbo loan products. Gary Dear serves as Chairman and CEO.
What Happened?
On September 21st, 2026, the ransomware group known as Storm posted a claim on its dark web leak site alleging it had attacked The Money Store (themoneystore.com). The claim was reported by Ransomware.live. No confirmation from The Money Store, MLD Mortgage, or any government regulator has been found, and no specific data types, data volume, or breach dates were included in the attacker’s posting. No independent corroborating source was found. The claim should be treated as an allegation only.
Storm is an emerging ransomware-as-a-service (RaaS) group first observed in August 2026, according to WatchGuard’s ransomware tracker. It operates a Tor-based extortion site and uses double-extortion tactics. Storm has claimed multiple victims since August 2026, including organizations in real estate, insurance, auto financing, and financial services. Separately, Microsoft Threat Intelligence has tracked a financially motivated threat actor designated Storm-1175 that began deploying a custom ransomware strain called StormEncryptor on August 2nd, 2026, possibly exploiting CVE-2026-18577, an N-able authentication-bypass vulnerability. Microsoft assesses Storm-1175 as likely operating from a UTC+8 timezone consistent with Chinese-speaking regions and previously linked to Medusa ransomware campaigns against healthcare, professional services, and finance organizations. It is not independently confirmed whether the Storm leak-site group and Microsoft’s Storm-1175 designation refer to the same actor.
Key Facts at a Glance
- Company or Organization: The Money Store (MLD Mortgage, Inc.)
- Industry: Residential Mortgage Lending / Financial Services
- Location: Florham Park, New Jersey
- Incident type: Ransomware claim (dark web allegation)
- Prior breach: No prior cybersecurity incidents found in public reporting
- Source: Ransomware.live leak-site allegation; WatchGuard Storm tracker; GBHackers — Storm-1175; The Record — Storm-1175
What Should You Do?
Even though The Money Store has not confirmed a breach, it is a reasonable precaution to take protective steps now. Consider placing a fraud alert or credit freeze on your credit files with Equifax, Experian, and TransUnion, and monitor your accounts and credit reports closely for any unauthorized activity. You can request free credit reports at AnnualCreditReport.com. If you believe your personal information has been misused, visit IdentityTheft.gov for guidance on reporting and recovery steps.
Your Legal Rights
If your personal information was involved in this breach, you may have legal rights depending on the facts of the incident and the law in your state. Almeida Law Group represents consumers in data breach and privacy litigation and can help you evaluate whether you may have a claim. Contact us at (708) 529-5418 or through our contact page for a free case evaluation.