Attorneys at Almeida Law Group are investigating whether a class action lawsuit can be filed on behalf of individuals affected by a possible theLender data breach. According to dark web monitoring sources, a hacker group calling itself termite claimed responsibility for a cyberattack on theLender in a post first observed in September 2026, alleging it had gained access to internal company systems. As of this writing, theLender has not issued a public confirmation of the incident, and the exact scope of any exposed data remains unknown. If you believe you were affected, contact Almeida Law Group.
About theLender
theLender is a trade name of Hometown Equity Mortgage, LLC (NMLS #133519), a privately held wholesale mortgage lender headquartered in Lake Forest, California. Founded in 2017, the company offers mortgage products including Non-QM, FHA, VA, conventional, USDA, and jumbo loans through broker partnerships, and reports over $11 billion in Non-QM loan funding. It was ranked the fastest-growing real estate company on the Inc. 5000 list in 2022 and employs between 51 and 200 people.
What Happened?
On September 22nd, 2026, the Termite ransomware group posted a claim on its dark-web leak site listing theLender as a victim. The claim was observed and cataloged by Ransomware.live and independently noted by the security aggregator hendryadrian.com, both of which characterize it as an unverified, attacker-side allegation. theLender has not publicly confirmed or denied the incident. No state attorney general filings, regulatory disclosures, or mainstream cybersecurity news reporting corroborating the claim were found. No specific data types, data volume, or number of affected individuals have been disclosed by any party. The Termite group’s leak-site posting reproduces theLender’s own marketing language and does not describe any exfiltrated data.
Termite is a ransomware and data-extortion group first identified in late 2024 that uses a modified version of Babuk ransomware and employs double-extortion tactics. Its most notable prior attack was the November 2024 breach of supply-chain firm Blue Yonder. The group has claimed at least 48 victims across 14 countries and has been linked to exploitation of Cleo file-transfer software zero-day vulnerabilities.
Key Facts at a Glance
- Company or Organization: theLender (a trade name of Hometown Equity Mortgage, LLC, NMLS #133519)
- Industry: Financial Services — Wholesale Mortgage Lending
- Location: Lake Forest, California
- Incident type: Ransomware claim (unconfirmed, attacker-side allegation)
- Source: Ransomware.live leak-site allegation; hendryadrian.com
What Should You Do?
If you have ever applied for or received a mortgage through theLender and are concerned about this allegation, it is a good idea to take precautionary steps now. Place a fraud alert or credit freeze with the three major credit bureaus—Equifax, Experian, and TransUnion—to make it harder for unauthorized parties to open accounts in your name. Monitor your financial accounts and credit reports closely for unfamiliar activity, and request your free annual credit reports at AnnualCreditReport.com. If you become a victim of identity theft, report it and get a recovery plan at IdentityTheft.gov.
Your Legal Rights
If your personal information was involved in this breach, you may have legal rights depending on the facts of the incident and the law in your state. Almeida Law Group represents consumers in data breach and privacy litigation and can help you evaluate whether you may have a claim. Contact us at (708) 529-5418 or through our contact page for a free case evaluation.