American Lending Center Notifies 123K of Ransomware Data Breach: Ransomware Claim — What’s Alleged & What To Do
American Lending Center has notified 123,000 individuals of a ransomware data breach disclosed on April 28, 2026, exposing names, dates of birth, and Social Security numbers. Affected individuals should verify their status and monitor their accounts for signs of misuse.
Inside the incident
The company stated that the ransomware incident was identified in July 2025. An investigation followed, and once completed it showed that names, dates of birth, and Social Security numbers belonging to more than 123,000 individuals may have been accessed. Notifications to those individuals were issued after the review concluded.
Public information does not include the method of initial access, the duration of unauthorized presence, or whether data was copied or only encrypted. The company has not disclosed any ransom demand or payment.
How a breach like this happens
Ransomware incidents at organizations that hold personal records often begin with an attacker gaining entry through remote-access tools, stolen credentials, or unpatched software. Once inside, the operators deploy encryption across systems and may also copy files before demanding payment.
Investigation of such events typically requires weeks or months to determine what data was reachable and whether it left the network. Organizations then assess notification obligations under state and federal rules that apply to financial-service providers.
Who is American Lending Center?
American Lending Center operates as a non-bank lender, providing loans outside the traditional banking system. Entities in this sector routinely collect and store identifying information from applicants and borrowers to complete credit checks, verify identities, and comply with regulatory requirements.
Because the data maintained by such firms includes elements used for identity verification, any confirmed access carries implications for the individuals whose records are held, regardless of the lender’s size or market focus.
The information in question
The company has reported that names, dates of birth, and Social Security numbers may have been accessed. These data elements are the only categories named in the disclosure.
Financial-service organizations commonly retain additional details such as addresses, account numbers, and income information. The exact contents of any files that left American Lending Center’s systems remain unconfirmed beyond the three data types already stated.
What's at stake
Names combined with dates of birth and Social Security numbers can be used to open accounts or file claims in someone else’s name. Individuals whose information was involved may see an increase in attempts to misuse their identity over time.
For the organization, the incident adds regulatory reporting requirements and potential costs associated with notification, credit monitoring offers, and any follow-on legal or compliance actions. The long-term effect on customer trust depends on the adequacy of the response and future security measures.
If your data was in this claimed breach
Review any notice received from American Lending Center for specific instructions. Place a fraud alert or credit freeze with the major credit bureaus and monitor account statements and credit reports for unusual activity.
Readers can also run a free exposure scan of their email address against known breach data sets to check whether their information appears in other incidents.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
JCPenney Data Breach (2026)AssuranceAmerica Breach Exposes 6.9M Driver's LicensesSBI Software Hit by Genesis Data LeakUnsafe ransomware group claims Deutsche Bank data breachLatest breaches
Publicly posted — pending verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.