LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Lennar Mortgage, LLC Data Breach Notice (Massachusetts Attorney General)

CRITICAL severityConfirmedHow we verify

Lennar Mortgage, LLC Data Breach Notice (Massachusetts Attorney General): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·August 14, 2026
Lennar Mortgage, LLC Data Breach Notice (Massachusetts Attorney General)

Reported August 14, 2026. Approximately 674 people affected.

CRITICAL
Severity
674
People affected
5
Data types exposed
August 14, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Lennar Mortgage, LLC has notified the Massachusetts Attorney General of a data breach affecting 674 individuals, with the incident disclosed on August 14, 2026. The exposed data includes Social Security numbers, medical records, financial account numbers, driver’s license numbers, and credit or debit card numbers; individuals should review the notice and take recommended protective steps if their information was involved.

Severity & verification
CRITICAL severityConfirmed
Exposes government-ID/financial/medical data.
Corroborated by an official disclosure or a verified breach feed.
Check your exposure
674 accounts were exposed here. We can’t confirm any single incident against the sources we search — but we can show you every leak and listing tied to your email. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

A formal notice filed with Massachusetts authorities says Lennar Mortgage, LLC has told residents that personal information belonging to 674 people was exposed in a data breach. For anyone who has applied for, held, or serviced a mortgage through the company, the practical question is straightforward: whether identifiers that can be used for identity theft, account fraud, or medical-related scams were among the records involved.

The filing, reported on August 14, 2026, to the Massachusetts Office of Consumer Affairs, lists Social Security numbers, medical records, financial account numbers, driver’s license numbers, and credit or debit card numbers among the information exposed. Public detail beyond that notice remains limited; what is confirmed is the scale reported to the state and the categories of data named in the disclosure.

Inside the incident

According to the breach notice associated with the Massachusetts Attorney General’s reporting channel, Lennar Mortgage, LLC notified Massachusetts residents of a data breach in a filing dated August 14, 2026. The notice states that 674 people were affected and enumerates the data types listed above as among the information exposed.

How the incident began, how long unauthorized access lasted, whether systems were encrypted, and whether data was copied, viewed, or only potentially accessible are not described in the facts available from that filing. No threat group is attributed. The public record at this stage consists of the organization’s notice to the state, the reported headcount of 674, and the named categories of personal information.

How a breach like this happens

Incidents that lead to notices of this kind often follow familiar patterns in financial and mortgage servicing environments, though none of the following should be read as a confirmed description of this specific event. Attackers may obtain credentials through phishing or reused passwords, exploit unpatched remote-access software, or abuse a compromised vendor account that already has legitimate pathways into customer systems. Once inside, they may search file shares, databases, or document repositories that hold loan applications, servicing files, and identity documents.

In other cases, a misconfigured cloud storage bucket, an errant email, or a lost device can expose the same kinds of records without a dramatic “break-in.” Mortgage-related workflows routinely move sensitive identifiers between originators, underwriters, servicers, and third-party processors; each handoff widens the set of systems that must be protected. When a breach is later discovered—through monitoring, a customer complaint, law-enforcement tip, or an external notification—organizations assess what was stored in the affected environment and then issue notices required by state law. The Massachusetts filing reflects that notification step; it does not, by itself, establish the technical root cause.

Lennar Mortgage, LLC and its sector

Lennar Mortgage, LLC operates in residential mortgage lending and related services. Firms in this sector collect and retain extensive personal and financial information in order to originate loans, verify identity and income, service payments, and meet investor and regulatory requirements. Typical holdings for such organizations include government identifiers, account and payment details, property and employment data, and, in some files, health-related information tied to disability, insurance, or hardship documentation.

A breach affecting a mortgage company is consequential because the data set is both rich and durable. Loan files can remain relevant for years, and the same identifiers used to underwrite a mortgage are the ones criminals reuse for new credit, tax fraud, or account takeover. Even when only a few hundred people are named in a state notice, those individuals may face elevated monitoring burdens, and the organization faces notification costs, regulatory scrutiny, and potential civil claims. The Massachusetts notice places this event in that familiar sector context without adding further operational detail about Lennar Mortgage’s internal systems.

What data was at risk

The notice lists the following categories as among the information exposed: Social Security numbers, medical records, financial account numbers, driver’s license numbers, and credit or debit card numbers. Those are the only data types confirmed in the facts provided. The filing does not itemize every field in every record, does not state whether full card magnetic-stripe or CVV data were included, and does not describe the format or completeness of the medical records.

Organizations in mortgage lending commonly also hold names, addresses, dates of birth, income and employment history, and property details; whether any of those additional elements were involved here is unconfirmed. Readers should treat only the named categories as established by the disclosure and regard other contents as unknown unless a later official update says otherwise.

What's at stake

For affected people, the combination of government identifiers, financial account and card numbers, driver’s license data, and medical records creates several concrete risks. Social Security numbers and license numbers can support synthetic identity fraud or the opening of new credit. Account and card numbers can enable unauthorized charges or attempts to manipulate existing banking relationships. Medical information can be misused in targeted phishing, insurance fraud, or embarrassment-based scams. These harms are not automatic—many breach victims never see direct misuse—but the exposure raises the baseline need for monitoring and caution.

For the organization, stakes include regulatory follow-up, the cost of notice and credit-monitoring offers if provided, reputational damage among borrowers, and potential litigation. None of those outcomes is predetermined by the filing alone; they depend on later facts about cause, scope, and response. The confirmed public picture remains the August 14, 2026 notice, the figure of 674 people, and the data categories named.

If your data was in this breach

If you have a relationship with Lennar Mortgage, LLC or receive a formal notice, treat the letter’s instructions as the primary guide. In parallel, ordinary protective steps reduce the chance that exposed data is turned into lasting harm:

You can also run a free exposure scan of your email address to check whether that address has already appeared in other known breach data sets, which helps you prioritize password changes and monitoring. Official updates, if any, will come from the company or regulators; until then, the Massachusetts notice is the clearest public statement of what was reported.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

CompanyLennar Mortgage, LLC security record
52/100
DoxxScan™ · Elevated doxx risk
D+ 56Weak record

1 reported incident on record.

See Lennar Mortgage, LLC’s full breach history →
RelatedMore incidents at Lennar Mortgage, LLC

More recent breaches

Infinity Globus Business Services LLC Data Breach Notice (Massachusetts Attorney General)August 20, 2026Merced Union High School District Data Breach Notice (Massachusetts Attorney General)August 20, 2026Rockland Trust Data Breach Notice (Massachusetts Attorney General)August 20, 2026Aerospace Alloys Inc Data Breach Notice (Massachusetts Attorney General)August 19, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Lennar Mortgage, LLC Data Breach Notice (Massachusetts Attorney General) →

Source: Massachusetts Office of Consumer Affairs breach notification

Verified breach

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram