Union Home Mortgage Corp. Data Breach Notice (Oregon Attorney General): What Was Exposed & What To Do
Union Home Mortgage Corp. has disclosed a data breach that occurred on May 27, 2025, exposing the personal information of 425,538 individuals. If you are or were a customer, review the notice filed with the Oregon Attorney General and consider placing a fraud alert or credit freeze.
When a mortgage company reports that hundreds of thousands of people’s personal information may have been involved in a cyber incident, the practical concern is straightforward: loan files and identity details are the kind of material that can be reused for fraud long after the initial event. Union Home Mortgage Corp. has notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on September 11, 2025. That filing places the incident itself on May 27, 2025, and states that 425,538 people were affected. Public detail on exactly which fields were taken is limited to “personal information” as described in the breach notification.
For anyone who has applied for a home loan, refinanced, or otherwise shared documents with a mortgage lender, the gap between the incident date and the public notice is part of why these events matter. Identity and financial data do not expire quickly, and affected people often learn of exposure only after a regulator filing or formal letter arrives.
Inside the incident
According to the Oregon Attorney General–related breach notice, Union Home Mortgage Corp. reported the matter on September 11, 2025. The company’s filing states that the underlying incident occurred on May 27, 2025. The notice indicates that 425,538 individuals were affected and that the exposed data is characterized as personal information under the breach notification.
Beyond those points, public detail is limited. The available record does not describe the technical method of intrusion, whether systems were encrypted or exfiltrated, how long unauthorized access lasted, or which specific systems held the data. No dollar loss, ransom demand, or named threat group appears in the facts provided. What is established is the organization’s disclosure to Oregon authorities, the incident date given in that filing, the headcount of people said to be affected, and the high-level category of data involved.
How a breach like this happens
In general terms, incidents that lead to mortgage- or lending-related breach notices often begin with common entry paths rather than exotic techniques. Attackers may obtain valid credentials through phishing, reuse of passwords from earlier unrelated breaches, or malware on an employee device. Once inside a corporate network or a cloud application used for loan processing, they may move toward file shares, customer databases, document-management systems, or email archives where applications and closing packages are stored.
Another frequent pattern is compromise of a third-party service provider that handles underwriting support, document storage, or customer communications. In those cases the lender may learn of exposure only after the vendor reports an incident. Ransomware groups sometimes steal copies of data before locking systems, then pressure organizations by threatening publication. None of these scenarios is confirmed for this specific event; they are the ordinary background against which mortgage-sector notices are typically written when technical detail is sparse in public filings.
Detection can lag for weeks or months if logging is incomplete or if the activity blends with normal administrative access. Notification timelines then reflect investigation, legal review, and statutory deadlines in states such as Oregon, which helps explain why a May incident can surface in a September filing.
About Union Home Mortgage Corp.
Union Home Mortgage Corp. operates in the residential mortgage sector: originating, processing, and servicing home loans. Firms in this line of business routinely collect and retain large volumes of sensitive material because underwriting and compliance require it. Typical holdings across the industry include full legal names, current and former addresses, dates of birth, Social Security numbers, employment and income records, bank account and routing details, tax documents, credit-related information, and copies of identification and property paperwork.
A breach at a mortgage company is consequential because that concentration of identity and financial data is useful to criminals who open credit accounts, file fraudulent tax returns, attempt account takeovers, or craft targeted scams that reference a real loan or property. The organization’s role as a steward of closing and servicing records also means a single incident can touch applicants, borrowers, and sometimes co-borrowers or guarantors across multiple states, even when the formal notice is filed in one jurisdiction such as Oregon.
What was likely exposed
The breach notification names the exposed category as personal information. It does not, in the facts available here, itemize fields such as Social Security numbers, financial account numbers, or driver’s license data. Exact contents therefore remain unconfirmed beyond that broad label.
Organizations of this type typically hold the categories described above—identity identifiers, contact data, and financial and loan-file documents—because those elements are required to evaluate creditworthiness and complete real-estate transactions. Readers should treat any assumption about a specific data element as unverified unless a later official notice lists it. The confirmed public statement is that personal information was involved for the 425,538 people referenced in the filing.
Why it matters
For affected individuals, the main risks are long-lived: new-account fraud, tax-refund fraud, social-engineering calls that cite a real mortgage relationship, and difficulty unwinding errors on credit reports. Even when a lender offers monitoring, the underlying identifiers can still be misused years later. People who shared documents during an application may not remember every vendor in the chain, which complicates knowing where else copies might reside.
For the organization, consequences include regulatory scrutiny, notification and support costs, potential civil claims, and reputational damage among borrowers and referral partners. Operational disruption can follow if systems must be taken offline or rebuilt. None of that establishes negligence as a proven fact in this case; it simply describes why mortgage-sector incidents draw sustained attention once headcounts reach the hundreds of thousands.
The multi-month span between the stated May 27, 2025 incident date and the September 11, 2025 Oregon filing also matters in practical terms: exposed data may already have circulated or been tested in small fraud attempts before many people received formal notice.
Were you affected?
If you have been a customer, applicant, or co-borrower with Union Home Mortgage Corp., watch for an official breach notification letter and follow the instructions it provides for credit monitoring or other support, if offered. Place a fraud alert or credit freeze with the major consumer reporting agencies if you believe your identifiers may be involved, and treat unexpected calls or emails about your mortgage or “updated wiring instructions” with extreme caution. Review account statements and credit reports for unfamiliar inquiries or accounts. You can also run a free exposure scan of your email address to check whether that address has already appeared in known breach datasets, which can help you prioritize password changes and monitoring even when a single company’s notice is still incomplete.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Decisely Insurance Services Data Breach Notice (Oregon Attorney General)Apro, LLC d/b/a United Pacific Data Breach Notice (Oregon Attorney General)Apro, LLC d/ Data Breach Notice (Oregon Attorney General)CareOregon Data Breach Notice (Oregon Attorney General)Latest breaches
Verified breach
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.