A Mortgage Lender Got Hit in February. Loan Application Data Is Now in the Wrong Hands.
In this week’s “Strike a Nerve” update, I want to close out the month with a story that is a clear reminder of what is at stake when a cyberattack hits a business handling sensitive financial data.
Plaza Home Mortgage disclosed that a February cyberattack compromised personal data for both customers and employees. The information exposed included details from loan applications. Names, Social Security numbers, income records, employment history, and financial account information. The kind of data that takes years to recover from if it ends up in the hands of identity thieves or fraud operators.
Mortgage companies, financial services firms, and any business that collects detailed personal and financial information during a transaction are high-value targets. Attackers know exactly what that data is worth and exactly how to use it. A loan application file contains nearly everything needed to open fraudulent accounts, file false tax returns, or impersonate someone for years.
For small and mid-sized businesses in financial services, healthcare, legal, and professional services, the lesson is consistent. The sensitivity of the data you collect creates a responsibility that follows that data for as long as you hold it. The attack does not have to be sophisticated to be devastating. It just has to find the right file in the wrong place.
Three steps to take right now:
- Identify where your most sensitive client and employee data is stored and confirm that access is restricted to only those with a genuine need.
- Implement data retention policies that limit how long sensitive information is kept after a transaction is complete. Data you no longer hold cannot be stolen.
- Make sure your incident response plan includes a clear process for notifying affected individuals quickly. Delayed notification compounds the damage and the liability.
Do you know how long sensitive client data stays in your systems after a transaction closes? Let us help you find out where your exposure is.
— Steve, “Strike a Nerve” Weekly Cyber Threat Update