On the evening of September 23, NFM Lending's legal department said something for the first time since the company's name appeared on a ransomware group's leak site sixteen days earlier. It confirmed a cybersecurity incident. It did not confirm a breach, a number, or a category of data.

The most quoted line from that statement is the narrowest one. The company said it could not confirm the number of people impacted, that it had brought in an outside forensics firm, and that it was following protocols to ensure compliance with notification and credit protection resources for anyone affected. Read against the five federal lawsuits already on a Maryland docket, the second half of that sentence is the part that matters. A notification process that is still running is a notification process that has not yet missed a deadline.

What the gang says it took

Interlock, the group that claimed the intrusion on September 7, says it took more than 2.5 terabytes from NFM: customer names, Social Security numbers, bank account data, credit information, loan terms, addresses, phone numbers, borrower and loan identifiers, loan pricing, itemized expense reports, and staff personal data. One figure in the post stands out. Interlock claims access to data from the Encompass loan origination system containing information on more than 1 million clients. Trade coverage has reported the volume figure variously as more than 2 terabytes and more than 2.5.

NFM is a real target for that kind of claim. The Linthicum, Maryland lender operates in 49 states, originated more than $7.2 billion in the prior year, and sponsors over 600 loan originators. A loan origination system holds exactly the mix of identifiers that makes a breach expensive.

Interlock is not an unknown quantity. The group surfaced in late September 2024, and the FBI, CISA, HHS, and MS-ISAC published a joint advisory on it in July 2025 under the StopRansomware banner. That advisory describes a double extortion model, encryption after exfiltration, and an initial access route the agencies called atypical: drive-by downloads from compromised sites and a fake-CAPTCHA trick that talks users into pasting a Base64 PowerShell command into the Run window.

The post on NFM ends with a legal argument. Interlock asserts the exposure violated federal GLBA and FCRA, state privacy laws, and what it calls the CFPB's data breach reporting rules.

The rule the post cites does not exist

There is no CFPB rule that requires a non-bank mortgage lender to file a breach report. The Consumer Financial Protection Bureau supervises and sues non-bank mortgage companies under the Consumer Financial Protection Act, and an unreported breach can become the factual spine of an unfairness or deception claim. But the bureau has never issued a notification clock of the kind the post describes, and no lender files a breach report with it. Naming a rule that does not exist is a pressure tactic as much as a legal theory. It gives a victim's compliance department something to search for at the moment it is deciding whether to pay.

That mismatch between an incident and the moment the law requires someone to describe it is a recurring shape in incident law, as a recent Australian case showed when a breach ran from a June model evaluation to a September email with no clock in between. The real obligations here are elsewhere and narrower than the post suggests.

The first is federal. Under the FTC's Safeguards Rule at 16 CFR Part 314, a covered financial institution must notify the Federal Trade Commission of a notification event involving at least 500 consumers as soon as possible and no later than 30 days after discovery. The FTC added the requirement by amendment in October 2023, effective May 2024. Mortgage lenders that are not banks sit inside the FTC's GLBA jurisdiction, which is why the amendment exists at all: the bank regulators already had a version of this, and the non-bank half of consumer finance did not.

Two features matter here. The 30-day clock starts when any employee, officer, or agent learns of the event, not when the institution finishes deciding whether notice is required. And the rule never requires the lender to tell borrowers anything. It requires a filing with the FTC, which the commission intends to publish.

The second obligation is state. Maryland's Personal Information Protection Act, Md. Code Com. Law section 14-3504, requires a business holding computerized personal information of Maryland residents to notify them no later than 45 days after discovering the breach, a clock a 2022 amendment moved forward from the conclusion of the investigation. The Maryland Attorney General has to be told before residents are, and at 1,000 or more affected residents the business must also notify each nationwide consumer reporting agency. The Attorney General's office publishes guidelines describing those steps.

Two clocks, and neither one has run out

Run the arithmetic from the date the public claim appeared, which is the latest date the lender could plausibly have discovered the event and very likely not the earliest. September 7 plus 30 days is October 7. September 7 plus 45 days is October 22. Today is September 24. On the tighter of the two, at the outer edge of the possible discovery dates, roughly thirteen days remain.

That window explains why NFM's statement reads the way it does. A lender inside an open notification period has no reason to describe what was taken, because the description is the thing it is still assembling. The forensics firm such a statement always mentions is doing the work that has to finish before the notice can be written: which systems, which records, which residents.

It also explains why the first public confirmation may not come from the company at all. A borrower waiting to hear from NFM should be watching the FTC's breach database, because the rule does not oblige the lender to write to them directly. Even that filing can sit unpublished for a while, since the commission can delay publication by up to 30 days at law enforcement's request and longer on a written request.

Maryland's sequence is the one that does reach individuals, but it is ordered so that the Attorney General sees the notice first. A Maryland borrower who has heard nothing yet has learned what the statute allows them to learn.

Five suits arrived before the lender said anything

Between September 11 and September 17, five cases were filed against NFM Lending in the United States District Court for the District of Maryland. Koppenhaver came first, on September 11. Romancik, No. 1:26-cv-03627, and Clark, No. 1:26-cv-03632, both arrived on September 14. Smith, No. 1:26-cv-03661, followed on September 16, and Richardson, No. 1:26-cv-03677, on September 17.

The Smith complaint is the one that has been reported in most detail. The plaintiff is a former NFM customer who alleges the lender failed to maintain reasonable safeguards and has not notified customers. The claims are negligence, breach of implied contract, unjust enrichment, and violations of Maryland consumer protection law, framed as a class action on behalf of people whose information was exposed.

Every one of those complaints predates the company's September 23 statement. The first beat it by twelve days.

NFM's response to the litigation was unusually direct for a company still inside an investigation. It described suits of this kind as designed to revictimize organizations, and said they would not distract it from the forensic work.

What a complaint can plead without a notice letter

That timing is not just a public relations problem for the plaintiffs. It is a pleading problem, and it is the most interesting legal question the case raises.

Start with what a complaint needs. Since TransUnion v. Ramirez in 2021, a federal plaintiff needs a concrete harm, not a heightened risk of one. Exposure of Social Security numbers and financial account numbers has generally carried that burden, and this claim involves both. The harder question is how a named plaintiff establishes that their own data was in the stolen set when no notification letter has issued and no regulator has published a finding.

Without a notice letter, the only public evidence that anything was taken is a post on a leak site. That post is a sales document whose audience is NFM's board and its insurers, and its purpose is to make payment look cheaper than the alternative. A court weighing a motion to dismiss will notice that the complaints rest on a threat actor's marketing, and that the company has never confirmed the figures.

The allegation that NFM failed to notify customers runs into a similar issue. Under Maryland law and the FTC rule, the notification deadlines that applied when those complaints were filed had, on the public timeline, not passed. A defendant can argue that it breached nothing by staying quiet, because the law gave it until October.

None of that makes the suits weak by default. Discovery is where a defendant's own forensic reports become the plaintiff's evidence, and a class action holds a position while those reports are written. Consolidation is the near-term certainty: five similar cases in one district invite a motion under Rule 42(a) of the Federal Rules of Civil Procedure, and a court that grants it picks lead counsel before it touches the merits.

What the cases mostly do right now is create a record. Every filing is a public document saying that a mortgage lender with a $7.2 billion origination book may have lost the loan files of a seven-figure number of people, and that statement does reputational work whether or not it survives a motion to dismiss. The financial question sits one layer further out, in a cyber policy where the argument is rarely about whether a breach is covered and usually about which sublimit applies, a characterization fight that decides most claims well before a court sees them.

The dates to watch

The next four weeks resolve most of the open questions, and they resolve them on a schedule set in 2023 and 2022 rather than by anyone involved in this case.

October 7 is the outer edge of the FTC's 30-day clock if discovery began September 7. October 22 is the outer edge of Maryland's 45-day clock on the same assumption. Both dates move earlier if the company knew before the public post, which the forensics firm in its first statement suggests.

Before either date, the likelier signal is a database entry. A filing under the Safeguards Rule is meant to become public, and the entry carries the number of consumers affected or potentially affected. That number, entered by the company under a federal rule and published by the agency, would be the first version of this story that does not originate with Interlock.

Maryland adds a second checkpoint. If the number of affected Maryland residents crosses 1,000, the consumer reporting agencies have to be told, and that notice reaches the bureaus before most borrowers hear anything. A credit freeze placed early is worth more than one placed after a letter arrives.

The five suits will sort themselves out, probably into one consolidated action with a lead firm and a schedule. Nothing in that process will establish whether Interlock's terabytes were real. That question belongs to the forensics firm, the FTC filing, and eventually the Maryland Attorney General, in that order.

Primary sources

  1. National Mortgage News, Ransomware gang claims big hack at NFM Lending, September 24, 2026.
  2. DeXpose, Interlock Targets NFM Lending in a Major Ransomware Attack, September 7, 2026.
  3. Cybersecurity and Infrastructure Security Agency, StopRansomware: Interlock, AA25-203A, July 22, 2025.
  4. Federal Trade Commission, Safeguards Rule notification requirement now in effect, May 2024.
  5. Federal Trade Commission, FTC Amends Safeguards Rule to Require Non-Banking Financial Institutions to Report Data Security Breaches, October 27, 2023.
  6. Maryland General Assembly, Commercial Law Article, section 14-3504.
  7. Office of the Attorney General of Maryland, Guidelines for Businesses to Comply with the Maryland Personal Information Protection Act.
  8. Weekly Real Estate News, NFM Lending Faces Lawsuits After Alleged Ransomware Attack, September 22, 2026.