Skip to content
Leak-site post naming NFM Lending, captured by ThreatCluster

NFM Lending

interlock

Ransomware leak-site victim intelligence

Data size
2 560 GB
Posted
Sep 7, 2026
Country
US
Industry
Financial Services

Summary

Written by ThreatClusterfrom victim profile, leak post, our reporting

Interlock claims 2,560 GB of data from NFM Lending has been exposed. The leak states the exposed materials include sensitive personal customer information and proprietary pricing formulas, along with data from the Encompass database (containing information on more than 1 million clients) and internal databases, tax forms, and employees' personal information. The leak post is published. Victim is identified as NFM Lending (nfmlending.com).

Describes what the group claims on its leak site. A listing is not confirmation that a breach occurred.

What was taken

NFM Lending is a national mortgage lender with over 1,000 employees that originated approximately $7.15 billion in mortgages in the past 12 months. The data breach exposed over 2.5 TB of sensitive personal customer information (names, Social Security numbers, bank accounts, credit information, loan terms, addresses, phone numbers, email addresses, borrower and loan identifiers, loan pricing, and itemized loan expense reports), as well as proprietary pricing/profit formulas, in violation of federal GLBA/FCRA, state privacy laws, and the CFPB's data breach reporting rules. You also have access to data from the Encompass database, which contains information on more than 1 million clients, as well as internal databases, an extensive database of tax forms, and employees' personal information.

Leak-site images (1)

Images from the victim's leak listing. Thumbnails scraped from the onion page are blurred by default — click a thumbnail to view.

ThreatCluster capture