Skip to content
Leak-site post naming theLender, captured by ThreatCluster

theLender

termite

Ransomware leak-site victim intelligence

Views
549
Posted
Sep 22, 2026
Country
United States
Industry
Wholesale mortgage

Summary

Written by ThreatClusterfrom site fields, victim profile, leak post, screenshot, our reporting

TERMITE claims theLender (thelender.com) was a ransomware victim; the leak page provides no information on what data was taken, whether anything was encrypted, or the scale of the impact. The leak post is published and includes an onion link for reference. ThreatCluster’s reporting notes that on September 21–22, 2026, TERMITE named theLender among victims, but the posts offer no details on attack methods or ransom demands, and the claims are not verified. Victim profile on the leak page lists thelender.com, United States, and wholesale mortgage as the sector.

Describes what the group claims on its leak site. A listing is not confirmation that a breach occurred.

Victim profile

Domains
thelender.com

What was taken

theLender was created to make a difference. As a group of proven industry leaders who recently founded one of the largest and fastest growing Wholesale mortgage companies in the United States, the company aims to change the stagnant landscape of Wholesale mortgage - one partnership, one loan, and one day at a time.

Also stated on the leak page

Fields this group publishes that do not map to a standard column. Labels are the site's own.

Extra info
http://y4bdg56uaznmbptf7dgp5xn3sjyyh4qodqjrsbziqatnyapmiqqctgid.onion/thelender/

Leak-site images (1)

Images from the victim's leak listing. Thumbnails scraped from the onion page are blurred by default — click a thumbnail to view.

ThreatCluster capture