Summary
Written by ThreatClusterfrom site fields, victim profile, leak post, screenshot, our reportingTERMITE claims theLender (thelender.com) was a ransomware victim; the leak page provides no information on what data was taken, whether anything was encrypted, or the scale of the impact. The leak post is published and includes an onion link for reference. ThreatCluster’s reporting notes that on September 21–22, 2026, TERMITE named theLender among victims, but the posts offer no details on attack methods or ransom demands, and the claims are not verified. Victim profile on the leak page lists thelender.com, United States, and wholesale mortgage as the sector.
Describes what the group claims on its leak site. A listing is not confirmation that a breach occurred.
Victim profile
- Domains
- thelender.com
What was taken
theLender was created to make a difference. As a group of proven industry leaders who recently founded one of the largest and fastest growing Wholesale mortgage companies in the United States, the company aims to change the stagnant landscape of Wholesale mortgage - one partnership, one loan, and one day at a time.
Also stated on the leak page
Fields this group publishes that do not map to a standard column. Labels are the site's own.
- Extra info
- http://y4bdg56uaznmbptf7dgp5xn3sjyyh4qodqjrsbziqatnyapmiqqctgid.onion/thelender/
Leak-site images (1)
Images from the victim's leak listing. Thumbnails scraped from the onion page are blurred by default — click a thumbnail to view.