Affordable Mortgage Advisors LLC, the Pittsburgh lender that markets itself as HMA Mortgage, told state regulators that strangers sat inside its computer systems for more than two months in 2025 — and that the files they could reach look like a mortgage closing packet: names, addresses, Social Security numbers, and financial account details. Massachusetts received the company’s disclosure on September 18, 2026; late-September reporting tied to Texas and multi-state filings puts the nationwide headcount at roughly 3,025 people, including about 957 Texas residents. Canonical record: hma-mortgage2026.
This is a verified HMA Mortgage data breach, not a leak-site rumor. The attestation chain runs through regulator-facing notices summarized by Claim Depot, the Massachusetts OCABR filing (2026-1581), and a September 22 class-action investigation announcement from Edelson Lechtzin LLP on PR Newswire. If you applied for a purchase or refinance loan through HMA, assume your Social Security number may be in play until you read your own letter.
What happened in the Affordable Mortgage Advisors breach
According to those public accounts, an unauthorized party accessed Affordable Mortgage Advisors’ systems between approximately July 7, 2025 and September 9, 2025. The company says it discovered the incident on or about August 25, 2025, retained outside cybersecurity help, and eventually completed a file-by-file review of what might have been touched. That review finished on August 21, 2026 — more than a year after the initial discovery date the notices cite.
The gap between “we saw something wrong” and “we know whose SSN is in the set” is the part borrowers feel in their gut. Attackers who reach a mortgage shop rarely need ransomware branding; they need read access to loan origination folders long enough to copy W-2s, bank statements, and 1003 applications. HMA has not, in the sources BreachHistory indexed, named a threat group, published a CVE, or described phishing versus stolen VPN credentials. What is confirmed is simpler and worse for consumers: prolonged unauthorized access to systems that store mortgage borrower data.
Regulators began receiving the disclosure package in mid-September 2026. Claim Depot’s breach summary lists filings or references across multiple state attorneys general — Texas, Massachusetts, and others — plus a consumer notification letter hosted on its site. Edelson Lechtzin’s release notes at least one Massachusetts resident in the early regulatory picture and 957 Texas residents in Texas Data Security Breach reporting, while aggregators cite roughly 3,025 individuals nationally once other states’ counts are rolled up.
No ransomware gang has claimed HMA on a public leak tracker in the materials used for this write-up. That absence does not mean the data stayed on the attacker’s laptop. It means the company’s story is a classic unauthorized-access disclosure, not an extortion countdown posted on the clear web.
Timeline: access window, discovery, and 2026 notices
- July 7, 2025 — Start of the unauthorized access window described in state-facing disclosures.
- September 9, 2025 — End of that access window; intruders could reach information stored on company systems during this period.
- August 25, 2025 — Affordable Mortgage Advisors reportedly discovers the incident (per Claim Depot and Edelson Lechtzin summaries).
- August 21, 2026 — Company completes its comprehensive review of affected data types and individuals (same sources).
- September 18, 2026 — Disclosure to the Massachusetts Office of Consumer Affairs and Business Regulation (OCABR).
- September 21–22, 2026 — Claim Depot publishes field-level detail; Edelson Lechtzin announces a class-action investigation.
Read that timeline twice. The access window spans summer 2025, yet the individualized review completion date sits in late summer 2026. Consumer lawyers will argue about whether state notification deadlines were met; borrowers should not wait for litigation to protect credit files. If your loan was in processing during July–September 2025, you are squarely in the risk window the company describes.
What data was exposed
Investigation summaries agree on a core set of fields. Claim Depot quotes Affordable Mortgage Advisors as confirming exposure of:
- Names
- Addresses
- Social Security numbers
- Financial account information, including credit and debit card numbers
That is already enough for identity takeover, synthetic identity fraud, and card-not-present abuse. Mortgage files often contain more than the minimum a state AG table lists — pay stubs, tax transcripts, government ID numbers, and asset statements are normal in underwriting. Claim Depot’s breach page also tags dates of birth, government IDs, and medical information as information types associated with the incident; treat those as categories that may appear on some loan files unless your notification letter narrows the list. Edelson Lechtzin’s investigation release sticks to the same core four categories in its “at a glance” section.
For a mortgage borrower, the dangerous combination is not any single field. It is Social Security numbers plus address history plus bank or card numbers — the same triad criminals use to open accounts, change mailing addresses on existing credit, or impersonate you during closing.
What was not confirmed publicly
HMA’s public regulatory summaries do not, in the indexed sources, specify whether full loan documents (PDF scans of driver’s licenses, appraisal photos, or signed notes) were exfiltrated versus viewed in place. They also do not break out employees versus customers, co-borrowers versus guarantors, or applicants who withdrew before funding. If you co-signed for a family member’s HMA loan, you may still be in scope if your data lived in their file.
The company has not stated that passwords to HMA’s consumer portal were compromised, and none of the primary summaries emphasize online-account credentials. Do not treat that as a clean bill of health for reused passwords — rotate them anyway if you ever registered on hmamortgage.com.
How the attack worked — what we know and what we do not
Affordable Mortgage Advisors describes unauthorized individuals gaining access to its computer systems. That is the entire technical sentence in the consumer-facing chain so far. There is no Mandiant report appendix, no CISA advisory, no “we forgot to patch Citrix” footnote in the Massachusetts PDF summary available to reporters.
Mortgage lenders of HMA’s size typically run a loan origination system, document imaging, email, and maybe a CRM for realtor referrals — often a mix of on-prem Windows servers and SaaS vendors. Without a vendor name, security teams cannot tell whether this was identity theft of a loan officer’s login, exploitation of a remote access appliance, or a supply-chain compromise at a document host. All three patterns have hit peer lenders in 2026.
What you can infer safely from the dates: the actor had persistence or repeated entry across roughly nine weeks. That favors stolen credentials or an unremoved web shell over a one-day smash-and-grab. Longer dwell time also increases the odds that outbound data collection happened quietly — the scenario where no ransomware note ever appears.
Who is at risk
Current and former HMA Mortgage customers. Anyone who financed or refinanced through Affordable Mortgage Advisors and whose file was active or archived on the affected systems during 2025 should read a breach letter carefully. “Former” matters: paid-off loans do not erase underwriting PDFs.
Co-borrowers, spouses, and non-borrowing spouses on title. Mortgage applications routinely carry multiple SSNs. If you signed a 1003 but were not the primary contact, you may still receive a separate notice — or you may not, even though your SSN is in the folder. If a household member got HMA mail, assume the whole household is in play.
Applicants who never closed. Lenders often retain credit pulls and bank statements for declined or withdrawn files. If you shopped rates with HMA in mid-2025 and walked away, check whether a notice arrives before assuming you escaped the census.
Texas residents in the first wave of counts. Texas AG reporting surfaced early with 957 residents; national aggregators cite ~3,025. Other states listed on Claim Depot — California, Iowa, Maine, Montana, Nebraska, New Hampshire, Oregon, Rhode Island, South Carolina, Vermont, Washington — suggest a multi-state borrower footprint typical of a retail lender licensed beyond Pennsylvania.
Wire fraud and phishing after a mortgage breach
Mortgage borrowers are prime targets for wire fraud phishing even when no breach occurs. After an incident like this, the scripts get sharper: “Your closing wire instructions changed — here is the updated PDF,” or “HMA underwriting needs you to re-verify your bank account before funding.”
Real lenders do not change wiring instructions by email alone. If you are in an active HMA pipeline today, call your loan officer using the number on hmamortgage.com or your original engagement letter — not a number in an unexpected text. If you closed in 2025, watch for “escrow refund” or “overpayment return” messages that ask for routing numbers; those are classic post-breach social engineering plays that reuse leaked financial fields.
Also expect IRS impersonation and credit-repair spam. A stolen SSN plus DOB (if present in your file) is enough to attempt tax refund fraud next January. File early if you are eligible, and create an IRS Identity Protection PIN if you qualify.
What HMA Mortgage says it is offering
Claim Depot summarizes Affordable Mortgage Advisors’ response as:
- Single-bureau credit monitoring, fraud consultation, and identity theft restoration through Kroll
- A dedicated toll-free response line during Central Time business hours (excluding some U.S. holidays)
- Notification letter language on placing security freezes with Equifax, Experian, and TransUnion
Single-bureau monitoring is better than nothing, but it is not full tri-bureau coverage. If your letter includes enrollment codes, use them — and still place freezes or fraud alerts yourself if you want uniform protection. Freezes stop most new account fraud; monitoring tells you after someone might have already opened an account.
Preserve the physical letter or PDF. Class-action investigators — including Edelson Lechtzin — will ask for it. That is separate from the Kroll benefit; do not discard the envelope because you think “the lawyers will email me.”
Regulators, litigation, and the ~3,025 headcount
The Massachusetts OCABR document (2026-1581) anchors the East Coast regulatory record. Texas provides the first hard subset number — 957 residents — via its Data Security Breach portal, which Claim Depot links directly. Rolling those state filings into a national figure yields about 3,025 people in late-September 2026 reporting cited on BreachHistory’s catalog row.
Edelson Lechtzin’s September 22 PR Newswire release states plainly that certain details — “true scope,” per-person data mixes, and the nationwide count — “have not been fully confirmed publicly” even while investigations proceed. That is lawyer language, not a denial. It is a reminder that state AG tables can lag and that your individual letter remains the best inventory of your fields.
Claim Depot exists to connect people with settlement news; Edelson Lechtzin is investigating fee-shifting class claims. Neither replaces the company notice for determining whether your SSN was involved. Use them as secondary context.
Mortgage sector context in 2026
Retail and wholesale lenders have been under sustained pressure this year. Verified incidents in the same neighborhood as HMA include OneMain Financial’s May 2026 network intrusion, which exposed names, addresses, and SSNs for more than 16,000 people in early state filings — another mid-market consumer finance story with a long gap between intrusion and September notifications. On the mortgage-specific side, Plaza Home Mortgage and other lenders appear repeatedly in state breach lists as the industry digitizes more of the closing table.
Unverified ransomware marketing has also targeted mortgage brands — for example the BrainCipher listing against Gold Star Mortgage, which remained an actor claim without a matching company notice at indexing time. HMA’s disclosure path is the opposite pattern: no public extortion site narrative, but a sober regulator filing and SSN-heavy field list.
For readers comparing fintech outages to lender file theft, the April Chime outage and hack-claim cycle shows how quickly mobile banking customers mobilize around class actions — a dynamic Edelson Lechtzin is now mirroring for mortgage borrowers who never expected their 1003 to become court exhibit A.
Was I affected? How to check
Start with your mail and email for “Affordable Mortgage Advisors,” “HMA Mortgage,” or “Kroll” branding. The notification is the authoritative yes/no for your household, even if you do not appear in early Texas counts.
If you believe you had a 2025 relationship with HMA but receive nothing by late October 2026, call the toll-free line referenced in Claim Depot’s summary (use only the number printed on a legitimate company letter or hmamortgage.com — not a number from a random search ad). Ask whether your loan number or application ID was in scope.
Pull free credit reports at annualcreditreport.com and look for inquiries or accounts you do not recognize. A freeze will not remove old fraud; it prevents most new tradelines.
What you should do now
- Place a credit freeze (or fraud alert if you prefer less friction) at Equifax, Experian, and TransUnion. A credit freeze is free under federal law; store your PINs where you will not lose them before refi shopping.
- Enroll in Kroll if your letter provides an activation code — then decide whether you also want supplemental monitoring elsewhere for the other two bureaus.
- Turn on transaction alerts on checking and card accounts tied to your mortgage application, even if you already closed the loan.
- Verify wires out-of-band for any active closing; tell family co-borrowers to do the same.
- File taxes early next season if your SSN was exposed; consider an IRS IP PIN.
- Report phishing that cites HMA, Kroll, or “mortgage compliance” to the FTC at ReportFraud.ftc.gov and to your state AG consumer division.
- Keep documentation of time spent freezing credit, disputing accounts, or calling banks — class-action economics often turn on documented consumer loss.
None of that requires waiting for a final court ruling. The access window already happened; your defense is forward-looking.
Questions HMA has not answered in public filings
Security researchers and affected borrowers will reasonably ask:
- Which systems were reachable — LOS, email, document store, or all three?
- Was access read-only or did the actor create accounts or scheduled tasks?
- Did the company notify law enforcement, and was there a ransom demand?
- Why did the individualized review run from August 2025 discovery to August 2026 completion in public summaries?
- Will tri-bureau monitoring or identity theft insurance be upgraded beyond single-bureau Kroll?
Until HMA or a regulator publishes more detail, treat those as open items — not as excuses to delay a freeze.
Canonical record and sources
BreachHistory catalog entry: https://breachhistory.com/hma-mortgage/hma-mortgage2026
Primary and secondary sources used for this article:
- Massachusetts OCABR — Affordable Mortgage Advisors disclosure (2026-1581)
- Claim Depot — HMA Mortgage / Affordable Mortgage Advisors summary
- PR Newswire — Edelson Lechtzin LLP investigation announcement (Sept. 22, 2026)
- Texas Attorney General Data Security Breach reporting (957 residents — linked via Claim Depot)
If you are comparing other 2026 financial incidents, see related coverage on property-management notices, credit-union phishing exposure, and fintech CRM targeting — different attack shapes, same consumer homework: freeze credit, verify outbound money movement, and treat your SSN as already in a broker’s spreadsheet until proven otherwise.