2026 Plaza Home Mortgage — employee workstation breach exposed 137,976 borrowers
Data compromised
Names, addresses, SSNs, DOB, government IDs, mortgage application/servicing data; employee usernames/passwords for staff subset
Technical writeup
Plaza Home Mortgage, Inc. detected unauthorized access to an employee computer around February 17, 2026, discovered March 3, and began notifying affected individuals May 29, 2026. Regulator summaries cite 137,976 persons affected with names, addresses, Social Security numbers, dates of birth, government identification numbers, and mortgage loan application/servicing information; some employee credentials were also exposed. Plaza offered 12 months of CyEx credit monitoring. BreachHistory catalogs the company-confirmed incident; actor marketing claims are noted separately in trade press.
Root cause
Unauthorized access to one employee computer; illegal network access (discovered March 3, 2026)