← SitusAMC

2025 SitusAMC — non-ransomware exfiltration; bank clients notified (JPMorgan, Citi, Morgan Stanley)

2025 Unknown records affected Share on X

Data compromised

Mortgage and loan servicing documents, SSNs and financial fields per breach notifications

Technical writeup

On November 12, 2025, mortgage-technology and loan-servicing vendor SitusAMC disclosed a cyberattack characterized in company and press narratives as data exfiltration without ransomware encryption. Coverage (CSO Online, Cybersecurity Dive, Reuters via NYT, FINRA alert) described accounting records, legal agreements, and sensitive customer files tied to mortgage workflows, with major U.S. banks including JPMorgan Chase, Citigroup, and Morgan Stanley assessing downstream client exposure. FBI investigation was noted publicly.

Root cause

Unauthorized access to vendor file and collaboration systems; simple file-share path cited in some reporting

References