Cyber & AI intelligence
Wasteland.
Briefs indexed2597
Issues28
Published Mondays07:30 CT
█ Ransomware NFM-LENDING-INTERL 2026-09-14

NFM Lending: Interlock Ransomware Leak Site Claim

"On September 7, 2026, the Interlock ransomware operation added Maryland-based residential mortgage lender NFM Lending to its "Worldwide Secrets Blog" leak site, claiming to have exfiltrated more than 2.5 terabytes of…"

On September 7, 2026, the Interlock ransomware operation added Maryland-based residential mortgage lender NFM Lending to its "Worldwide Secrets Blog" leak site, claiming to have exfiltrated more than 2.5 terabytes of borrower and corporate data covering over one million clients. As of the most recent source updates on September 9, 2026, NFM Lending has not publicly confirmed the incident, filed a breach notification, or disputed the claim. Every figure in this brief originates with the threat actor or with dark web monitoring services that indexed the actor's post, and should be read accordingly.

What Happened

The listing was first observed on September 7. Undercode News, citing the ThreatMon Threat Intelligence Team, timestamps the victim addition at approximately 18:31:55 UTC+3 that day, alongside an unrelated Aurora ransomware listing for Jinny Beauty Supply. Ransomware.live picked up the same post, and it was independently cataloged by DeXpose and by Breach House, which recorded the victim as "leaked" with one leak site screenshot captured by its collector on September 7.

Breach House measures the gap between leak site publication and public disclosure at one day and still open, with the "disclosed / notified" field marked as pending. That is the operative fact here: the extortion post is the only account of the intrusion that exists. No dwell time, no initial access vector, no encryption impact, and no ransom demand figure has been reported for this specific incident by any source.

The sources also disagree on the victim's own profile. Interlock's extortion note describes NFM Lending as a national lender with over 1,000 employees that originated roughly $7.15 billion in mortgages over the preceding twelve months. Breach House's index lists the company in the 51 to 100 employee bracket. ClassAction.org and Rankiteo describe NFM as a Maryland-based residential mortgage lender licensed in 49 states. Extortion posts routinely inflate victim size to pressure payment, and automated leak indexes routinely carry stale firmographic data, so neither employee figure should be treated as established.

What Was Taken

Interlock's claim is unusually itemized. According to the threat actor statement reproduced by DeXpose, the exfiltrated set includes names, Social Security numbers, bank account details, credit information, loan terms, physical addresses, phone numbers, email addresses, borrower and loan identifiers, loan pricing, and itemized loan expense reports. The actor additionally claims to hold proprietary pricing and profit formulas, an extensive archive of tax forms, internal databases, and employee personal information.

Notably, the actor names the specific system of record: an Encompass database said to contain information on more than one million clients. Encompass is a widely deployed loan origination platform across the U.S. mortgage industry, and a compromise at that layer would place a borrower's full underwriting file, not merely a marketing record, in the attacker's hands.

On volume, the sources are consistent rather than conflicting: National Cyber Security Consulting, DeXpose, Class Action U, ClassAction.org, and Rankiteo all report "over 2.5 TB" and "over 1 million" clients, because all of them trace back to the same leak site post. The apparent corroboration is a single claim reflected across multiple indexes. Rankiteo's structured record assigns the event a severity score of 100 and an impact rating of 4, which is that vendor's own scoring output and not an independently verified measure of harm.

Interlock also frames the theft in regulatory terms, asserting violations of the Gramm-Leach-Bliley Act, the Fair Credit Reporting Act, state privacy statutes, and CFPB breach reporting rules. That language is a pressure tactic aimed at the victim's compliance exposure, and it is worth reading as part of the negotiation rather than as legal analysis.

Two plaintiff-side investigations were already underway within 48 hours. Class Action U and ClassAction.org both opened intake for current and former NFM Lending clients and employees, explicitly on the basis of the unconfirmed leak site claim.

Why It Matters

The strategic signal here is sector drift. Sophos, which tracks Interlock as GOLD EMBRACE, assesses that the group focuses on North American and European targets in critical infrastructure, healthcare, and education. A national mortgage lender does not sit in any of those buckets. If the NFM listing is genuine, it suggests either an opportunistic acquisition of access outside the group's usual targeting or a deliberate move toward financial services, where the per-record extortion leverage is substantially higher.

Mortgage originators are a uniquely dense target. A single loan file aggregates what a threat actor would otherwise need multiple breaches to assemble: Social Security number, income and employment verification, bank account and asset statements, credit report data, and property records, all retained for the life of the loan and often far beyond. The claimed theft of pricing and profit formulas adds a second dimension of competitive harm that has no consumer notification remedy.

There is also the silence itself. Breach House's one-day and counting exposure window is the practical measure of risk to borrowers: for as long as a victim neither confirms nor denies, affected individuals have no basis to freeze credit or watch for fraud. Interlock's business model depends on that silence being uncomfortable enough to convert.

One counterpoint worth recording: Breach House cross-referenced the victim against HaveIBeenRansom's dark web index and found zero hits in infostealer logs, traditional breaches, and ransomware leak corpora. That is an absence of corroborating data, not evidence against the claim, but it means no independently sourced NFM data has surfaced in the indexed underground as of September 7.

The Attack Technique

No source describes how Interlock entered NFM Lending. What follows is the group's documented tradecraft from the Sophos incident response reporting, offered as a hunting baseline rather than as an account of this intrusion.

Interlock emerged in September 2024 and operates as a small closed team that builds its own malware and runs its own intrusions, rather than as a ransomware-as-a-service affiliate program. It practices double extortion: steal first, encrypt second, then publish to the Worldwide Secrets Blog if payment does not arrive.

Documented tooling and techniques include ClickFix-style social engineering for initial access, a custom remote access trojan tracked as NodeSnake or Interlock RAT, and a PHP-based backdoor used for cross-platform persistence across both Windows and FreeBSD environments. Most relevant to current exposure, Sophos reports that Interlock has been actively exploiting CVE-2026-20131, a critical-severity zero-day in Cisco Secure Firewall Management Center software.

The novel detail from the March 2026 Sophos Emergency Incident Response engagement is the group's abuse of Volatility3, a legitimate open source memory forensics framework, on the Patient Zero host before responders arrived. That is living-off-the-land taken a step further: the attacker running defender tooling inside the victim environment, where its presence is plausible enough to survive a cursory look. Sophos also noted that the affected environment had endpoints running no protection at all, a gap that recurs in nearly every one of these cases.

What Organizations Should Do

Sources: Interlock Targets NFM Lending in a Major Ransomware Attack #ransom... | Interlock ransomware gang creates volatile situation SOPHOS | Interlock Targets NFM Lending in a Major Ransomware Attack - DeXpose | NFM Lending Data Breach Lawsuit - Class Action U | NFM Lending Data Breach? Attorneys Investigating Hackers' Claims | Interlock and Aurora Ransomware Strike Again: NFM Lending and Jinny... | NFM Lending: NFM LendingData Breach? | NFM Lending — INTERLOCK Ransomware Attack Breach House