Gold Star Mortgage Sued Following Data Breach

A federal class action lawsuit claims the Ann Arbor-based firm failed to secure sensitive consumer documents.

Updated on Sept. 28, 2026 in Cybersecurity

Gold Star Mortgage Sued Following Data Breach

Live Poll

Do you trust mortgage lenders to adequately protect your personally identifiable information?

A consumer has filed a class action complaint against Ann Arbor-based Gold Star Mortgage, alleging negligence in protecting customer data. The ransomware group BrainCipher allegedly exfiltrated 10.5 gigabytes of files, including Social Security numbers and tax documents.

Why it matters

The lawsuit centers on claims that the firm failed to protect personally identifiable information after the ransomware group BrainCipher reportedly accessed and posted internal files. This action underscores the growing legal liability for financial institutions facing cyberattacks.

The breach reportedly involved 10.5 gigabytes of data encompassing over 10,300 distinct documents. Gold Star Mortgage currently manages 318 sponsored mortgage loan originators across 51 branches.

The players

Gold Star Mortgage

This Ann Arbor-based mortgage lender originated over $2 billion in volume during the previous year.

BrainCipher

This criminal organization specializes in ransomware attacks and data exfiltration.

The details

The complaint alleges that Gold Star Mortgage failed to implement adequate security measures to prevent the unauthorized exfiltration of sensitive records like credit reports and Social Security numbers. BrainCipher reportedly publicized screenshots of the stolen data on a website to confirm the breach.

Timeline

  1. A consumer filed the class action lawsuit against Gold Star Mortgage last week.

  2. Three mortgage companies announced separate cyber incidents in September 2026.

  3. Real estate firms agreed to pay millions in settlements in Summer 2026.

  4. Union Home Mortgage disclosed a ransom payment in Summer 2025.

  5. Flagstar paid a $1 million ransom in 2021.

The Tech Race

This litigation follows a pattern of legal accountability established by recent industry settlements involving hundreds of thousands of class members. It highlights the escalating security arms race as mortgage firms struggle to protect massive data sets against persistent ransomware groups.

Customers of the firm may be at increased risk of identity theft due to the exposure of Social Security numbers and credit reports. Affected individuals should monitor their financial accounts and credit monitoring services for suspicious activity.

The takeaway

The increased frequency of cyber incidents in the mortgage sector suggests that firms must prioritize data hardening to avoid costly class action litigation. Consumers should proactively freeze their credit reports if they have recently applied for loans with smaller, branch-based lenders.

Further reading

For more information on current digital threats, visit Cybersecurity.

Source note: This article includes information reported by National Mortgage News.

Live Poll

Do you trust mortgage lenders to adequately protect your personally identifiable information?