California penalizes Academy Mortgage over 2023 data breach
California’s Department of Financial Protection and Innovation (DFPI) has fined Academy Mortgage $825,000 and criticized the lender’s deficient cybersecurity and governance practices after a 2023 breach exposed the personal data of 284,443 people, including 34,452 Californians. As part of a consent order, Academy must also provide 12 months of free identity-theft insurance to affected individuals. The company has since exited loan originations and servicing.
“Companies that have access to our personal information must have robust, stringent cybersecurity,” DFPI Commissioner KC Mohseni said, adding, “This penalty should act as a deterrent to companies — strong data protection for Californians is non-negotiable.”
DFPI fine and consumer relief
- Penalty: $825,000 paid to DFPI under a consent order.
- Consumer support: 12 months of complimentary identity-theft insurance for those affected.
- Scope of impact: 284,443 individuals’ data at risk nationwide; 34,452 of them in California.
The consent order does not include an admission or denial of DFPI’s findings. Attorneys representing Academy’s parent company did not respond to requests for comment, and a Guild Mortgage spokesperson declined to comment.
How the 2023 intrusion unfolded
According to the consent order, hackers infiltrated Academy’s network in mid-March 2023, deploying malware and stealing credentials used to disable security tools. The breach was contained within about a week. The ransomware group AlphV/BlackCat later claimed responsibility.
Academy commissioned an initial third-party investigation in the two months after the incident and conducted additional internal review in the fourth quarter of 2023. Despite that, customer notifications did not begin until December 2023, prompting lawsuits that accused the Draper, Utah-based company of delaying disclosures.
Regulators detail sweeping cybersecurity breakdowns
DFPI examiners said Academy’s shortcomings in information security, recordkeeping, and governance left it vulnerable to the 2023 attack. Among the findings cited in the consent order:
- No documented, up-to-date asset inventory of systems and data.
- No current incident-response plan.
- No documentation for tracking audit findings or follow-up.
- Missing written IT policies and procedures across multiple areas.
- No comprehensive, formal audit of the information security program from 2017 to 2023.
- Insufficient security risk assessments in the two years leading up to the breach.
- Deficient vulnerability and patch management practices.
Governance and documentation lapses
DFPI also faulted Academy’s board for weak oversight of business operations and security planning. While Academy told the department it followed appropriate day-to-day security practices, examiners said those practices were not documented in policies and procedures. Recordkeeping gaps were so extensive that regulators could not determine whether the company complied with certain California mortgage regulations.
On the breach itself, DFPI said Academy failed to obtain a written forensic report, limiting transparency into the incident’s scope and root causes.
Aftermath: asset sale to Guild, operations halted
In late February 2024—days before DFPI began its examination—Academy sold its retail lending operations to Guild Mortgage. The company stopped originating new mortgages in March 2024. The consent order resolving the enforcement action was finalized with no admission or denial of DFPI’s conclusions.
California’s enforcement muscle grows as federal posture loosens
The Academy case underscores how state regulators, led by California, are increasingly driving consumer protection and cybersecurity enforcement as federal scrutiny fluctuates. California’s outsized market and aggressive oversight make it a focal point for lenders and their counsel.
- In 2025, California was among several states that reached a settlement with E Mortgage Capital over alleged unlicensed lending activity.
- Earlier this year, Fairway Home Mortgage resolved a similar case with DFPI.
- In July, Gov. Gavin Newsom appointed former Consumer Financial Protection Bureau Director Rohit Chopra to serve as secretary of the state’s newly created business and consumer services agency—signaling continued emphasis on consumer protection.
Why it matters
For mortgage lenders and servicers, DFPI’s findings read like a checklist of what not to neglect: asset inventories, incident-response plans, policy documentation, risk assessments, vulnerability management, and board-level oversight. The order reinforces that regulators expect both effective day-to-day security operations and rigorous, provable governance—complete with documentation and independent assessments.
For consumers, the case highlights the lengthy timelines that can accompany breach investigations and notifications, and the importance of promptly using offered protections when available.