51 State Financial Regulatory Agencies Enter Settlement and Consent Order with Nonbank Mortgage Servicing Companies

Goodwin
Contact

Goodwin

​On January 9, 2025, 51 State Financial Regulatory Agencies (the “Agencies”) announced a coordinated consent order and settlement agreement with nonbank mor​tgage servicing companies (the “Companies”). This action came following a data breach that impacted 5.8 million customers, allegedly due to deficient cybersecurity practices, and for lack of cooperation with state regulators.

The Companies are licensed as mortgage brokers, lenders, and/or servicers under the laws of each participating state. On October 11, 2021, a cybersecurity breach occurred which compromised the personal information of an estimated 5.8 million customers. The Agencies allege that deficient IT and cybersecurity practices were identified in contravention of federal and state-specific compliance laws and regulations. For example, they allege that the Companies ​had deficient IT patch management and deficient centralized IT vulnerability remediation monitoring and enterprise monitoring, among other issues. They also claim that the Companies did not fully comply with the examination authority of the Agencies.

The parties agreed that the Companies’ corporate governance frameworks related to the IT and cybersecurity programs will be monitored and consumer remediation efforts will continue. The Companies will also pay an administrative penalty of $19,629,400 to be prorated among each participating state, as well as administrative costs.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations. Attorney Advertising.

© Goodwin

Written by:

Goodwin
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Goodwin on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide