The Money Store, a mortgage lender based in Florham Park, New Jersey, may have experienced a cybersecurity incident after a cybercriminal group named the company on a dark web leak site. Mortgage lenders handle detailed financial and identity records for their borrowers, so any reported compromise of that information is a serious concern for anyone who has done business with the company.
The Money Store’s Data Breach Investigation
According to a posting reviewed on a dark web leak site, a cybercriminal group identifying itself as Storm claimed responsibility for a cybersecurity incident involving The Money Store. The claim was reportedly posted in September 2026, and it raised concerns that information belonging to the company’s borrowers may have been taken. As of this writing, The Money Store has not publicly confirmed the incident, and the categories of information potentially involved have not been disclosed.
Mortgage lenders are frequently targeted by cybercriminals because loan files typically consolidate a wide range of sensitive information in one place, including Social Security numbers, income and employment records, bank account details, and government-issued identification. When this kind of consolidated financial data is compromised, it can be used to commit identity theft, open fraudulent lines of credit, or file false loan applications in a victim’s name, making mortgage-lender breaches especially consequential for those affected.
Dark web leak site claims often surface before, or entirely in place of, a formal company notification, particularly while a forensic review is still underway to determine what, if anything, was actually accessed. Because The Money Store has not yet issued its own public statement, borrowers and former customers should not wait for an official notice before taking steps to protect their information, especially given how long compromised financial data can remain valuable to fraudsters even months after an initial claim surfaces.
Under most state data breach notification laws, once a company confirms that personal information was in fact compromised, it is typically required to notify affected individuals within a set window, though exact timelines vary by state and by the type of information involved. Until The Money Store confirms or denies the cybercriminal group’s claim, individuals connected to the company are encouraged to treat the leak site posting seriously and monitor their accounts proactively.
When Did This Breach Occur?
The cybercriminal group’s claim was reportedly posted to a dark web leak site in September 2026. The specific date of any underlying unauthorized access, if it in fact occurred, has not been publicly disclosed by The Money Store.
What Information Was Breached?
The Money Store has not publicly confirmed which categories of information may have been involved. The cybercriminal group’s leak site posting raised concerns that borrower information may have been taken, but the specific data types have not been independently verified.
What You Can Do
If you are a current or former customer of The Money Store, consider taking the following steps while this incident remains under investigation:
- Monitor your bank accounts, credit card statements, and credit reports closely for unauthorized activity
- Consider placing a fraud alert or credit freeze with the three major credit bureaus
- Be alert to phishing emails or calls referencing your mortgage or this incident
- Change passwords on any online accounts associated with The Money Store and enable two-factor authentication where available
- Keep any communications you receive from The Money Store about this incident for your records
File a Data Breach Lawsuit Against The Money Store
If a cybercriminal group’s claims are confirmed, The Money Store could face legal responsibility for failing to adequately protect the sensitive financial information entrusted to it by borrowers. Companies that collect and store personal and financial data have a legal obligation to maintain reasonable security safeguards, and a failure to do so can form the basis of a data breach lawsuit.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.