Were you recently affected by a data breach?

The Money Store Data Breach

A cybercriminal group known as Storm claimed in September 2026 to have obtained borrower information from The Money Store, a New Jersey mortgage lender, though the company has not publicly confirmed an incident.

The Money Store
Date of Breach: September 2026 (dark web claim date; underlying incident date not confirmed)
CAU logo

Who was affected:

Clients of The Money Store

Impacted Data:

Not publicly confirmed; a cybercriminal group claims to have obtained borrower information

The Money Store, a mortgage lender based in Florham Park, New Jersey, may have experienced a cybersecurity incident after a cybercriminal group named the company on a dark web leak site. Mortgage lenders handle detailed financial and identity records for their borrowers, so any reported compromise of that information is a serious concern for anyone who has done business with the company.

The Money Store’s Data Breach Investigation

According to a posting reviewed on a dark web leak site, a cybercriminal group identifying itself as Storm claimed responsibility for a cybersecurity incident involving The Money Store. The claim was reportedly posted in September 2026, and it raised concerns that information belonging to the company’s borrowers may have been taken. As of this writing, The Money Store has not publicly confirmed the incident, and the categories of information potentially involved have not been disclosed.

Mortgage lenders are frequently targeted by cybercriminals because loan files typically consolidate a wide range of sensitive information in one place, including Social Security numbers, income and employment records, bank account details, and government-issued identification. When this kind of consolidated financial data is compromised, it can be used to commit identity theft, open fraudulent lines of credit, or file false loan applications in a victim’s name, making mortgage-lender breaches especially consequential for those affected.

Dark web leak site claims often surface before, or entirely in place of, a formal company notification, particularly while a forensic review is still underway to determine what, if anything, was actually accessed. Because The Money Store has not yet issued its own public statement, borrowers and former customers should not wait for an official notice before taking steps to protect their information, especially given how long compromised financial data can remain valuable to fraudsters even months after an initial claim surfaces.

Under most state data breach notification laws, once a company confirms that personal information was in fact compromised, it is typically required to notify affected individuals within a set window, though exact timelines vary by state and by the type of information involved. Until The Money Store confirms or denies the cybercriminal group’s claim, individuals connected to the company are encouraged to treat the leak site posting seriously and monitor their accounts proactively.

When Did This Breach Occur?

The cybercriminal group’s claim was reportedly posted to a dark web leak site in September 2026. The specific date of any underlying unauthorized access, if it in fact occurred, has not been publicly disclosed by The Money Store.

What Information Was Breached?

The Money Store has not publicly confirmed which categories of information may have been involved. The cybercriminal group’s leak site posting raised concerns that borrower information may have been taken, but the specific data types have not been independently verified.

What You Can Do

If you are a current or former customer of The Money Store, consider taking the following steps while this incident remains under investigation:

  • Monitor your bank accounts, credit card statements, and credit reports closely for unauthorized activity
  • Consider placing a fraud alert or credit freeze with the three major credit bureaus
  • Be alert to phishing emails or calls referencing your mortgage or this incident
  • Change passwords on any online accounts associated with The Money Store and enable two-factor authentication where available
  • Keep any communications you receive from The Money Store about this incident for your records

File a Data Breach Lawsuit Against The Money Store

If a cybercriminal group’s claims are confirmed, The Money Store could face legal responsibility for failing to adequately protect the sensitive financial information entrusted to it by borrowers. Companies that collect and store personal and financial data have a legal obligation to maintain reasonable security safeguards, and a failure to do so can form the basis of a data breach lawsuit.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: September 2026 (dark web claim date; underlying incident date not confirmed)
Date of Breach: September 2026 (dark web claim date; underlying incident date not confirmed)
Date of Breach: Notification issued September 18, 2026 (exact breach date not disclosed)
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.