Were you recently affected by a data breach?

Affordable Mortgage Advisors Data Breach

Affordable Mortgage Advisors (HMA Mortgage) discovered unauthorized network access exposing customers’ names, Social Security numbers, passport numbers, financial account details, and health information. Affected individuals may be entitled to compensation.

Affordable Mortgage Advisors
Date of Breach: April 25, 2025 - May 15, 2025 (discovered May 16, 2025; notified February 20, 2026)
CAU logo

Who was affected:

Clients of Affordable Mortgage Advisors

Impacted Data:

Names, Social Security numbers, passport numbers, taxpayer identification numbers, digital signatures, biometric information, dates of birth, banking and financial account information, health insurance information, medical information

Affordable Mortgage Advisors, a Pittsburgh-based mortgage lending and financial services company operating under the trade name HMA Mortgage, has disclosed a data breach affecting current and former customers. The company recently notified affected individuals that an unauthorized party gained access to its computer network and may have viewed or taken files containing sensitive personal and financial information.

Companies that handle Social Security numbers, financial account details, and health information have a responsibility to keep that data secure, and when a breach occurs, those affected deserve a clear explanation of what happened and what they can do to protect themselves.

Affordable Mortgage Advisors’s Data Breach Investigation

Affordable Mortgage Advisors first learned of unauthorized activity on its network on or about May 16, 2025. The company launched an investigation with the help of outside cybersecurity professionals, who determined that an unauthorized actor had access to the network between approximately April 25, 2025, and May 15, 2025. During that window, certain files stored on the company’s systems may have been accessed or acquired.

Affordable Mortgage Advisors states that it took a comprehensive review to determine exactly whose information was affected and what data was involved, a process it completed on or about November 25, 2025. The company reported the incident to the Massachusetts Office of Consumer Affairs and Business Regulation on February 20, 2026, and began sending written notices to affected individuals shortly after. According to the notice, roughly 3,025 individuals were affected by the incident.

Mortgage lenders and financial services companies are frequent targets for cybercriminals because the loan origination process requires collecting an unusually complete profile of a borrower’s identity and finances in one place, including Social Security numbers, government identification, and bank account details. A single successful intrusion into that kind of system can expose everything an identity thief needs to open new accounts, file fraudulent tax returns, or take out loans in a victim’s name.

The gap of several months between when Affordable Mortgage Advisors first detected unauthorized access and when it finished determining which individuals and what data were affected is not unusual for incidents of this type. A thorough forensic review of a compromised network, especially one holding loan files with mixed categories of sensitive data, can take considerable time to complete accurately, and companies are generally expected to notify regulators and consumers once that review is complete rather than before the scope of the incident is fully understood.

Combinations of Social Security numbers, passport numbers, and financial account details are especially valuable to identity thieves because they can be used together to pass identity verification checks that a single stolen data point usually could not clear on its own. When digital signatures and biometric information are also included, as they reportedly were in this incident, the risk extends beyond simple account fraud, since that data can potentially be used to forge documents or bypass certain authentication systems that rely on those same identifiers. This is part of why companies handling loan applications are held to a high standard of care when storing this category of information.

The breach also reportedly compromised some individuals health insurance and medical information, which is protected under a separate set of state and federal privacy standards from purely financial data. Health-related records carry their own resale value on illicit marketplaces because they can be used to commit medical identity theft, including fraudulent insurance claims filed in a victim name, so affected individuals whose notice mentions health information should review their insurance explanation-of-benefits statements as carefully as their bank and credit card statements in the months following this notice.

Regulatory notification timelines for incidents like this are also often misunderstood by the public. Under Massachusetts law and similar statutes in other states, a company is generally expected to notify affected residents and the state Attorney General office as soon as practicable after determining the scope of a breach, but that determination itself can take months when a company must reconstruct exactly which files were accessed and cross-reference that against a large volume of loan records. A notification date that falls well after the initial discovery date does not necessarily indicate a company delayed unnecessarily, but affected individuals are still entitled to ask questions about why the process took as long as it did.

When Did This Breach Occur?

The unauthorized access to Affordable Mortgage Advisors’s network occurred between approximately April 25, 2025, and May 15, 2025, and was first discovered by the company on May 16, 2025. The company completed its review of which individuals and data were affected on November 25, 2025, and notified the Massachusetts Attorney General’s office on February 20, 2026.

What Information Was Breached?

The information potentially involved varies by individual but may include full names, Social Security numbers, passport numbers, taxpayer identification numbers, digital signatures, biometric information, dates of birth, and banking or other financial account information. For some individuals, the exposed files also included health insurance information and medical information.

What You Can Do

Affordable Mortgage Advisors is offering complimentary credit monitoring and identity theft protection services through Kroll to individuals affected by this incident. If you received a notice, consider taking the following steps:

  • Enroll in the complimentary credit monitoring and identity theft protection services offered in your notice letter before the stated deadline.
  • Place a fraud alert or security freeze on your credit files with Equifax, Experian, and TransUnion.
  • Request and review a free copy of your credit report at annualcreditreport.com for any accounts or inquiries you do not recognize.
  • Monitor your bank, credit card, and health insurance statements closely for unfamiliar activity.
  • Be cautious of unsolicited calls, emails, or texts referencing this breach, and never provide personal information to a party you cannot independently verify.

File a Data Breach Lawsuit Against Affordable Mortgage Advisors

If you received a notice that your personal information was exposed in the Affordable Mortgage Advisors data breach, you may have legal options available to you. Companies that collect sensitive financial and health data are expected to take reasonable steps to protect it, and when that trust is broken, affected individuals may be entitled to pursue compensation.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Between March 28, 2026, and April 12, 2026 (at vendor Ernst & Young LLP)
Date of Breach: On or about August 26, 2026
Date of Breach: On or about March 6, 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.