Subscribe To Our Newsletter

This field is for validation purposes and should be left unchanged.

Academy Mortgage Reaches $1.995M Data Breach Settlement Over Sensitive Customer Data Security Incident

Academy Mortgage has agreed to a $1.995M data breach settlement covering 285,000 consumers whose Social Security numbers and personal data were exposed. Learn if you qualify and what you can claim.

large-field-of-ripe-wheat-under-the-open-sky-on-a-2025-02-12-05-09-11-utc 1

Roughly 285,000 consumers whose sensitive personal information was compromised during a March 2023 cyberattack against Academy Mortgage Corporation may soon be eligible for cash payments and credit monitoring services. Plaintiffs in a consolidated class action lawsuit filed an unopposed motion for preliminary approval of a $1.995 million settlement in the U.S. District Court for the District of Utah.

What You Need to Know About the Academy Mortgage Cyberattack

In March 2023, Utah-based Academy Mortgage Corporation discovered unauthorized access to its internal computer network. Following an investigation, the mortgage lender confirmed that an unauthorized third party had accessed files containing highly sensitive customer and employee data.

The compromised information included full names, Social Security numbers, dates of birth, financial account details, and mortgage application materials. The ransomware gang known as BlackCat/Alphv claimed responsibility for the breach, threatening to release the stolen records on the dark web after demanding a ransom payment.

Affected individuals were not notified of the incident until December 2023, roughly nine months after the initial intrusion was detected. Following these notifications, multiple affected consumers filed class action lawsuits in January 2024, alleging that the lender failed to implement reasonable cybersecurity safeguards to protect their data. The lawsuits were subsequently consolidated in federal court in Utah.

Allegations Against Academy Mortgage and Legal Claims

The operative class action complaint alleged several legal claims against Academy Mortgage Corporation, including negligence, breach of implied contract, invasion of privacy, unjust enrichment, and violations of various state consumer protection laws.

Plaintiffs alleged that Academy Mortgage had a legal duty to protect the personally identifiable information (PII) entrusted to it by home loan applicants and employees. The lawsuit claimed that the company maintained weak digital defenses, failed to detect the unauthorized intrusion in a timely manner, and delayed notifying impacted individuals, exposing them to an ongoing risk of identity theft, fraud, and financial harm.

While Academy Mortgage moved to dismiss the claims, the court allowed the majority of the lawsuit to proceed, prompting the parties to negotiate a resolution to avoid prolonged litigation. Under the terms of the settlement agreement, Academy Mortgage does not admit to any wrongdoing or liability.

Key Settlement Benefits: What Affected Consumers Can Receive

The proposed $1.995 million settlement fund will be used to provide compensation, credit protection, and administrative relief to class members. If preliminarily and finally approved by the court, eligible individuals who submit valid claims may receive:

  • Out-of-Pocket Loss Reimbursement: Class members can claim up to $3,000 for documented out-of-pocket expenses directly tied to the data breach. This includes costs such as fraudulent charges, bank fees, credit freeze fees, and professional identity restoration services.

  • Pro Rata Cash Payouts: Remaining funds after administrative expenses, service awards, and out-of-pocket claims are paid will be distributed as pro rata cash payments to class members who submit valid claims.

  • Enhanced Payments for California Residents: California class members will receive a stepped-up pro rata payment to address statutory damages claims under California privacy legislation, including the California Consumer Privacy Act (CCPA).

  • Credit Monitoring and Insurance: All class members are eligible to enroll in three years of free one-bureau credit monitoring. This benefit includes dark web monitoring, up to $1 million in identity theft insurance, and fully managed identity recovery services.

In addition to financial compensation, the settlement agreement mandates that Academy Mortgage implement structural business practice changes to enhance its data security protocols going forward.

Who Is Eligible to File a Claim in the Settlement?

You may be eligible to participate in this settlement if you were sent a formal written notice from Academy Mortgage Corporation informing you that your personal information was potentially exposed in the March 2023 data breach.

The settlement class encompasses approximately 285,000 individuals nationwide. When the settlement administrator receives preliminary approval from the court, official notices detailing claim submission instructions, deadlines, and unique claim forms will be distributed by mail or email to all identified class members.

How Consumer Protection Laws Apply to Mortgage Data Breaches

Financial institutions and mortgage lenders collect some of the most sensitive personal data in existence, from tax documents and bank account details to Social Security numbers. State consumer protection laws and data privacy statutes—such as the CCPA—require companies handling sensitive PII to implement reasonable security measures.

When companies fail to safeguard consumer records, affected individuals face an increased risk of identity theft and financial fraud. Class action lawsuits serve as an important tool for everyday people to hold corporations accountable for security failures and recover compensation for lost time and out-of-pocket expenses.

Subscribe To Our Newsletter

New cases and investigations, settlement deadlines, and news straight to your inbox.

This field is for validation purposes and should be left unchanged.
The Time for Action is Now!
Mass Arbitrations
Active Data Breaches
Date of Breach: Unauthorized network access identified August 28, 2026; disclosed in an SEC Form 8-K filed September 1, 2026
Date of Breach: Reported to HHS Office for Civil Rights on August 14, 2026
Date of Breach: April 13, 2026 (Akira ransomware claim); breach notice filed with Vermont Attorney General September 1, 2026
Latest News