Ransomware Group Interlock Claims Attack on NFM Lending

A ransomware group calling itself Interlock claims to have carried out an attack on NFM Lending, with the claim dated September 7, 2026. This claim comes from the group’s own leak-site listing, which is tracked by ransomware.live, a security research platform that monitors ransomware groups’ public leak sites. At this time, the claim is unverified — NFM Lending has not confirmed any incident, and no regulator has issued a statement regarding this matter.

What we know — and don’t
  • A group identifying itself as Interlock listed NFM Lending on its leak site, with a claimed date of September 7, 2026.
  • NFM Lending operates in the finance sector, specifically in mortgage lending.
  • The specific data types the group claims to have obtained have not been disclosed or confirmed by any party.
  • NFM Lending has not issued a public statement confirming or denying the claim as of this writing.
  • No regulatory filing or breach notification related to this claim has been identified.
What should you do if you have an account with this company?
  • Change your NFM Lending account password, and avoid reusing that password on any other site.
  • Enable two-factor authentication on your account if it is available and not already active.
  • Be cautious of unexpected emails, texts, or calls claiming to be from NFM Lending, especially any asking for personal or financial information.
  • Monitor your bank and credit card statements for unfamiliar activity in the coming weeks.
  • Consider placing a fraud alert or credit freeze with the major credit bureaus if you are concerned about identity theft.
  • Because mortgage-related accounts often involve sensitive personal and financial details, using a service like a service like Aura or LifeLock to monitor for signs of identity misuse can add an extra layer of protection.

BreachLetter will update this page if NFM Lending confirms this incident or if it is officially reported to regulators.

Leave a Comment