Search Results: Cybersecurity

California Consent Order Highlights Cybersecurity Documentation and Vendor Oversight Risks for Mortgage Companies

In August 2026, the California Department of Financial Protection and Innovation (DFPI) announced that it had entered into a consent order with Academy Mortgage Corporation resolving findings arising from a March 2023 ransomware attack, which signaled that a mortgage company’s ability to document cybersecurity governance may matter as much as…

Read More

NY Department of Financial Services Announces $2 Million Settlement with Peer-to-Peer Payment Processor Over Data Breach

​On January 23, 2025, the New York Department of Financial Services​ announced that it had entered into a Consent Order​ with a Peer-to-Peer Payment Processor for alleged violations of New York’s Cybersecurity Regulation. This regulation requires all financial and banking entities operating in New York to establish and maintain adequate cybersecurity controls and protections…

Read More

New York Department of Financial Services Reaches $2,000,000 Settlement with Peer-to-Peer Payment Platform

On January 23, 2025, the New York Department of Financial Services (DFS) announced that it reached a $2,000,000 settlement as part of a broader consent order with a peer-to-peer payment platform (“P2P”) about its cybersecurity practices.  DFS contended that the P2P violated rules on Cybersecurity Policy, Cybersecurity Personnel and Intelligence,…

Read More

51 State Financial Regulatory Agencies Enter Settlement and Consent Order with Nonbank Mortgage Servicing Companies

​On January 9, 2025, 51 State Financial Regulatory Agencies (the “Agencies”) announced a coordinated consent order and settlement agreement with nonbank mor​tgage servicing companies (the “Companies”). This action came following a data breach that impacted 5.8 million customers, allegedly due to deficient cybersecurity practices, and for lack of cooperation with state regulators. The Companies are licensed as…

Read More