Go to Wolters Kluwer VitalLaw.comGo to Wolters Kluwer VitalLaw.com
VitalLaw®
  • Find answers to your questions
  • Log in to access your subscriptions
In depth. On point.
In depth. On point.
  • Home
  • Legal Directory
  • Home
  • Legal Directory
In depth. On point.
  • Articles
  • Articles
  • Organizations
  • Organizations
    • Bipartisan Senate Bill Seeks to Help Electric Grid Withstand Quantum-Powered Hacks
    • Academy Mortgage to pay $825,000 over 2023 cybersecurity failures
    • Airlines’ Use of Surveillance Pricing Probed by Rep. Pallone
    • House Bill Would Renew Grant Program for Water System Cybersecurity
    • Legislation to Expand Consumers’ Privacy Rights Advances in California
    • Recommendations for Personal Information Protection Measures Offered in China
    • Senate Committee Advances Children’s Privacy Bill in California
    • State Coalition Sues to Stop Feds From Collecting Commercial Driver Information
  • Articles
  • Articles
  • Organizations
  • Organizations

    Cybersecurity Policy Report, Academy Mortgage to pay $825,000 over 2023 cybersecurity failures, (Aug 14, 2026)

    By Shashi Kant, BALLB, LLM.

    California’s DFPI fined Academy Mortgage $825,000 over a 2023 ransomware breach, citing cybersecurity and recordkeeping deficiencies that predated the attack.

    The California Department of Financial Protection and Innovation (DFPI) has ordered A ...

    By Shashi Kant, BALLB, LLM.

    California’s DFPI fined Academy Mortgage $825,000 over a 2023 ransomware breach, citing cybersecurity and recordkeeping deficiencies that predated the attack.

    The California Department of Financial Protection and Innovation (DFPI) has ordered Academy Mortgage Corporation to pay an $825,000 administrative penalty and to provide identity theft insurance to California borrowers affected by a March 2023 ransomware attack, after an examination the department says found serious, longstanding cybersecurity and recordkeeping deficiencies at the Utah-based residential mortgage lender and servicer. The consent order was signed by Academy on August 7, 2026, and on August 10, 2026, for Commissioner Khalil Mohseni by Deputy Commissioner Mary Ann Smith, and DFPI announced the action on August 13.

    The data breach. The consent order states that a cyber threat actor breached Academy’s corporate network on Saturday, March 18, 2023, installed malware, stole employee login credentials and used them to disable network security systems, before initiating a ransomware attack on March 20. Academy retained a third-party cybersecurity consultant on March 22, the breach was contained by March 25, and operations were restored within approximately one week, though lending was disrupted for multiple days. The threat actor accessed systems storing personally identifiable information belonging to 284,443 individuals, including 34,452 California residents. Academy notified affected individuals by mail on approximately December 20, 2023.

    Examination findings. The Commissioner examined Academy’s cybersecurity systems and processes under Financial Code section 50302. The order states the examination found deficiencies and areas of concern in information security, recordkeeping and governance, each predating the breach: inadequate information security risk assessments for 2021 through 2023; inadequate information security program audits, including no full and formal audit between 2017 and 2023; ineffective security practices, including deficient vulnerability and patch management, deficient access controls and an apparent failure to document any correction of deficiencies identified through penetration testing; and board of directors-level oversight and planning.

    Records and forensic reporting. The Commissioner found that Academy did not maintain a documented asset inventory, an up-to-date incident response plan, documentation of follow-up on audit findings, or written IT policies for multiple issue areas, and that the company said it carried out appropriate day-to-day security practices without documenting them in its policies and procedures. Academy also neither requested nor obtained a written forensic report from its consultant on the probable root cause of the breach, contributing factors or remediation steps, giving examiners a one-page close-out letter that the Commissioner found insufficient. Those records alone could not enable the Commissioner to determine whether the company’s lending and servicing functions complied with the California Residential Mortgage Lending Act (CRMLA), the order states.

    Legal conclusions. The Commissioner concluded that Academy failed to proceed with due care and competence under Financial Code section 50124(a)(16) and so engaged in unsafe and injurious acts within the meaning of section 50322; that it failed to comply with laws binding on it under section 50321, the Gramm-Leach-Bliley Act’s information security requirements at 15 U.S.C. section 6801(b), the implementing Safeguards Rule at 16 C.F.R. Part 314 and Civil Code section 1798.100(e); and that it failed to maintain records as required by section 50314(a).

    Penalty and consumer remediation. Academy agreed to pay the $825,000 penalty under Financial Code section 50501 within 30 calendar days of the effective date, and within the same period must retain an identity theft insurance provider to cover all California-resident borrowers affected by the breach, with coverage lasting 12 months from the start date of each borrower’s policy. It must notify those borrowers within 60 days using a notice approved by the Commissioner, may not condition coverage on a borrower waiving any right, and must report full compliance within 90 days. DFPI’s press release states that consumers must opt in to receive the remedy and that a point of contact for consumer inquiries will be established; the order itself sets no opt-in condition, requiring coverage for all affected California-resident borrowers. The order also directs Academy to discontinue violations of section 50314 and to end unsafe and injurious acts with respect to its cybersecurity systems and processes.

    Commissioner’s statement. DFPI Commissioner Mohseni said in the department’s announcement that companies with access to personal information must have robust, stringent cybersecurity and that the penalty should act as a deterrent, adding that “strong data protection for Californians is non-negotiable.”

    Company position and wind-down. Academy entered the order without admitting or denying the recitals or the Commissioner’s findings and conclusions, and waived its rights to a hearing, reconsideration, appeal or other review. The order records that roughly two weeks before the examination began, the company notified the department that it had sold its loan production-related assets on February 28, 2024, and transferred its production and operations personnel to the purchaser, and that it stopped accepting loan applications on March 4, 2024. Academy represents that, as it liquidates and winds down operations, the settlement reflects its willingness to work with regulators to bring its cybersecurity into compliance for an institution of its size, complexity and risk profile.

    MainStory: TopStory CaliforniaNews CyberPrivacyFeed DataBreach DataSecurity EnforcementActions FinTech GCNNews IdentityTheft Privacy UtahNews DataPrivacy

    © 2026 CCH Incorporated and its affiliates and licensors. All rights reserved.

    • Manage Cookie Preferences
    • Privacy Statement
    • Terms of Use