Data Breaches

Mr. Cooper Data Breach Impacts 14.7 Million Individuals

Mr. Cooper has confirmed that personal and bank account information was compromised in a recent cyberattack.

Mr. Cooper has confirmed that personal and bank account information was compromised in a recent cyberattack.

Mortgage giant Mr. Cooper is sending notification letters to 14.7 million individuals to inform them that their personal information was stolen in a recent cyberattack.

The incident was identified on October 31, resulting in certain systems being taken down, including those used for processing customer payments, the company announced in early November.

On December 15, Mr. Cooper started notifying customers that, between October 30 and November 1, the attackers had access to certain systems and exfiltrated files containing customer personal information.

“Based on our investigation to date, roughly 14.7 million homeowners, representing former and current customers and co-borrowers, had personal information contained in the files that were affected by this incident,” the company says in an incident notice.

In the notification letter sent to the impacted individuals, a copy of which was submitted to the Maine Attorney General’s Office, Mr. Cooper says that the compromised personal information includes names, addresses, dates of birth, phone numbers, Social Security numbers, and bank account numbers.

On its website, the company clarifies that “a limited group of approximately 32,000 reverse mortgage customers’ bank account numbers were contained in the files that were affected by this incident.”

Advertisement. Scroll to continue reading.

Mr. Cooper says it has fully restored the systems that were locked down following the attack, and that it is monitoring the dark web to see if the stolen data is being shared by the attackers.

The company says it has no evidence at this time that the stolen information was misused for fraud or identity theft, but it is providing identity protection and credit monitoring services to the impacted individuals and encourages them to enroll.

Mr. Cooper has not provided specific details on the type of cyberattack it has suffered, but taking systems offline is the typical response to a ransomware attack.

To date, however, SecurityWeek has not observed any ransomware gang taking responsibility for the incident.

Related: Toyota Germany Says Customer Data Stolen in Ransomware Attack

Related: Yamaha Motor Confirms Data Breach Following Ransomware Attack

Related: Royal Ransomware Possibly Rebranding After Targeting 350 Organizations Worldwide

Related Content

Data Breaches

The hacker claimed to have stolen the information of 2 million Origin Energy customers after breaching its systems.

Data Breaches

The Anubis cybercrime group has taken credit for the attack and is threatening to leak data.

Data Breaches

In May 2026, hackers stole personal and dental health information from DentaQuest’s computer network.

Data Breaches

The PEAR ransomware group claimed to have stolen 3 TB of information from the medical business management company.

Data Breaches

A hacker claims to have stolen the information of 2 million Origin Energy customers and is threatening to leak it. 

Data Breaches

Threat actors used credentials obtained from other companies to hack into Chick-fil-A One accounts.

Data Breaches

Hackers recently obtained non-sensitive customer information and other documents from the company.

Data Breaches

Hackers leaked names, email addresses, phone numbers, passwords, and financial information stolen from the two platforms. 

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version