Fifty-three state financial regulatory agencies have imposed a $20 million penalty on Bayview Asset Management LLC and its affiliates — Lakeview Loan Servicing, Community Loan Servicing, and Pingora Holdings — for inadequate cybersecurity practices and delayed compliance with state regulators. The coordinated enforcement action follows a 2021 data breach impacting 5.8 million consumers.
The big picture:
- Participating States: The action involved 53 states and jurisdictions, including California, Maryland, North Carolina, and Washington, which led the investigation.
- Data Breach Details: The breach originated in October 2021 when an employee inadvertently downloaded malware. Over the following months, malicious actors extracted sensitive consumer data.
- Consumer Impact: Approximately 5.8 million individuals were notified about the compromise of their personal information. The companies offered affected consumers credit monitoring and identity theft protection services.
Regulatory findings
- Deficient Practices: The multistate examination revealed insufficient IT patch management, weak encryption of sensitive data, and inadequate vulnerability tracking and remediation systems.
- Noncompliance: The companies were cited for delaying the regulatory process by failing to provide requested information promptly during the early stages of the investigation. During the multistate cybersecurity examination covering January 2020 to September 2022, Bayview delayed providing requested information, citing privilege and other concerns. While the company eventually complied, this slowed the regulatory process.
Corrective actions
In addition to the financial penalty, the Bayview Companies are required to:
- Enhance their cybersecurity programs and comply with both state and federal regulations. Key required enhancements include:
- Information Security Policy: Maintain and annually review a comprehensive policy to protect information systems and consumer data.
- Encryption Standards: Encrypt consumer information both at rest and in transit, or implement compensating controls approved by the Chief Information Security Officer.
- Patch Management: Develop processes to identify and install critical software updates promptly and retire unsupported hardware or software unless mitigated by alternative controls.
- Data Loss Prevention: Establish an enterprise-wide program to detect and prevent unauthorized data exfiltration.
- Third-Party Oversight: Strengthen vendor management practices to ensure service providers meet cybersecurity requirements.
- Incident Response: Update plans to clearly define roles and responsibilities for handling cybersecurity incidents.
- Independent Assessments: Engage a third-party consultant to review cybersecurity programs, prioritize corrective actions, and report progress to state regulators.
- Regular Reporting: Provide updates to regulators on cybersecurity enhancements, material issues, and any new security incidents.
- Conduct independent cybersecurity assessments.
- Provide ongoing reports to state regulators for three years.




