California’s Department of Financial Protection and Innovation has ordered Academy Mortgage Corporation to pay $825,000 and provide affected borrowers with a year of identity theft insurance, resolving an examination that traced a 2023 ransomware attack to cybersecurity and recordkeeping failures the regulator said predated the breach.
The consent order stems from a March 2023 intrusion in which a threat actor installed malware, stole employee login credentials, disabled network security systems, and launched ransomware two days later. The attacker reached systems holding personally identifiable information on 284,443 individuals, including 34,452 California residents. Academy contained the incident within roughly a week but did not notify affected consumers until December 2023.
DFPI’s examination, conducted under the California Residential Mortgage Lending Act, faulted Academy for inadequate risk assessments from 2021 through 2023, the absence of a full information security audit between 2017 and 2023, deficient patch management and access controls, no comprehensive asset inventory, and gaps in board-level oversight. Regulators also found the company’s records too thin to let the Commissioner determine whether its lending and servicing functions complied with the law. Academy retained a forensic consultant but never obtained a written root-cause report, handing examiners only a one-page close-out letter that the Commissioner deemed insufficient.
Notably, Academy sold its loan production assets in February 2024 and stopped accepting applications the following month, yet the regulator pursued the penalty as the company winds down. Academy resolved the matter without admitting or denying the findings.
Within 30 days of the effective date, Academy must retain an identity theft insurance provider and, within 60 days, notify California borrowers of coverage that DFPI must approve in advance. The company must verify full compliance within 90 days.
.




