On August 21, 2026, California DFPI ordered a mortgage company to pay $825,000 due to cybersecurity failures leading up to a ransomware attack.
What changed
The order cites violations of the GLBA Safeguards Rule, particularly regarding governance and access control.
Compliance perspective
Mortgage companies should assess their cybersecurity measures and compliance with the GLBA to avoid similar penalties.
Need help keeping up with these changes?
Tell us where you operate and what licenses you hold; we'll handle the filings and renewals so changes like this do not catch you off guard.