[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1w73lt32rq4qn":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":21,"affectedCountUnit":22,"hasEnglishDescription":4,"severity":23,"dataClasses":24,"description":34,"seoTitle":35,"seoTitleEn":36,"seoDescription":35,"seoDescriptionEn":37,"logoUrl":38,"isVerified":4,"isSensitive":4,"isSpamList":39,"isMalware":39,"company":40},"6a6f84dbbd37add4e748ca11","PlazaHomeMortgage2026","Plaza Home Mortgage Data Breach","plaza-home-mortgage-2026","plazahomemortgage.com","2026-02-17T00:00:00.000Z","2026-08-02T17:56:43.380Z","2026-08-02T17:58:52.417Z","Unauthorized access to an employee computer and company information systems","https:\u002F\u002Foag.my.site.com\u002Fdatasecuritybreachreport\u002Fapex\u002FDataSecurityReportsPage",[15,17,18],"https:\u002F\u002Foag.ca.gov\u002Fecrime\u002Fdatabreach\u002Freports\u002Fsb24-624434","https:\u002F\u002Fwww.housingwire.com\u002Farticles\u002Fplaza-security-incident-breach\u002F",137976,"known",null,"people","High",[25,26,27,28,29,30,31,32,33],"Names","Physical addresses","Social security numbers","Driver's license numbers","Dates of birth","Government IDs","Loan information","Usernames","Passwords","\u003Cp>Plaza Home Mortgage, Inc. is a United States mortgage lender serving wholesale and correspondent channels. According to the company, an employee computer and company information systems were accessed without authorization on or around February 17, 2026; security controls alerted the company and the access was terminated.\u003C\u002Fp>\u003Cp>The Texas Attorney General record reports 137,976 affected people nationwide, including 12,610 Texas residents. The company discovered the incident on March 3 and notified affected customers and employees on May 29, 2026.\u003C\u002Fp>\u003Ch2>Confirmed incident scope\u003C\u002Fh2>\u003Cp>The California Attorney General lists February 17 and publishes separate notice samples for customers and employees. Texas's 12,610 residents are a state subset within the nationwide total of 137,976, so the two figures must not be added together.\u003C\u002Fp>\u003Cp>Public statements say the access involved an employee computer. They do not disclose the initial access method, technical root cause, or identity of the threat actors, so phishing, malware, or another method should not be assumed.\u003C\u002Fp>\u003Ch2>What information may have been affected?\u003C\u002Fh2>\u003Cp>Depending on the person, affected information may include names, addresses, dates of birth, Social Security numbers, driver's licenses or other government identification, and mortgage application or servicing information. Employee records may also include account usernames and passwords.\u003C\u002Fp>\u003Cp>This does not mean every listed field was present for every affected person. The unspecified “other” category in the Texas record is not expanded into a separate data class; only information expressly named by the sources is included.\u003C\u002Fp>\u003Ch2>Identity-theft risks\u003C\u002Fh2>\u003Cp>A combination of Social Security numbers, birth dates, addresses, and government identification can support fraudulent credit applications, tax fraud, or account-recovery attempts. Notice recipients should review their credit reports and consider a credit freeze or fraud alert when appropriate.\u003C\u002Fp>\u003Cp>People whose individual notice confirms driver's-license information can review replacement or monitoring options with their state licensing agency. Employees should promptly change the affected account password and replace reused or similar passwords elsewhere.\u003C\u002Fp>\u003Ch2>Mortgage-themed fraud\u003C\u002Fh2>\u003Cp>Mortgage application and servicing context can make fake payment-change, escrow, refinancing, document-upload, or identity-verification messages more convincing. An attacker may use a real name and address to create urgency.\u003C\u002Fp>\u003Cp>If an unexpected message changes payment instructions, bank details, a closing date, or contact information, verify it through a previously known official number before acting. Do not rely on the link or phone number supplied in the unexpected message.\u003C\u002Fp>\u003Ch2>Practical protective steps\u003C\u002Fh2>\u003Cp>Consider the free credit and identity-monitoring services described in the company notice, and regularly review credit reports, new-account applications, and tax records. A unique email password and multifactor authentication reduce the impact of follow-on phishing.\u003C\u002Fp>\u003Cp>Employees should revoke active sessions, review recovery methods, and replace any reused passwords. Customers should check their mortgage-servicing account for unauthorized changes to contact or payment information.\u003C\u002Fp>\u003Ch2>How should a result be interpreted?\u003C\u002Fh2>\u003Cp>\u003Cstrong>A positive match connected to this incident is sufficient reason to apply the notice's protective steps without delay.\u003C\u002Fstrong> It does not, by itself, prove that every listed data type was present for that person.\u003C\u002Fp>\u003Cp>A negative result does not guarantee that a person was absent from other company systems or unrelated breaches. Anyone who received a direct Plaza Home Mortgage notice should follow the company's and regulators' guidance regardless of a search result.\u003C\u002Fp>","","Plaza Home Mortgage Data Breach (138 Thousand People Affected)","Plaza Home Mortgage's February 2026 breach affected 137,976 people, exposing names, addresses, birth dates, SSNs, IDs, and mortgage information.","https:\u002F\u002Fwww.plazahomemortgage.com\u002Fapple-touch-icon.png",false,{"name":41,"sector":42,"country":43,"website":10,"websiteArchiveUrl":35,"websiteStatus":44,"websiteCheckedAt":12},"Plaza Home Mortgage","Financial Services","United States","active"]