Mortgage Investors Group discloses December breach after Black Basta claim

Organization
Mortgage Investors Group
Exploit
Ransomware
Industry
Financial Services

Mortgage Investors Group, a Tennessee based lender that says it serves about 300,000 customers through more than 26 branches, posted a breach notice in January 2025 saying an unauthorized user had gained access to its computer environment the previous month. The Record reported the notice on January 14, 2025, and the company issued a press release restating it on January 20.

According to the company's notice, the intrusion began on December 11, 2024 and was detected in the early hours of December 12, when MIG shut down network access and cut off the intruder. Outside cybersecurity specialists were engaged, and the company said the forensic investigation was completed on December 30 and confirmed that its containment measures had worked.

MIG said full names and certain financial information may have been exposed. It had not determined how many people were affected at the time of the announcement and said it had retained a vendor to identify them, with notification letters and complimentary credit monitoring to follow. The lender set up a dedicated web page and support line and said it had seen no evidence of fraudulent misuse.

The Black Basta ransomware group listed MIG on its leak site shortly before the disclosure. The company did not say whether ransomware was deployed or whether a ransom was demanded, and The Record reported that MIG did not respond to further questions about the attack.

Sources