ARTICLE
25 August 2026

California Consent Order Highlights Cybersecurity Documentation And Vendor Oversight Risks For Mortgage Companies

GP
Goodwin Procter LLP

Contributor

At Goodwin, we partner with our clients to practice law with integrity, ingenuity, agility, and ambition. Our 1,600 lawyers across the United States, Europe, and Asia excel at complex transactions, high-stakes litigation and world-class advisory services in the technology, life sciences, real estate, private equity, and financial industries. Our unique combination of deep experience serving both the innovators and investors in a rapidly changing, technology-driven economy sets us apart.
California's Department of Financial Protection and Innovation imposed an $825,000 penalty on Academy Mortgage Corporation following a 2023 ransomware attack, finding that inadequate cybersecurity documentation and governance failures constituted substantive violations.
United States California Finance and Banking
Sophie Barnett’s articles from Goodwin Procter LLP are most popular:
  • within Finance and Banking topic(s)
  • in United States
  • with readers working within the Automotive, Banking & Credit and Business & Consumer Services industries
Goodwin Procter LLP are most popular:
  • within Accounting and Audit, Criminal Law and Law Practice Management topic(s)

In August 2026, the California Department of Financial Protection and Innovation (DFPI) announced that it had entered into a consent order with Academy Mortgage Corporation resolving findings arising from a March 2023 ransomware attack, which signaled that a mortgage company’s ability to document cybersecurity governance may matter as much as the controls themselves. The order adds to a growing body of state enforcement actions in which regulators have treated cybersecurity documentation deficiencies not as mere procedural shortcomings but as substantive violations warranting penalties in their own right. According to the order, a threat actor installed malware, stole employee login credentials, disabled network-security systems, and accessed systems containing personally identifiable information for 284,443 people, including 34,452 California residents.

DFPI’s examination identified alleged weaknesses that predated the attack, including inadequate risk assessments from 2021 through 2023, no full formal information security audit between 2017 and 2023, deficient vulnerability and patch management, deficient access controls, no comprehensive asset inventory, and inadequate documentation of remediation after penetration testing. The order also identified concerns with board-level oversight and planning, placing governance alongside technical safeguards as a central part of DFPI’s analysis.

Recordkeeping played an equally prominent role. DFPI found that Academy lacked an up-to-date incident response plan, documentation tracking follow-up on audit findings, and written information technology policies and procedures for multiple issue areas. Although Academy retained a third-party cybersecurity consultant to contain and investigate the breach, the company did not obtain a written forensic report addressing the probable root cause, contributing factors, or remediation steps; DFPI concluded that the consultant’s one-page close-out letter was insufficient.

Without admitting or denying DFPI’s recitals, findings, or conclusions, Academy agreed to pay an $825,000 administrative penalty, discontinue the cited violations and allegedly unsafe or injurious practices, and provide 12 months of identity theft insurance to affected California borrowers. The order requires Academy to retain an insurance provider within 30 days, notify affected California borrowers within 60 days using a notice approved by DFPI, and report compliance within 90 days. The settlement also came as Academy represented that it was liquidating and winding down operations after selling its loan-production-related assets in February 2024 and ceasing to accept loan applications in March 2024.

The order is a reminder that regulators may treat missing documentation as more than an examination inconvenience: DFPI tied Academy’s alleged recordkeeping gaps to California Residential Mortgage Lending Act requirements and cited the Gramm-Leach-Bliley Act, the Safeguards Rule, and California’s reasonable security requirements in its findings. Mortgage companies should consider whether their boards receive documented cybersecurity reporting, their policies match actual practices, and their incident response engagements require vendors to deliver detailed written findings that can support both remediation and regulatory review.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

[View Source]

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More