Impac Mortgage Holdings was listed on the Medusa ransomware group's leak site on February 21, 2024. The California-based mortgage lender, which provides lending and warehouse financing services, had 592.2 GB of internal files exfiltrated during a ransomware attack. Anyone whose mortgage records, loan applications, or personal financial documents passed through Impac may now face heightened identity theft and fraud risks.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
Reported Details from the Listing
The Medusa leak site states that Impac Mortgage Holdings suffered a ransomware attack in which attackers exfiltrated internal files before encryption. The disclosure lists 592.2 GB of data and provides a sample of the stolen material. The primary disclosure does not specify the exact number of individuals affected or list the precise data types beyond claiming that internal files were taken. Public reporting on Medusa indicates the group typically posts proof-of-exfiltration samples and threatens full data release if ransom demands are not met. The listing remains active on the onion site, showing the incident remains unresolved from the attackers' perspective.
Why This Matters for You and Your Family
If you or your family obtained a mortgage, refinanced a loan, or used Impac's warehouse lending services in the past three decades, your personal information may sit inside the stolen files. Mortgage records routinely contain full names, Social Security numbers, dates of birth, addresses, bank account details, employment history, and tax returns. Exposure of this information allows criminals to file fraudulent tax returns, open new credit lines, or impersonate you when dealing with other lenders. Because mortgage data often links multiple family members — spouses, co-borrowers, even children listed as dependents — one breach can place every household member at risk simultaneously.
Doxxing and Identity-Chain Implications
Stolen mortgage files rarely exist in isolation. They frequently include email addresses, phone numbers, and employer details that attackers can cross-reference with other breaches. A single leaked loan application can anchor an identity chain that reveals your online handles, family relationships, and even children's gaming accounts. Once attackers map these connections, they can pivot to social engineering, SIM-swapping, or direct account takeovers. The 592.2 GB volume suggests the dataset is large enough to enable automated correlation at scale, increasing the chance that your information will surface in future extortion campaigns or underground marketplaces.