Lennar Mortgage, LLC Data Breach Notice (Washington Attorney General)
If you were named in this filing, here’s what the filing says was exposed, and what to do about it.
Lennar Mortgage, LLC notified Washington residents of a data breach in a filing reported to the Washington State Attorney General on August 14, 2026, and the notice lists name, social security number, driver's license or Washington ID card number, financial & banking information, full date of birth, military ID number, passport number and medical information among the information exposed. The filing puts the incident itself on May 26, 2026.
The data breach at Lennar Mortgage now means that for 11,417 people, a single incident has placed their Social Security number, full date of birth, passport number, and medical information beyond their control. These four categories cannot be replaced or reset like a credit card. Once they are in the wrong hands they remain useful for identity theft and fraud for years.
80 Days Passed Between the Incident and Notification
Lennar Mortgage, LLC reported the breach to the Washington Attorney General on August 14, 2026. The filing states the incident itself occurred on May 26, 2026. That interval of 80 days, roughly two and a half months, is the most concrete timing detail available. The record does not disclose when the company first discovered the incident, only these two dates.
What Was Exposed and What It Enables
The filing lists eight categories of information involved in the incident: name, Social Security number, driver’s license or Washington ID card number, financial and banking information, full date of birth, military ID number, passport number, and medical information. No passwords were exposed.
A Social Security number paired with a full date of birth is the foundational combination used to open new credit accounts, file fraudulent tax returns, or create synthetic identities. Adding a passport number or driver’s license number increases the credibility of those applications. Medical information can be used to file false insurance claims or to impersonate someone when seeking care. Financial and banking details can accelerate account takeover attempts even when the primary account itself was not compromised.
Because no passwords were included, this is not an account-level compromise that requires you to change a Lennar Mortgage login. The risk sits in the permanent identifiers that follow a person for life.
The Value That Does Not Expire
Unlike a compromised credit card that can be canceled and reissued within days, a Social Security number cannot be changed at will. The same is true for a date of birth, passport number, and most medical history. These pieces of information retain their value to identity thieves long after the breach fades from headlines. The 11,417 affected individuals now carry an elevated risk that is measured in years rather than weeks.
The presence of medical information alongside biographic identifiers creates additional overlap with healthcare identity fraud. Fraudsters can use the combination to obtain services, prescriptions, or insurance payouts in someone else’s name, sometimes leaving the victim with unexpected bills or corrupted medical records.
How to Determine Whether This Affects You
Lennar Mortgage is required to notify affected individuals directly, usually by mail. If you have not received a letter, it is likely your information was not included in this incident. However, if you have moved since May 26, 2026, or if mail from that period could have gone astray, contact Lennar Mortgage directly to confirm whether you were among the 11,417 Washington residents named in the filing.
The Limitations of What We Know
The filing does not state how the incident occurred, whether any encryption was in place, or how long any data may have been accessible. It also does not indicate whether this was a ransomware event or an external intrusion. Those details remain undisclosed. What is known is limited to the categories exposed, the number of people, and the two dates provided.
Why the Combination Matters More Than Any Single Field
One exposed field by itself is rarely enough for sophisticated fraud. The danger compounds when multiple permanent identifiers travel together. Here the record shows that for those affected, name, Social Security number, date of birth, and at least one government-issued ID number were all listed in the same incident. That bundle is precisely what lenders, insurers, and government agencies use to establish identity. Once it exists outside controlled systems, verification processes become easier to defeat.
Medical information adds another vector. It can be sold on dark-web marketplaces specifically because it pairs well with the other data to support longer-term impersonation schemes.
Practical Steps That Address This Specific Exposure
- Place a fraud alert or credit freeze with Equifax, Experian, and TransUnion immediately. This is the single most effective step for limiting new-account fraud when a Social Security number has been exposed.
- Review your Explanation of Benefits statements from every health insurer you use. Look for claims you did not file or services you did not receive. Medical identity theft often surfaces first through insurance paperwork.
- Monitor IRS transcripts and tax filings for unexpected activity. A common use of stolen Social Security numbers paired with dates of birth is fraudulent tax returns filed in the victim’s name.
- Treat any unsolicited contact claiming to be from a bank, mortgage servicer, or government agency with extra caution. Verify requests through known official channels rather than responding to incoming calls or emails.
- Keep records of the breach notice. If identity theft occurs later, documentation that your information was exposed in this specific incident can help when dealing with creditors, insurers, or credit bureaus.
What Cannot Be Fixed and What Still Can
You cannot change your date of birth, Social Security number, or the medical history already created. Those facts are now permanently available to anyone who obtained the data. What remains under your control is how aggressively you monitor for misuse and how quickly you respond when something appears.
The 80-day gap between the May 26 incident and the August 14 filing does not change the categories that were lost, but it does mean the information may have circulated for some time before official notification began. That reality makes early, consistent monitoring the only practical defense available.
The letter from Lennar Mortgage remains the definitive answer for any individual wondering whether they are one of the 11,417 affected. Absent that letter, and assuming mail has been reliable, the filing indicates your records were not part of this breach. For those who did receive notice, the exposure is serious but not total. The accounts themselves were not compromised, passwords were not taken, and many concrete protective steps still work. Use them.
What to do now Every step below is free and you do it yourself, and none of it depends on Lennar Mortgage, LLC. One more, whatever was exposed: a breach notice is a
favourite disguise for a phishing email. If a message about this arrives,
do not use its links — go to the company’s site yourself, or
call the number on your statement.Steps that match what this notice says was exposed
Report details & sourcing
Related breaches
Castle Management, LLC Data Breach Notice (Vermont Attorney General)
Castle Management, LLC notified Vermont residents of a data breach in a filing reported to the Vermo…
Together Women's Health LLC Data Breach Notice (California Attorney General)
Together Women's Health LLC notified California residents of a data breach in a filing reported to t…
Pan American Group LLC Data Breach Notice (California Attorney General)
Pan American Group LLC notified California residents of a data breach in a filing reported to the Ca…