On December 11, 2024, Mortgage Investors Group, operating as migonline.com, appeared on the leak site of the Black Basta ransomware group. The listing states that roughly 1.5 TB of the Tennessee-based mortgage lender’s internal files were exfiltrated during a ransomware attack. Anyone who has applied for a home loan, refinanced, or provided personal financial documents to MIG in the past 35 years may now have their information at risk.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch migonline.com
Get alerted the next time migonline.com files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about migonline.com’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details from the Listing
The Black Basta leak page for migonline.com explicitly lists three categories of stolen material: financial data and accounting records, contracts and loans data, and home folders containing personal employee information. The disclosure does not quantify the number of affected individuals, nor does it publish sample files. It simply states that the data was taken in a ransomware incident and gives the company’s physical address in Knoxville, Tennessee, along with its main phone number. The listing does not detail the initial access vector or the exact date of compromise.
Why This Matters for You and Your Family
If you or anyone in your household has ever borrowed money from Mortgage Investors Group, your Social Security number, income history, bank account details, and home address are likely among the records now held by criminals. Mortgage files routinely contain tax returns, pay stubs, credit reports, and loan application forms that remain valuable to identity thieves for years. Even if you were only a co-borrower, guarantor, or employee of a company that used MIG’s services, your information can still be exposed. The volume—1.5 TB—suggests the breach is not limited to a handful of records.
Doxxing and Identity-Chain Risks
Loan documents often link your name, current and previous addresses, date of birth, phone numbers, email accounts, and employer information in one convenient package. Attackers can use these details to build an identity chain that connects your online handles, gaming accounts, and family members. A single exposed email or phone number from an old MIG loan file can unlock password-reset flows on other services, turning this claimed breach into the starting point for account takeovers across your digital life. Children’s records included in a parent’s loan application can also enter these chains, exposing minors to long-term identity fraud.