Utah Department of Financial Institutions · UT
Utah joins $20 million multistate settlement for customer data breach by nonbank mortgage company
January 9, 2025
Summary
Utah joined a 52-state regulatory settlement requiring the Bayview Companies to pay $20 million due to inadequate cybersecurity practices following a data breach affecting 5.8 million consumers. The settlement mandates that the company implement comprehensive corrective actions, conduct independent security assessments, and provide three years of periodic compliance reporting to state regulators.
Utah joins $20 million multistate settlement for customer data breach by nonbank mortgage company
Utah and 52 state financial regulatory agencies have entered into a $20 million settlement agreement and taken coordinated action against mortgage company Bayview Asset Management LLC and three of its affiliates, Lakeview Loan Servicing, Community Loan Servicing, and Pingora Holdings (collectively the Bayview Companies), for deficient cybersecurity practices and for not fully cooperating with state regulators following a data breach that impacted 5.8 million customers.
The settlement and corrective plan underscore the importance of meeting state requirements to protect consumer data and complying with state supervisory demands.
“The Utah Department of Financial Institutions is very sensitive to how financial institutions under our jurisdiction safeguard consumer data and maintain effective cybersecurity programs,” said Commissioner Darryle P. Rude. “The Department expects that companies utilizing consumers’ information do everything in their power to protect that information and, if a breach occurs, take appropriate action to notify and assist consumers.”
In addition to the monetary penalty, the Bayview Companies have agreed to take specified corrective actions, improve cybersecurity programs, undergo independent assessments, and provide three years of additional reporting to the states.
Utah residents with questions about the enforcement action should contact the Utah Department of Financial Institutions complaints.dfi@utah.gov. Consumers can also visit NMLS Consumer Access to verify that a company is licensed to do business in Utah, and they may also view past enforcement actions.
Source: https://dfi.utah.gov/resources/news/
Common questions
- What does "Utah joins $20 million multistate settlement for customer data breach by nonbank mortgage company" cover?
- Utah joined a 52-state regulatory settlement requiring the Bayview Companies to pay $20 million due to inadequate cybersecurity practices following a data…
- Which agency issued this update?
- This update was issued by Utah Department of Financial Institutions.
- When was it published?
- It was published on January 9, 2025.
Related updates
- Lakeview Loan Servicing, LLC, Pingora Loan Servicing, LLC, Community Loan Servicing, LLC, and Bayview Asset Management, LLC Multistate Settlement Agreement and Consent Order issued by the Division of Banking
- Pionex, Inc. Consent Order issued by the Division of Banking
- Two Ocean No-Action Letter: Digital Asset Custody & Qualified Custodian Status
- Ultralight FS,. Inc., formerly known as Obopay, Inc., also doing business as Obopay USA
- Updated Nonbank Ransomware Self-Assessment Tool (R-SAT)
- ACI Payments, Inc. Settlement Agreement and Consent Order issued by the Division of Banking