California Consent Order Highlights Cybersecurity Documentation and Vendor Oversight Risks for Mortgage Companies
In August 2026, the California Department of Financial Protection and Innovation (DFPI) announced that it had entered into a consent order with Academy Mortgage Corporation resolving findings arising from a March 2023 ransomware attack, which signaled that a mortgage company’s ability to document cybersecurity governance may matter as much as the controls themselves. The order adds to a growing body of state enforcement actions in which regulators have treated cybersecurity documentation deficiencies not as mere procedural shortcomings but as substantive violations warranting penalties in their own right. According to the order, a threat actor installed malware, stole employee login credentials, disabled network-security systems, and accessed systems containing personally identifiable information for 284,443 people, including 34,452 California residents.
DFPI’s examination identified alleged weaknesses that predated the attack, including inadequate risk assessments from 2021 through 2023, no full formal information security audit between 2017 and 2023, deficient vulnerability and patch management, deficient access controls, no comprehensive asset inventory, and inadequate documentation of remediation after penetration testing. The order also identified concerns with board-level oversight and planning, placing governance alongside technical safeguards as a central part of DFPI’s analysis.
Recordkeeping played an equally prominent role. DFPI found that Academy lacked an up-to-date incident response plan, documentation tracking follow-up on audit findings, and written information technology policies and procedures for multiple issue areas. Although Academy retained a third-party cybersecurity consultant to contain and investigate the breach, the company did not obtain a written forensic report addressing the probable root cause, contributing factors, or remediation steps; DFPI concluded that the consultant’s one-page close-out letter was insufficient.
Without admitting or denying DFPI’s recitals, findings, or conclusions, Academy agreed to pay an $825,000 administrative penalty, discontinue the cited violations and allegedly unsafe or injurious practices, and provide 12 months of identity theft insurance to affected California borrowers. The order requires Academy to retain an insurance provider within 30 days, notify affected California borrowers within 60 days using a notice approved by DFPI, and report compliance within 90 days. The settlement also came as Academy represented that it was liquidating and winding down operations after selling its loan-production-related assets in February 2024 and ceasing to accept loan applications in March 2024.
The order is a reminder that regulators may treat missing documentation as more than an examination inconvenience: DFPI tied Academy’s alleged recordkeeping gaps to California Residential Mortgage Lending Act requirements and cited the Gramm-Leach-Bliley Act, the Safeguards Rule, and California’s reasonable security requirements in its findings. Mortgage companies should consider whether their boards receive documented cybersecurity reporting, their policies match actual practices, and their incident response engagements require vendors to deliver detailed written findings that can support both remediation and regulatory review.
The post California Consent Order Highlights Cybersecurity Documentation and Vendor Oversight Risks for Mortgage Companies appeared first on Consumer Finance Insights (CFI).