Latest Posts Latest Episodes Free Tools

What loanDepot Just Told the SEC About Its 2024 Data Breach

A Get Out of Debt series · Reading the filings so you don’t have to

What They Told Wall Street

FORM 10-QLOANDEPOT, INC. (LDI)FILED 08/06/2026QUARTER ENDED 06/30/2026CIK 0001831631

A data breach happens, the company sends you a letter, offers a year of free credit monitoring, and life moves on. That’s the story most of us tell ourselves once the notification arrives. Here’s what one of the country’s largest mortgage lenders just told the SEC about its own breach — more than two and a half years after it happened.

I’ve written before about whether you should freeze your credit after a data breach and what to do if you’re an identity theft victim. loanDepot isn’t new territory for this site, either — I’ve written about the company’s customer-communication practices before. What’s new is what the company itself just told investors about a breach that happened in January 2024 and, by its own admission, still isn’t resolved.

What most of us assume

“If a data breach happened two years ago and nobody’s announced a settlement or a fine, it must be winding down.”

What loanDepot told the SEC

This quarter — for the first time in any quarterly or annual report it has filed since the breach — the company told investors a loss from the state investigations is now “probable.” It still can’t put a number on it. (Its wording is that it can’t estimate a loss “beyond amounts accrued” — the filing doesn’t break out what, if anything, is accrued for these investigations specifically.)

On its face, a data breach notice feels like an event with a beginning and an end: you get the letter, you sign up for the free monitoring, and eventually you stop thinking about it. But the company on the other end of that breach has its own clock, and its own lawyers, and every quarter it has to tell Wall Street — under penalty of law — exactly where things really stand. What a company tells the SEC carries legal consequences that a customer-service script does not. So I went and read what loanDepot actually filed.

The disclosure

Form 10-Q · Note 15, Commitments and ContingenciesFiled August 6, 2026

“The Company is cooperating with state regulators and attorneys general regarding ongoing investigations into the cybersecurity incident that occurred in January 2024 resulting from unauthorized access to our systems (“Cybersecurity Incident”). The Company believes that a loss is probable, but it cannot reasonably estimate a loss or range of loss beyond amounts accrued that might result from adverse judgments, settlements, penalties or other resolution of these investigations due to the preliminary stage of discussions and unresolved factual and legal matters.”

What I think they’re really saying

Read plainly, this is loanDepot telling its investors: “We now expect this to cost us something, we can’t yet say how much, and the regulators still aren’t done.” A “probable” disclosure is a threshold in the accounting rules, not a promise about a final number. That’s a real change in the company’s own legal language. Why it appeared in this particular filing and not an earlier one is my read, not something the filing states.

The receipt: this got worse, not better

I didn’t stop at one quarter. I also pulled loanDepot’s prior 10-Q — filed just three months earlier, on May 7, 2026, for the quarter ended March 31, 2026 — to see what the company was saying about the same breach back then. Here’s that filing, word for word:

Form 10-Q · Prior quarterFiled May 7, 2026

“The Company is cooperating with various state regulators and attorneys general regarding ongoing investigations into the Cybersecurity Incident. While the ultimate dispositions of the investigations are not yet determinable, the Company does not believe that a loss is reasonably estimable in these matters at this time.

What changed between the two filings

Three months ago, on this matter, loanDepot said only that a loss was not reasonably estimable. It did not say a loss was probable, and it did not say one wasn’t. This quarter it states plainly that a loss is probable. I went back and read every quarterly and annual report the company has filed since the January 2024 breach: this is the first one in which it says that about the state investigations.

An honest caveat, because it matters. Under the accounting rules, “not reasonably estimable” and “probable” are not opposites — a company can hold both views at once, and it is possible loanDepot considered a loss probable earlier and simply hadn’t said so. So what is documented is a change in disclosure. My read is that a company’s lawyers don’t add the word “probable” to a sworn filing casually. That read is opinion. The wording change is fact.

One more number worth sitting with. In the same filing, loanDepot’s own non-GAAP reconciliation tables show it is still booking real dollars against this breach — and paying more this year than last:

Form 10-Q · Non-GAAP Reconciliation footnoteFiled August 6, 2026

“Represents expenses directly related to the Cybersecurity Incident, net of insurance recoveries during fiscal 2024, including costs to investigate and remediate the Cybersecurity Incident, the costs of customer notifications and identity protection, professional fees including legal expenses, settlement costs, and commission guarantees.”

What the numbers show

The line item this footnote explains reads $1.058 million for the quarter ended June 30, 2026 — up from $301,000 in the same quarter a year earlier. Read the half-year next to it before you draw a trend: six-month costs were $1.179 million in 2026 versus $1.089 million in 2025, which is close to flat. So the fair statement is not that costs are exploding. It is that more than two years on, a line item for this breach is still open on the books and still being funded.

Two things this figure is not. It is not the whole cost of the breach — loanDepot told investors back in its 2023 annual report that it expected roughly $12 to $17 million of incident expenses in the first quarter of 2024 alone, net of expected insurance recovery. And it is not the “amounts accrued” mentioned in the legal note above; those are money set aside against future liability, which is a different thing from money already spent. In 2024 the company recorded a $25.0 million accrual in connection with the consolidated class action brought over this breach. The “settlement costs” you see listed in the footnote below are a standing category label for what this bucket can include — not an announcement that regulators have settled anything.

Infographic showing loanDepot's own SEC filings shifted from 'not reasonably estimable' in the May 2026 10-Q to 'considered probable' loss in the August 2026 10-Q, for the same January 2024 data breach investigations.
Steve’s read: what loanDepot told the SEC three months apart — same breach, stronger language. The quoted wording is the company’s; the interpretation is mine, and nothing here is a finding that loanDepot did anything wrong.

What these legal words actually mean

“A loss is probable” (but not “estimable”)

In plain English

Under the accounting rules public companies follow (ASC 450, contingencies), a company has to book a reserve on its books once a loss is both probable and reasonably estimable. loanDepot is telling investors it has now crossed the first bar — it expects to lose money over this — but not the second: it still can’t put a number on it. In my experience that combination points to active, unresolved negotiations rather than a case quietly fizzling out — though that is my inference, not something the filing says.

A state attorney general “investigation” is not a consent order

In plain English

It’s worth being precise here, because the two get confused. A consent order is a formal, public settlement between a company and a regulator that spells out findings, penalties, and required changes — think of it as the ending. loanDepot’s filings describe something earlier in that process: multiple state regulators and attorneys general still actively investigating, with no public settlement, fine, or consent order announced in any filing I read as the outcome of those investigations. Be precise about the boundary, because the two get blurred: private class actions over the same breach are a separate track that has moved on its own timetable, and the company disclosed a $25.0 million accrual in that consolidated litigation back in 2024. What is still open, and unsettled, is the regulator and attorney general side.

Why a mortgage lender’s breach is a bigger deal than most

In plain English

Not all data breaches carry the same risk. A retailer’s breach might expose your card number, which your bank can cancel and reissue in a day. A mortgage lender’s application file typically includes your Social Security number, income, employer, bank account and asset statements, and often your spouse’s information too — the exact ingredients someone needs to open new credit in your name or file a fraudulent tax return. That’s why freezing your credit matters more, not less, when the breached company is a lender.

What this means for you

If you applied for, refinanced, or closed a loan with loanDepot around the January 2024 timeframe — or received a breach notification letter from the company — this filing is a reason to check back in, not a reason to relax. The investigations that could produce a settlement, restitution, or additional relief for affected customers are still open more than two years later, and the company itself now says it expects to pay something, even though it can’t say what yet.

What I’d do — If you haven’t already, place a free credit freeze with all three bureaus; a freeze costs nothing and doesn’t expire. Pull your free credit reports at annualcreditreport.com and look for accounts you didn’t open. Keep any breach notification letter or email you received — if a settlement or restitution program eventually opens (through a state AG action or a class action), you’ll likely need proof you were a customer. And if fraudulent debt already shows up in your name because of a breach like this, that’s identity theft debt, not debt you owe — my identity theft guide walks through how to dispute it.

Steve’s bottom line

We treat a data breach notice like a closed chapter the moment the letter arrives. loanDepot’s own SEC filings tell a different story: more than two and a half years after the fact, the investigations are still open, the company now tells investors a loss from them is probable, and a line item for this breach is still being funded more than two years on. Nothing in these filings says loanDepot did anything wrong — that is for the regulators to determine, and no consent order, fine, or settlement has been announced as the outcome of those investigations. (The separate private class action over the same breach has moved on its own track, and the company disclosed a $25.0 million accrual there back in 2024.) What it does say is that “it’s been a while, so it must be over” is not a safe assumption — for this breach or the next one that lands in your inbox.

Frequently asked questions

What did loanDepot’s SEC filing say about its 2024 data breach?

In its 10-Q for the quarter ended June 30, 2026 (filed August 6, 2026), loanDepot disclosed it is still cooperating with state regulators and attorneys general on ongoing investigations into a January 2024 cybersecurity incident, and that it now believes “a loss is probable” but cannot yet estimate how much, beyond amounts already accrued.

Is this the same as a CFPB enforcement action or a consent order?

No. Reading every quarterly and annual report loanDepot has filed since the breach, I found no consent order and no CFPB enforcement action connected to it. What the filings describe are ongoing state regulator and attorney general investigations that have not, as of these filings, produced a public settlement, fine, or consent order. Keep that separate from the private class action brought over the same breach, which is its own track — the company disclosed a $25.0 million accrual in that litigation in 2024.

How is this different from what loanDepot said three months earlier?

In its prior 10-Q (filed May 7, 2026, for the quarter ended March 31, 2026), loanDepot said it “does not believe that a loss is reasonably estimable in these matters at this time.” The August 2026 filing changed that language to say a loss is now “probable,” while still not putting a dollar figure on it. That is a documented change in what the company discloses. Whether its internal view changed, or it simply hadn’t said so before, the filings don’t tell us — under the accounting rules a loss can be probable and still not reasonably estimable at the same time.

My data may have been in the loanDepot breach. What should I do?

Place a free credit freeze with all three credit bureaus, pull your free credit reports and look for unfamiliar accounts, and keep any breach notification you received. If fraudulent debt shows up in your name as a result, that’s identity theft debt you can dispute, not debt you legitimately owe.

Does a company have to tell investors about an unresolved data breach investigation?

Yes, generally. Public companies must disclose loss contingencies once a loss becomes probable or reasonably possible and is material, under U.S. accounting rules (ASC 450) and SEC disclosure requirements — separate from and in addition to whatever it tells customers.

Read it yourself — the primary sources

loanDepot, Inc. — Form 10-Q, quarter ended June 30, 2026, filed August 6, 2026 (SEC.gov) →
loanDepot, Inc. — Form 10-Q, quarter ended March 31, 2026, filed May 7, 2026 (SEC.gov) →

The Cybersecurity Incident disclosure is in Note 15, “Commitments and Contingencies,” in both filings; the cost figures are in the Reconciliation of Non-GAAP Measures section of the August filing. To find any company’s filings yourself, search the company name at sec.gov/edgar/search.

How to read this

Two different things appear above, kept separate on purpose. The quotes in the gray boxes are fact — loanDepot’s own words, from its own SEC filings, public record filed under penalty of law, quoted verbatim and linked. The plain-English explanations and the amber notes are my interpretation, offered to help you understand what changed — not loanDepot’s position, and not a statement about any individual customer’s situation.

Nothing here says loanDepot did anything wrong. Across every quarterly and annual report loanDepot has filed since the breach, I found no consent order, fine, settlement, or regulatory finding announced as the outcome of the state investigations — those remain ongoing. The private class action over the same breach is a separate matter with its own history, including a $25.0 million accrual the company disclosed in 2024. I’m using its own filings as evidence that “the breach was two years ago, it must be resolved by now” is not a safe assumption, not as a claim about the outcome of any investigation. This is general information and my opinion after more than 30 years helping people with debt, not legal advice. If you believe you were harmed by this breach, or by identity theft that resulted from it, talk to a consumer attorney or your state attorney general’s office about your specific situation.

Got a loanDepot data breach notice sitting in a drawer somewhere? Please forward this to anyone who might have one. Most people never check back in after the first letter.

Dealing With Debt? Understanding your options is the first step. See how all your debt relief options compare — including ones most sites won’t tell you about. The Find Your Path quiz gives a recommendation based on your actual numbers, and the Scam-O-Meter checks any company’s complaint history before you sign. Federal Reserve Bank of New York research shows bankruptcy filers recover faster than those who don’t file.

“What They Told Wall Street” reads the SEC filings of the companies that handle your money and translates what they admitted — one filing at a time. Sourced entirely from public SEC records. · See the whole series →

author avatar
Steve Rhode The Get Out of Debt Guy | Consumer Debt Expert
Consumer debt expert & investigative writer. Personal bankruptcy survivor (1990). Washington Post award-winning author. Exposing debt scams since 1994.