Interlock claims data theft from NFM Lending
Interlock claims it obtained sensitive records from NFM Lending. The leak-site listing doesn't independently confirm the theft or identify whose records were involved.
- Report priority
- High
- Involves
- NFM Lending
- Group
- Interlock
What is known
- A public leak-site listing attributes the claim to Interlock.
- It alleges that the group obtained customer, loan, tax, and employee records.
- The listing doesn't disclose how access was gained, what permissions were required, or whether any systems were encrypted.
What to do
If you're an NFM Lending customer, borrower, or employee, check messages and the company's official website for a confirmed incident notice. Not receiving a notice doesn't establish whether your records were involved. If you need an answer, contact NFM Lending through details on an existing statement or its official website, describe your relationship with the organization, and ask whether it has confirmed the incident and whether your records were involved.
If NFM Lending confirms the incident, follow its official notice and verify contact details independently before providing personal information.
Reported details
The Ransomware.live entry records an Interlock leak-site claim discovered on September 7, 2026. Interlock alleges theft of more than 2.5 TB, including Encompass database records, tax forms, loan information, bank account details, Social Security numbers, and employee information. Ransomware.live indexes public operator posts without obtaining the underlying data, so neither the contents nor the amount is independently confirmed by the listing.