theLender Data Breach

Alleged

Ransomware claim involving theLender

Published: Sep 22, 2026 Termite
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
theLender
Industry
Financial Services
Threat Actor
Termite
Date of Incident
Sep 22, 2026

Executive Summary

Termite listed theLender on its dark web portal on September 22, 2026. theLender is a US mortgage and wholesale lending company operating in the financial services sector. The listing was identified through SOCRadar’s Dark Web Monitoring service. Termite claimed 6 other victims in the prior 60 days, concentrated in the United States and China across Manufacturing, Financial Services, and Healthcare. Recent US listings include TruAmerica Multifamily, Sealcon, Everglades Boats, and Affinia Healthcare. theLender’s US financial services profile fits Termite’s demonstrated targeting pattern directly.

Technical Analysis

SOCRadar’s stealer-log telemetry surfaced a severe exposure for thelender[.]com: 21 records spanning May 2025 through September 18, 2026 — more than 16 months of persistent, unrotated credential exposure. The breakdown: 11 employee credentials against organizational systems, 2 customer or third-party records on org infrastructure, and 3 corporate users on third-party SaaS platforms. Dominant profile: Mixed. High-value endpoints in the sample include the WordPress admin console (thelender[.]com/wp-login.php), the wholesale portal admin interface (wholesale.thelender[.]com/wp-login.php), and pro.realquest[.]com, a real-estate SaaS platform accessed by multiple corporate users. At least three distinct employee accounts appear across the 16-month window with no evidence of credential rotation. Sixteen months of exposure across a WordPress admin console, an internal wholesale portal, and a third-party lending platform is a textbook pre-intrusion foothold — the credential profile initial access brokers sell and ransomware operators buy. The stealer-log evidence doesn’t confirm Termite used these specific credentials; the breadth and persistence of the exposure make the point regardless.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.