Academy Mortgage Corporation
Draper, Utah
In August 2026, the California Department of Financial Protection and Innovation (DFPI) issued a consent order against Academy Mortgage Corporation. The order imposed an $825,000 administrative penalty tied to a March 2023 ransomware attack. The DFPI found that the company's cybersecurity documentation and governance failures constituted substantive violations.
Academy Mortgage agreed to cease the cited practices and provide 12 months of identity theft insurance to affected California borrowers. The action underscores state-level enforcement of cybersecurity governance standards, with direct relevance to firms managing third-party vendor relationships in financial services.
- Reinforces regulatory expectations around cybersecurity documentation for any regulated financial services entity, including BaaS participants
- Signals that vendor oversight and third-party risk management deficiencies can result in significant penalties, relevant to sponsor banks managing fintech partnerships
- State regulators are actively enforcing cybersecurity governance standards, adding compliance pressure beyond federal bank regulators
- NewsMondaq