Borrowers sue Lennar, alleging breaches exposed Social Security numbers

Two breaches in two months, and tens of thousands of homebuyers caught in the fallout

Borrowers sue Lennar, alleging breaches exposed Social Security numbers

Two breaches at Lennar exposed mortgage borrowers' Social Security numbers and financial data - and the warnings came months late, a class action alleges. 

A Goodyear, Arizona homeowner has taken homebuilder Lennar Corporation and its mortgage arm, Lennar Mortgage, LLC, to federal court, claiming the companies failed to protect a broad range of customers' personal and financial information and then waited months to tell them. 

The class action, filed August 24, 2026, in the US District Court for the Southern District of Florida, says Lennar was hit by two separate data breaches within about two months. Both, according to the filing, were carried out through “social engineering” - the practice of tricking employees into handing over access. 

The suit lays out the timeline in two parts. Lennar Corporation learned on or about March 30, 2026, that intruders had been in its systems between roughly March 24 and March 30, the filing says. Weeks later, it alleges, the mortgage business was hit: Lennar Mortgage, LLC found on or about June 1 that attackers had been inside its systems between about May 26 and June 1. 

According to court papers, both breaches involved names, contact details, dates of birth, Social Security numbers, passport or other government ID information, driver's license or state ID information, and financial account information. For a mortgage borrower, that covers much of the loan file. 

The person who filed the suit bought a Lennar home in 2024 and financed it through Lennar Mortgage. His notice letter, postmarked August 14, 2026, told him his name, contact information, date of birth and Social Security number were among the data involved, the filing says. That was almost four months after the first intrusion began, the filing notes. The delay, the suit claims, left customers without the time they needed to freeze their credit and watch their accounts before the data could be misused. 

The filing says Lennar reported that at least 61,295 people were affected. It puts the amount in dispute above $5 million. 

Much of the case leans on Lennar's own promises. The suit quotes the company's privacy policy, which says Lennar “maintains commercially reasonable administrative, technical and physical safeguards,” and Lennar Mortgage's privacy notice, which says its security measures “comply with federal law.” Those promises were not kept, the lawsuit alleges, describing the conduct as a “flagrant disregard of the rights of Plaintiff and the Class.” 

The borrower brings three claims: negligence, breach of an implied contract to protect customer data, and unjust enrichment. The suit also points to a federal consumer-protection law, the FTC Act, to argue Lennar had a duty to guard the information. It asks for damages and for a court order requiring the company to strengthen its security and pay for credit monitoring, which the filing puts at $200 or more a year. 

Much of the suit's focus is on timing. It treats the gap between the first breach and the first notice as a failure on its own, separate from the breaches themselves. For lenders and servicers, that is the part worth watching: how quickly customers are told can draw as much legal attention as how the data was stored. 

The allegations have not been tested in court. No judge has ruled on them.