A homebuyer's class action puts two 2026 intrusions and a mortgage arm under scrutiny
A class action says Lennar and its mortgage arm failed to stop two 2026 hacks that exposed customers' Social Security numbers and financial data.
The suit was filed on August 17, 2026, in federal court in Miami. It names Lennar Corporation, described in the filing as a national homebuilding company, and Lennar Mortgage, LLC, through which the filing says Lennar provides financing and mortgages to its customers. The plaintiff, a homebuyer who lives in South Carolina, brings the case on behalf of herself and a proposed nationwide class.
The information at issue is the kind gathered when a borrower applies for financing. According to the filing, Lennar collected names, addresses and contact information, government identification numbers, driver's license numbers, Social Security numbers, dates of birth and financial account information from customers and employees. The filing says tens of thousands of people provided it. The plaintiff says she handed hers over when she received financing through Lennar Mortgage for a home built by Lennar Corporation, and that she did so because she expected the company to protect it.
The suit describes two separate intrusions. Around March 2026, it says, unauthorized actors got into Lennar's computer systems and took files containing that information. Between May 2026 and June 2026, according to the filing, a second group did the same. The suit says Lennar disclosed the incident around August 11, 2026 and posted a public letter about the May breach stating that “names, contact information, dates of birth, Social Security numbers, passport or other government ID information, driver's license or other state ID information, and financial account information” had been compromised.
The plaintiff says the effects have already reached her. She claims she has seen unauthorized access or attempted access to at least one of her accounts, fraudulent transactions attempted in her name, and an increase in spam calls and text messages. She says she has spent time changing passwords on other accounts.
The case rests on two claims, both built on negligence rather than any allegation of intentional wrongdoing. The first says Lennar owed a duty to handle the information reasonably and did not. On information and belief, the filing lists what it says was missing: adequate employee training on phishing, social engineering and ransomware attacks; simulated phishing campaigns to test readiness; advanced email security platforms with phishing detection; real-time URL and attachment scanning; Zero Trust network architecture; endpoint detection and response systems; timely detection of unauthorized access; and prompt containment once the intrusion occurred. The filing also says the company held on to sensitive information long after it was reasonably necessary for legitimate business purposes.
The second claim, negligence per se, ties those alleged failures to Section 5 of the Federal Trade Commission Act, which bars “unfair or deceptive acts or practices in or affecting commerce.” The plaintiff's argument is that failing to use reasonable measures to protect this kind of data is itself an unfair practice under that provision.
The proposed class covers all persons residing in the United States whose information was accessed, exfiltrated or otherwise compromised in the Lennar data breach that occurred in or around 2026. Brought under the Class Action Fairness Act, the suit states that the amount in controversy exceeds $5 million. It asks the court to certify the class, award damages, and order Lennar to put in place a comprehensive information security program, engage independent third-party security auditors, train employees, and stop retaining data it no longer needs. Robbins Geller Rudman & Dowd LLP and Zimmerman Reed LLP represent the plaintiff and the proposed class. A jury trial has been demanded.
This is a newly filed complaint. The allegations have not been, and no court has ruled on any of the claims.