Skip to main content
Back to overview
Medium

American Lending Center Data Breach Affects 123,000 Individuals

American Lending Center this week revealed that a data breach discovered last year has impacted more than 123,000 individuals.

Key points

  • Data breach affected over 123,000 individuals.
  • Ransomware attack detected in July 2025.
  • Compromised data includes names, dates of birth, and Social Security numbers.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Ransomware

Threat source not confirmed

03

Potential impact

Data Exposure

Confidentiality, Availability

Published
May 15, 2026
Updated
Jul 22, 2026
Confidence
Medium
Evidence
2 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Threat source not confirmed

Watch phishing, executive impersonation and account-takeover exposure.

Business impact

Potential operational disruption
Impact area
Confidentiality, Availability
Likely asset
User or customer data

Mentioned entities

AmericanlendingcenterData DisclosureAffectsIndividuals American Lending CenterAmerican Lending CenterALCCalifornia-basedSSNsThroughMaine

Quick context

Questions about this signal

What happened in this signal?

American Lending Center this week revealed that a data breach discovered last year has impacted more than 123,000 individuals. American Lending Center (ALC) is a California-based non-bank lender that manages a $3 billion portfolio specializing in government-guaranteed small business loans. The organization is notifying individuals affected by the data breach that information such as names, dates of birth, and SSNs may have been stolen in a ransomware attack detected in July 2025.  “Through a forensic investigation into this breach, it was discovered that the threat actor compromised internal network, executed a ransomware attack, and accessed certain files that may have contained personal identifying or sensitive information,” ALC said in its notification to impacted customers, a c opy of which was submitted to the Maine attorney general’s office. The investigation was completed on April 8, and ALC has found no evidence that the potentially compromised information has been misused.  Companies often include a statement in their data breach notifications that there is no evidence of misuse, even when information has been made public by cybercriminals. Advertisement. Scroll to continue reading. In the case of ALC, no known ransomware group appears to have taken credit for the attack, which could indicate either that a ransom has been paid or that the financial institution has been targeted by a cybercrime gang that does not have a public leak website. SecurityWeek has reached out to ALC for clarification and will update this article if it responds. Related : Foxconn Confirms North American Factories Hit by Cyberattack Related : 716,000 Impacted by OpenLoop Health Data Breach Related : BWH Hotels Says Hackers Had Access to Reservation Data for 6 Months Related : Deal Reached With Hackers to Delete Data Stolen From the Canvas Educational Platform Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data Exploitation of ServiceNow Vulnerability Seen Days After Disclosure SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch New Index Tracks Material Breaches — And Refuses to Add Up the Losses WP2Shell WordPress Vulnerabilities Exploited in the Wild Two Scattered Spider Hackers Sentenced to Jail in UK ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains Cisco Launches Low-Cost AI Models for Source Code Security Empirical Security Raises $25 Million in Series A Funding SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage. CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! American Lending Center data breach impacts over 123,000 individuals American Lending Center revealed that a data breach discovered last year has impacted more than 123,000 individuals. The California-based non-bank lender, which specializes in government-guaranteed small business loans, is notifying affected individuals that personal information may have been stolen in a ransomware attack detected in July 2025, according to a recent report by Security Week. The breach involved a ransomware attack where threat actors compromised the internal network and accessed files containing personal identifying information. This potentially includes names, dates of birth, and Social Security numbers for over 123,000 individuals. A forensic investigation completed on April 8 found no evidence of misuse of the compromised data. It is unclear which ransomware group, if any, is responsible for the attack, as no known group has claimed responsibility.

When was this signal reported?

Shadow Tier lists May 15, 2026 as the signal date.

Which organization is connected to this signal?

Americanlendingcenter is the organization connected to this public signal.

Explore Americanlendingcenter
Which attack pattern is relevant?

This signal is connected to current ransomware incidents based on its reported incident context.

Explore current ransomware incidents
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence