SitusAMC, a vendor providing loan origination and servicing support for residential and commercial real estate, suffered a cyberattack on 12 November 2025. Reporting describes compromised corporate data including accounting records and legal agreements belonging to client institutions, among them JPMorgan Chase, Citi and Morgan Stanley.
Named Institutions, Unnamed Exposure
The corpus filed at 25-0814 that a compromise at an analytics vendor reached data belonging to customers of 74 banks and credit unions, and observed that seventy-four independent due-diligence processes established nothing about whether the vendor patched its perimeter.
This is the same structure at the top of the market. The institutions involved are among the largest and most heavily supervised financial firms in the world, with the most demanding third-party risk programmes in this database.
That is the finding. Vendor assessment at its most rigorous did not prevent this, which is consistent with the corpus’s repeated conclusion that the instrument measures the existence of a control framework rather than its operation.
Mortgage Servicing Accumulates Unusually Complete Files
A loan file contains income verification, tax returns, bank statements, employment history, property details and identity documents — assembled at origination because a lender requires all of it to make a decision.
It is arguably the densest financial record an ordinary person produces, and this desk made the same observation about credit applications at 25-1105. A servicing vendor holds those files for institutions the borrower has a relationship with, and has none itself.
What Is Not Established
The reporting this desk reviewed describes corporate data — accounting records and legal agreements — rather than consumer loan files. Whether borrower data was reached is not established here and we do not assert it.
That distinction matters for what follows, and it is the subject of 25-1124b.
Compiled from public reporting and regulatory guidance, listed below. The extent of any consumer data exposure is not established. Corrections: corrections@forensicpost.com.