Plaza Home Mortgage

Plaza Home Mortgage

Offers wholesale and correspondent mortgage financing

Overview

Plaza Home Mortgage offers mortgage lending in the United States, with conventional fixed-rate loans, adjustable-rate mortgages, FHA loans, VA loans, home equity loans, and reverse mortgages. It operates through two channels: Wholesale, which partners with brokers and originators, and Correspondent, which provides liquidity and loan execution for banks and mortgage lenders. Revenue comes from origination and servicing fees, as well as interest, and it has reintroduced the Solutions Non-QM program for borrowers who don’t meet traditional criteria. The company focuses on two-channel operations, client education, and technology updates to improve lending processes and customer service, aiming to provide flexible loan options and efficient processing while growing its servicing portfolio.

About Plaza Home Mortgage

Simplify's Rating
Why Plaza Home Mortgage is rated
C
Rated C on Competitive Edge
Rated B on Growth Potential
Rated D+ on Differentiation

Industries

Financial Services

Real Estate

Company Size

501-1,000

Company Stage

N/A

Total Funding

N/A

Headquarters

San Diego, California

Founded

2000

Get referred to Plaza Home Mortgage

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Q1 2026 originations reached about $2 billion, up 32% year over year.
  • Plaza’s Non-QM and DSCR updates on August 26, 2026 support specialty-volume growth.
  • Complimentary identity monitoring and remediation steps reduce immediate customer churn after the breach.

What critics are saying

  • February 17, 2026 breach exposed 137,976 people; lawsuits follow now.
  • Silent Ransom Group’s claim and class actions threaten margins, trust, and retention.
  • A March 2026 cyber-failure during mortgage volatility can drive broker defection and existential reputational damage.

What makes Plaza Home Mortgage unique

  • Plaza’s wholesale-correspondent model serves brokers and lenders, not direct consumer acquisition.
  • Its Solutions Non-QM and DSCR programs target borrowers traditional banks reject.
  • Plaza ranked 39th nationally in Q1 2026, showing durable scale.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Hybrid Work Options

Company News

TEISS
Jun 11th, 2026
Plaza Home Mortgage says February data breach affected over 135,000 customers.

Plaza Home Mortgage says February data breach affected over 135,000 customers. News 11 Jun 2026 American mortgage lender Plaza Home Mortgage said a data security incident it suffered in February compromised the sensitive personal information of over 135,000 customers. Headquartered in San Diego, California, Plaza Home Mortgage is a financial services company specialising in wholesale and correspondent lending, partnering with mortgage brokers and other financial institutions rather than originating loans directly to the consumer community. In a data security incident notice filed with the Office of Maine Attorney General, Plaza Home Mortgage said that on February 17, it experienced a data security incident in which an unauthorised party gained access to an employee's computer. The company immediately launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident. "Threat actors illegally accessed our information systems without permission. Our security controls immediately informed us about the access, and we took action immediately to shut down the attack. Based on our investigation about this issue, an unauthorised party may have obtained some of your personal information," Plaza said in its letter to affected customers. The compromised data included names, addresses, social security numbers, birth dates, driver's license or other government identification documents and more. The financial services company's filing with the Maine state regulator revealed that at least 137,976 individuals were impacted by the incident. "We took immediate actions to remove the threat actor from our systems and other security measures to further secure our information systems and your personal information. We have implemented additional organisational, technical and administrative security measures to prevent the recurrence of this security incident and to protect the personal information of our customers," Plaza added. The company has advised all affected individuals to regularly monitor their credit reports, account and benefit statements and report any suspicious activity to law enforcement authorities, including the police and the state attorney general. It has also offered one year of complimentary identity protection and credit monitoring services through CyEx to all affected individuals. In March, the Silent hacker group claimed responsibility for the cyber attack on Plaza Home Mortgage and listed the company as a victim on its data leak site. The group claimed to have exfiltrated confidential data from the company and threatened to release it publicly unless the company paid a ransom to regain access to the stolen files.

How to Perform a Securitization Audit
Jun 9th, 2026
Plaza Home Mortgage facing class actions after data breach.

Plaza Home Mortgage facing class actions after data breach. A notable cyber threat actor alleged it was behind a ransomware attack that impacted nearly 138,000 individuals, a claim refuted by the lender.

Comparitech
Jun 8th, 2026
Plaza Home Mortgage warns 138,000 people of data breach that leaked SSNs.

Plaza Home Mortgage warns 138,000 people of data breach that leaked SSNs. Tech Writer, Privacy Advocate and VPN Expert Updated: June 8, 2026 Plaza Home Mortgage over the weekend confirmed it notified 137,976 people of a February 2026 data breach that compromised the following personal info: * Names * Social Security numbers * Info related to mortgage loan applications and servicing * Government-issued IDs (e.g. driver's licenses) * Addresses * Birth dates A cybercriminal gang called Silent Ransom Group took credit for the breach on March 22, 2026. Plaza has not acknowledged Silent's claim and Comparitech cannot independently verify its authenticity. Comparitech Ltd. do not know if Plaza paid a ransom, how much Silent demanded, or how attackers breached Plaza's network. Comparitech contacted Plaza for comment and will update this article if it replies. "Plaza Home Mortgage, Inc. experienced a security incident involving unauthorized access to one employee's computer on or around February 17, 2026. Threat actors illegally accessed our information systems without permission," says Plaza's notice to breach victims. "Based on our investigation about this issue, an unauthorized party may have obtained some of your personal information." Plaza is offering breach victims 12 months of free credit monitoring through CyEx. Who is Silent Ransom Group? Silent Ransom Group, formerly called LeakedData, is a ransomware group that first surfaced in December 2024. It mostly targets US financial and legal businesses. Its malware does not encrypt files, instead relying on data theft and extortion. Silent has claimed responsibility for 95 data breaches in total. Of those, 20 were confirmed by the organizations targeted. Aside from Plaza, Silent has taken credit for four other data breaches this year: * Hawaii Employers' Mutual Insurance reported a data breach in February 2026 * Singleton Schreiber notified 232 people of a February 2026 data breach * Jones Day reported a March 2026 data breach for which Silent demanded $13 million * Weil, Gotshal & Manges refused to pay Silent a $20 million ransom after a data breach earlier this year Ransomware attacks on US finance. Comparitech researchers have logged 10 confirmed ransomware attacks on US financial firms in 2026 to date. The resulting data breaches compromised 304,000 records. Silent's attack on Plaza is the second largest such breach this year by number of records compromised. The largest hit Beacon Mutual Insurance Company, which notified 162,439 people of a January 2026 data breach claimed by INC. Last year, Comparitech Ltd. recorded 70 ransomware attacks on US finance companies, which compromised more than 2 million records. Other such recently confirmed ransomware attacks include: * American Lending Center notified 123,158 people of a July 2025 ransomware attack * US Tiger Securities notified 26,985 people of a July 2025 ransomware attack * Industrial Acceptance Corporation notified 79,216 people of a February 2025 data breach claimed by INC * IMA Diligence Services notified 525,306 people of a December 2025 data breach claimed by Genesis Ransomware attacks on financial firms can both steal data and lock down computer systems. Once infected, the attacker then demands a ransom to delete stolen data and restore systems. Companies that refuse to pay can face extended downtime, permanent data loss, and putting customers at increased risk of fraud. About Plaza Home Mortgage. Founded in San Diego, CA in 2000, Plaza Home Mortgage is a wholesale and correspondent mortgage lender.

TEISS
Jun 2nd, 2026
Plaza Home Mortgage discloses data breach affecting customers and employees.

Plaza Home Mortgage discloses data breach affecting customers and employees. News 02 Jun 2026 Plaza Home Mortgage, a wholesale and correspondent mortgage lender, has disclosed a data breach that may have exposed the personal information of customers and employees. The company said the incident occurred on or around Feb. 17, 2026, when threat actors gained unauthorized access to an employee's computer and illegally accessed its information systems. Plaza said its security controls detected the activity immediately, allowing the company to take action to shut down the attack. However, the company said customer information may have been compromised, including names, addresses, Social Security numbers, dates of birth, driver's license numbers or other government identification details, and information related to mortgage applications and servicing. For Plaza employees, the potentially exposed information also includes usernames and passwords for company accounts. The company has not publicly disclosed the exact number of affected individuals or the states involved. California-based Plaza Home Mortgage ranked as the 39th-largest mortgage lender in the U.S. during the first quarter of 2026, according to Inside Mortgage Finance. The company originated about $2 billion in loans during the period, a 32% increase from the previous year. Following the incident, Plaza said it launched an investigation and removed the threat actor from its systems. The company also said it implemented additional organizational, technical, and administrative security measures to prevent a similar incident from happening again. Plaza notified affected customers and employees on May 29. The company said it will provide free access to credit monitoring, identity monitoring, and identity restoration services to impacted individuals. "We are very sorry for any concerns that this incident has caused our customers and employees. We will continue to monitor our security systems to safeguard our customers' and employees' information and privacy," said Kevin Parra, co-founder, chairman, and CEO of Plaza Home Mortgage. The disclosure adds Plaza to a growing list of mortgage companies affected by cyberattacks and data compromises. In March 2026, US Mortgage Corp. faced a class-action lawsuit following a May 2025 breach that allegedly exposed sensitive information on the dark web. In July 2025, New American Funding also reported a data breach involving a vendor that may have compromised customer data.

Rankiteo
May 29th, 2026
Plaza Home Mortgage: Plaza Home Mortgage Confirms Data Breach, urges action from victims.

Plaza Home Mortgage: Plaza Home Mortgage Confirms Data Breach, urges action from victims. Plaza Home Mortgage Confirms Data Breach Following Ransomware Attack Plaza Home Mortgage, a national mortgage lender based in Costa Mesa, California, has notified customers and employees of a data breach stemming from a ransomware attack earlier this year. The company, which operates nationwide and specializes in wholesale and correspondent lending, disclosed the incident on May 29, 2026, through third-party notice administrator Simpluris, Inc. The breach appears linked to a February 27, 2026, attack claimed by the ransomware group SilentRansomGroup, which threatened to release sensitive data if ransom demands were not met. Initial reports suggested the compromise included employee records, user data, and third-party credentials, though the full scope remains unclear. While the February incident cited exposure for at least 54 users and 10 employees, the true number of affected individuals has not been publicly disclosed. Plaza Home Mortgage, founded in 2000 with over 900 employees and nearly $280 million in annual revenue, handles highly sensitive financial data, including Social Security numbers, bank account details, and loan information. The breach places the company under regulatory scrutiny, particularly under the Gramm-Leach-Bliley Act (GLBA), which requires financial institutions to report breaches affecting 500 or more consumers to the FTC within 30 days. State-level laws, including California's strict notification requirements, may also apply. The three-month gap between the attack and official notification reflects the complexity of breach investigations, during which companies must assess the extent of exposure and identify affected parties. Simpluris, a firm specializing in breach response, is managing victim communications and remediation efforts. The incident may also trigger legal challenges, including potential class-action lawsuits, depending on whether the company's security measures are deemed adequate. Affected individuals have been directed to a dedicated portal for details on protective measures, though specific data exposed and remediation services offered remain undisclosed. The breach underscores the ongoing risks of ransomware attacks targeting financial institutions and the prolonged impact on victims. "id": "pla1780136871", "linkid": "plaza-home-mortgage", "type": "Ransomware", "date": "5/2026", "severity": "100", "impact": "4", "explanation": "Attack with significant impact with customers data leaks" {'affected_entities': [{'industry': 'Financial Services', 'location': 'Costa Mesa, California, USA', 'name': 'Plaza Home Mortgage', 'size': '900+ employees, $280 million annual revenue', 'type': 'Mortgage Lender'}], 'customer_advisories': 'Dedicated portal for details on protective measures', 'data_breach': {'data_exfiltration': 'Threatened by ransomware group', 'personally_identifiable_information': 'Yes', 'sensitivity_of_data': 'High', 'type_of_data_compromised': ['Employee records', 'User data', 'Third-party credentials', 'Social Security numbers', 'Bank account details', 'Loan information']}, 'date_detected': '2026-02-27', 'date_publicly_disclosed': '2026-05-29', 'description': 'Plaza Home Mortgage, a national mortgage lender based in ' 'Costa Mesa, California, has notified customers and employees ' 'of a data breach stemming from a ransomware attack earlier ' 'this year. The breach appears linked to a February 27, 2026, ' 'attack claimed by the ransomware group SilentRansomGroup, ' 'which threatened to release sensitive data if ransom demands ' 'were not met. Initial reports suggested the compromise ' 'included employee records, user data, and third-party ' 'credentials. The breach places the company under regulatory ' 'scrutiny, particularly under the Gramm-Leach-Bliley Act ' '(GLBA), and may trigger legal challenges, including potential ' 'class-action lawsuits.', 'impact': {'brand_reputation_impact': 'Potential reputational damage', 'data_compromised': 'Employee records, user data, third-party ' 'credentials, Social Security numbers, bank ' 'account details, loan information', 'identity_theft_risk': 'High', 'legal_liabilities': 'Potential class-action lawsuits', 'payment_information_risk': 'High'}, 'investigation_status': 'Ongoing', 'motivation': 'Financial gain', 'ransomware': {'data_exfiltration': 'Threatened', 'ransomware_strain': 'SilentRansomGroup'}, 'references': [{'source': 'Simpluris, Inc. (third-party notice ' 'administrator)'}], 'regulatory_compliance': {'legal_actions': 'Potential class-action lawsuits', 'regulations_violated': ['Gramm-Leach-Bliley Act ' '(GLBA)', 'California state breach ' 'notification laws'], 'regulatory_notifications': 'FTC (if 500+ consumers ' 'affected)'}, 'response': {'communication_strategy': 'Dedicated portal for affected ' 'individuals', 'third_party_assistance': 'Simpluris, Inc.'}, 'threat_actor': 'SilentRansomGroup', 'title': 'Plaza Home Mortgage Data Breach Following Ransomware Attack', 'type': 'Ransomware'} Published by CBSE Revaluation Portal Hit by Cyberattack, Affecting 50 Students A malicious cyberattack targeted the Central Board of Secondary Education (CBSE)... May 30, 2026 Palo Alto Networks PAN-OS Authentication Bypass Vulnerability Exploited in the Wild On May 29, 2026, CISA added CVE-2026-0257, a critical... May 29, 2026 Cyberattack Disrupts Nevada's Washoe County School District Operations On [date not specified], the Washoe County School District (WCSD) in... May 29, 2026

Recently Posted Jobs

Sign up to get curated job recommendations

There are no jobs for Plaza Home Mortgage right now.

Find jobs on Simplify and start your career today

We update Plaza Home Mortgage's jobs every few hours, so check again soon! Browse all jobs →