Back to news
Cybersecurity Alert
June 5, 2026 by EmailMeNow IT Consulting

Cybersecurity Audit of Major U.S. Mortgage Lenders in 2026

Independent audits of the largest U.S. mortgage lenders — Rocket Mortgage, UWM, loanDepot, and more — reveal a wide range of cybersecurity results. Weak email authentication is a direct path to closing wire fraud.

MortgageReal EstateWire FraudCFPBEmail Security
Digital audit dashboard with a United States map showing cybersecurity scores of mortgage lenders

An independent cybersecurity review across the largest mortgage lenders in the United States — national retail and wholesale mortgage originators and servicers including Rocket Mortgage, United Wholesale Mortgage, and loanDepot — reveals a surprisingly wide range of results. These organizations handle sensitive customer and financial data at national scale, yet several show the same email-authentication gaps found at much smaller regional institutions.

Using data from audit.emailmenow.com, we evaluated each lender’s primary domain across email, website, and network security — including SPF, DKIM, DMARC, MTA-STS/TLS, and security headers.

In this national audit, scores ranged from 70% to 38%9 of 18 (50%) scored below 60%.

Cybersecurity Scores of Mortgage Lenders

Overall compliance scores from audit.emailmenow.com. Re-run any domain at the link to verify.

RankMortgage LenderDomainOverall ScoreWebsite ScorePerformance Level
1United Wholesale Mortgageuwm.com70%45%Good
2Better Mortgagebetter.com68%92%Above Average
3Guild Mortgageguildmortgage.com67%70%Above Average
4loanDepotloandepot.com66%45%Above Average
5Movement Mortgagemovement.com64%92%Above Average
5Freedom Mortgagefreedommortgage.com64%45%Above Average
5Chase Home Lendingchase.com64%45%Above Average
8Guaranteed Raterate.com62%45%Above Average
9Mr. Coopermrcooper.com61%45%Above Average
10PennyMacpennymac.com58%45%Average
11AmeriHome Mortgageamerihome.com55%45%Average
12Fairway Independentfairwaymc.com54%45%Average
12CrossCountry Mortgageccm.com54%45%Average
12Wells Fargo Home Mortgagewellsfargo.com54%45%Average
15Caliber Home Loanscaliberhomeloans.com52%45%Average
16New American Fundingnewamericafunding.com48%45%Below Average
16Homepointhomepoint.com48%45%Below Average
18Rocket Mortgagerocketmortgage.com38%45%Weak

Website Security Scores

Scores ranged from 92% to 45%; 0 of 18 reached the 100% ideal and 15 scored below 60%.

RankMortgage LenderDomainWebsite ScoreRating
1Better Mortgagebetter.com92%Strong
1Movement Mortgagemovement.com92%Strong
3Guild Mortgageguildmortgage.com70%Good
4United Wholesale Mortgageuwm.com45%Below Average
4loanDepotloandepot.com45%Below Average
4Freedom Mortgagefreedommortgage.com45%Below Average
4Chase Home Lendingchase.com45%Below Average
4Guaranteed Raterate.com45%Below Average
4Mr. Coopermrcooper.com45%Below Average
4PennyMacpennymac.com45%Below Average
4AmeriHome Mortgageamerihome.com45%Below Average
4Fairway Independentfairwaymc.com45%Below Average
4CrossCountry Mortgageccm.com45%Below Average
4Wells Fargo Home Mortgagewellsfargo.com45%Below Average
4Caliber Home Loanscaliberhomeloans.com45%Below Average
4New American Fundingnewamericafunding.com45%Below Average
4Homepointhomepoint.com45%Below Average
4Rocket Mortgagerocketmortgage.com45%Below Average

What the Results Reveal

  • Scores range from 70% (United Wholesale Mortgage) down to 38% (Rocket Mortgage) — only one major retail brand reaches a strong (70%+) posture.
  • Rocket Mortgage (38%), the nation’s largest retail originator by volume, scores lowest in the field — well below wholesale leader UWM (70%).
  • The gap from top to bottom is 32 points — household brand recognition does not predict closing-security posture.
  • Without an enforced DMARC policy, criminals can spoof a lender’s own domain to send fraudulent wiring instructions during loan closings.

Attack exposure in this audit

Domains scoring near 38% combine weak identity enforcement, missing inbound transport protections, and sub-60% website hardening. Without naming specific organizations, entities in that tier are disproportionately exposed to:

  • Closing wire fraud — spoofed lender or title mail sent in the last hour before recording, redirecting borrower down payments and cash-to-close.
  • Business email compromise (BEC) — spoofed messages appearing to come from executives or accounts payable, used to redirect wires and ACH payments.
  • Brand impersonation phishing — fake billing, HR, and vendor notices that pass visual inspection because DMARC and SPF are not fully enforced.
  • Credential harvesting — login pages linked from forged @company.com mail aimed at employees, contractors, and customers.
  • Invoice and procurement fraud — altered payment instructions sent to finance teams and partners who trust the corporate domain.
  • Account-recovery abuse — password-reset and MFA prompts triggered from impersonated sender addresses.
  • Inbound mail downgrade attacks — absence of enforced MTA-STS allows opportunistic TLS stripping on messages destined for the organization.
  • Clickjacking and session risks — missing HSTS, CSP, and frame protections on the public site increase browser-side attack surface for visitors and logged-in users.
  • Supply-chain targeting — partners who whitelist the domain for deliverability become secondary victims when spoofed mail originates unchecked.
  • Header gaps at scale15 of 18 domains scored below 60% on website security in this audit. Clickjacking and session risks are not confined to the bottom tier; many names share a 45% website score — the same floor shared by 14 other domains in this audit.

These are not theoretical edge cases. State breach portals and FBI IC3 reporting consistently tie weak email authentication and header gaps to measurable financial loss at large enterprises.

Real attacks, told as stories

The stories below are made up, but they are based on real crimes that police and cybersecurity teams see every year. No major U.S. mortgage lender is named. Each story shows how weak domain settings can hurt real people — customers, partners, and staff who trust mortgage lenders.


Story 1: Maria and the payment that was not real

Illustration: closing coordinator reviewing fraudulent wire instructions

Maria works in a closing coordinator at Lakeview Title, a settlement partner for a national lender.

On a Tuesday morning, she gets an email that looks normal:

From: accounts-payable@bigbrand.com
Subject: Final wire instructions for Friday closing

The logo looks right. The tone sounds like past closing emails. A PDF lists a new routing number.

Maria does not know that bigbrand.com has weak email security. A stranger sent the message from their own server and pretended to be the big brand. That is called brand impersonation.

She approves a $284,000 wire. The money goes to the attacker, not the real company.

The next day, the same fake sender emails two more partners Maria knows from title industry events. One ignores it. One also changes bank details. That is supply-chain targeting — hurting partners by faking the main organization’s name.

Attack vectors in this story: brand impersonation · invoice and procurement fraud · supply-chain targeting · business email compromise (BEC)

Simple fix: Strict DMARC (p=reject), SPF (-all), and a rule that every bank change needs a phone call to a known contact — not just email.


Story 2: Jordan clicks “reset password”

Illustration: loan processor facing a fake lender password reset

Jordan is a loan processor at a national mortgage lender. On Wednesday at 2 p.m., his phone buzzes:

From: it-security@bigbrand.com
Subject: Reset your password in 2 hours or lose access

Jordan is busy. The email looks like IT mail he has seen before. He clicks the link.

The page looks like his company login. It is not. It is a copy on a similar-looking website (bigbrand-secure.com). He types his username and password. The attacker saves them.

This is account-recovery abuse and credential harvesting. The criminal used a fake “reset your account” message because people trust mail from @company.com.

That night, the attacker signs into Jordan’s mailbox and reads old threads about a borrower escrow release. On Thursday, they email the CFO’s assistant:

From: cfo@bigbrand.com
Subject: Urgent — confidential wire for escrow

That is BEC — business email compromise. The assistant almost approves it. A bookkeeper asks, “Did you talk to the CFO on the phone?” The wire stops. Jordan still has to change every password he reused.

Attack vectors in this story: account-recovery abuse · credential harvesting · business email compromise (BEC)

Simple fix: DMARC p=reject, train staff that IT will never rush a reset by email alone, and require a callback before any wire.


Story 3: The contract email no one knew could be copied

Illustration: closing disclosure exposed on a downgraded mail path

Priya is a closing attorney emailing final HUD figures. She emails a closing disclosure to an inbox at @bigbrand.com. The send button works. Her screen says Delivered.

What Priya cannot see: on part of the internet path, the mail server connection was downgraded from locked (TLS) to unlocked. Without MTA-STS set to mode=enforce, the recipient’s mail system still accepts the message. An attacker on that path can copy attachment text in plain form.

This is an inbound mail downgrade attack. Most people worry about fake outgoing email. MTA-STS protects incoming mail — mail sent to your organization.

Priya’s closing desk sees green checkmarks in their dashboard. Nothing looks wrong. Weeks later, borrower funds route to the wrong account minutes before recording. The leak might have started on the wire, not in someone’s inbox.

Attack vector in this story: inbound mail downgrade (no MTA-STS)

Simple fix: Publish MTA-STS in enforce mode and turn on TLS-RPT reports so IT gets alerted when encryption fails.


Story 4: Alex applies for a job online

Illustration: homebuyer trapped on a fake mortgage application page

Alex is a college senior. He is already logged into his school portal in one browser tab. In another tab, he opens a job post: “Apply for pre-approval — secure upload required.

The site asks him to “confirm your profile” on what looks like the real company careers page. He clicks.

He does not know the page is a trap. The real login screen is hidden inside an invisible frame on a scam site. That trick is called clickjacking. The company’s website scored 45% on security headers — a floor shared by 15 of 18 domains in this audit, missing strong HSTS, CSP, and frame blocking.

Alex thinks he is on the real site. He is really interacting with a layer the attacker controls. If he had been logged into the company’s vendor portal in another tab, the same trick could hijack that session.

No phishing email was needed. The attack lived on the website, not in the inbox.

Attack vectors in this story: clickjacking · session risks (missing HSTS/CSP)

Simple fix: Add HSTS, Content-Security-Policy, and frame-ancestors / X-Frame-Options so login pages cannot be embedded on random sites.


How the stories connect

All four stories can hit one organization with a weak audit score (near 38%):

StoryWho got hurtMain gap
Maria (partner)Outside partnersFake mail from your domain
Jordan (employee)Inside staffFake password-reset mail
Priya (professional)Confidential data in transitIncoming mail not forced to stay encrypted
Alex (visitor)Website visitorsLogin page can be framed by attackers

Together, that is not one bug — it is a pattern. Fixing it means better DNS (DMARC, MTA-STS), better website headers, and better office rules (call back before you wire).

Why This Matters for Mortgage Lenders

Mortgage lenders and servicers are bound by CFPB mortgage rules, GLBA safeguards, and state licensing oversight. Email authentication (SPF, DKIM, and an enforced DMARC policy) is the single highest-impact control against closing wire fraud and business email compromise that redirect borrower funds at the last hour.

Check any lender’s posture at audit.emailmenow.com/?industry=real-estate.

See also — state audits

Recommendations

  • Enforce DMARC (p=reject), strict SPF (-all), and DKIM signing.
  • Add MTA-STS and website security headers.
  • Adopt verified call-back procedures for any change to payment or wiring instructions, and train customer-facing staff.

Protect your organization. Run a free Instant Cybersecurity Audit at audit.emailmenow.com/?industry=real-estate.

Contact EmailMeNow IT Consulting for help with wire-fraud-resistant email security hardening.


Source & methodology: Overall compliance scores from the free scan at audit.emailmenow.com — each domain checked for email authentication (SPF, DKIM, DMARC), transport security (MTA-STS/TLS), website security headers, and network security. Re-run any domain at the link to verify.