Mortgage data leaked over file network
NEW YORK - Three spreadsheets containing more than 5,000 Social Security numbers and other personal details about customers of ABN Amro Mortgage Group were inadvertently leaked over an online file-sharing network by a former employee.
Context & Ripple Effects
This is the second peer-to-peer leak disclosed in a single day: eWEEK's report that Citigroup customer data surfaced on LimeWire ran alongside this AP story, suggesting the file-sharing exposure problem is hitting major financial firms simultaneously rather than being an isolated slip.
It also extends a pattern visible since the April 2007 federal database exposure of Social Security numbers — the SSN keeps leaking at scale, and here the vector is not a hacked server but a former employee's desktop running sharing software.
First-order effects
- More than 5,000 ABN Amro Mortgage Group customers have their Social Security numbers and personal details exposed to anyone on the file-sharing network, putting them at immediate identity-theft risk while the files remain retrievable.
- ABN Amro Mortgage inherits notification, credit-monitoring, and reputational costs triggered by a departed employee's machine — a breach it did not architect but owns because the data left its control.
Second-order effects
- Lenders and mortgage servicers face pressure to treat employee endpoints as the perimeter — banning or monitoring peer-to-peer clients on any machine that has touched customer spreadsheets, not just guarding central databases.
- With Citigroup hit the same way on the same day, mortgage rivals will be audited against the same failure mode, making P2P hygiene a compliance checklist item across the sector rather than a one-bank fix.
Third-order effects
- If leaks keep tracing back to individual endpoints, accountability for consumer financial data shifts toward per-employee controls and exit procedures for departing staff, changing how data-heavy firms like mortgage originators govern access after someone leaves.
- Repeated exposures of Social Security numbers — from the April federal database incident to these file-sharing leaks — strengthen the case that SSN-based identification is structurally fragile, feeding regulatory debate about whether one number should unlock so much financial identity.
The trend: Consumer financial data breaches are migrating from centralized database hacks to employee endpoints and file-sharing networks, forcing lenders to secure data at the point of use rather than only at the server.