
One of the nation's largest homebuilders, Lennar Corp., disclosed a data breach that may have exposed the sensitive personal information.
An unauthorized party used "sophisticated social engineering tactics" to access some of Lennar's information systems over a seven-day period from March 24 through March 30, 2026. Social engineering is a type of cyberattack in which hackers trick people into giving up access to systems or information, rather than breaking in through technical means alone.
The company described the intrusion as affecting "a limited portion" of its information systems. Upon identifying the issue, Lennar said it immediately took steps to secure its systems and brought in a third-party forensics team to investigate the scope of the unauthorized activity.
The forensic investigation included an assessment of what sensitive personal information may have been accessed during the breach. That assessment concluded on July 30, 2026, approximately four months after the incident was first identified.
The types of personally identifiable information that may have been exposed included names, contact information, dates of birth, Social Security numbers, passport or other government ID information, driver's license or other state ID information and financial account information.
A small number of individuals may have also had health-related information involved, like health insurance IDs or medical-related information.
The breach was first reported to the Nebraska Attorney General, which identified one Nebraska resident as potentially affected.
Lennar Corp. discovered the breach on March 30, 2026, and is scheduled to begin mailing notification letters to affected consumers on Aug. 11, 2026. The company has also posted a notice of the privacy event on its website.
Lennar Corp. arranged for two years of free identity monitoring services through Kroll as a precaution. The Kroll monitoring package includes single bureau credit monitoring, which sends alerts when changes are made to an individual's credit file.
It also provides unlimited fraud consultation with Kroll specialists and identity theft restoration, in which a licensed Kroll investigator works on behalf of victims to resolve identity theft issues.
Affected individuals can enroll in the monitoring services by visiting the Kroll monitoring enrollment page. To receive credit monitoring services, individuals must be over age 18, have established credit in the United States and have a Social Security number and U.S. residential address associated with their credit file.
Enrollment must be completed by Nov. 13, 2026. More details about the monitoring program are available at Kroll's information page.
Individuals with questions about the breach can call 844-958-8940, Monday through Friday, from 9:00 a.m. to 6:30 p.m. Eastern Time, excluding major U.S. holidays. Callers should have their membership number ready, which is included in each notification letter.








.webp)
.webp)
.webp)

.webp)
.webp)
.webp)
.webp)