Lennar Was Breached Twice in 2026 and Sued Nine Times in Two Weeks. Texas Alone Counts 61,295 People — and There Is No Settlement, No Claim Form and No Lead Lawyer Yet.
Lennar Corporation, the Miami homebuilder, and its mortgage arm Lennar Mortgage, LLC disclosed two separate “social engineering” intrusions in August 2026: one between March 24 and March 30, 2026, whose review ended July 30, and one between May 26 and June 1, 2026, whose review ended August 4. The Texas Attorney General's breach registry lists 769 Texans for Lennar Corporation and 60,526 for Lennar Mortgage, both entries published August 14, 2026, with data types running from Social Security numbers and government ID numbers to financial account and medical information. Lennar has not published a national total. Between August 14 and August 28, nine class actions naming Lennar Corporation and/or Lennar Mortgage were filed in the U.S. District Court for the Southern District of Florida. Four of them have since been transferred to Chief Judge Cecilia M. Altonaga, who has the first, Ramkissoon v. Lennar Corporation, No. 1:26-cv-25518, and closed as separate dockets; no formal consolidation order has issued. On September 2 she declined, for now, to appoint lead counsel because, as the plaintiffs themselves told the court, “no Defendant has yet appeared in this action.” Lennar's lawyers appeared on September 8. There is no settlement, no class and no claim form; the only thing on offer is two years of Kroll identity monitoring, and the code for it is in the letter.
By Settlement Insight Data Desk ·

Two letters, two hotlines, one wording
The two notice letters are on file with the California Attorney General, and apart from the dates, the phone number and a few state-specific paragraphs they are the same document. Lennar Corporation's version: “On March 30, 2026, we became aware of a potential issue involving a limited portion of our information systems. We immediately took steps to secure our systems and, with the assistance of a third-party forensics team, investigate the extent of this activity. We then determined that an unauthorized party used sophisticated social engineering tactics to access some of our systems between March 24, 2026, and March 30, 2026.” The review of what was taken “concluded … on July 30, 2026.” Lennar Mortgage's version puts discovery on June 1, 2026, the access window at May 26 to June 1, and the end of the review at August 4, 2026. California logged the two reports on August 11 and August 14; Texas published both entries on August 14.
The Texas registry is where the only official numbers live. It lists 769 affected Texans for Lennar Corporation and 60,526 for Lennar Mortgage, LLC, with the data types for both given as name, address, Social Security number, driver's license number, government-issued ID number, financial information (“account number, credit or debit card number”), medical information and date of birth — the corporation's entry adds health insurance information. The company told National Mortgage News on August 18 that it had “recently identified two separate, and we believe, unrelated social engineering-based cybersecurity events involving unauthorized access to certain company systems,” and that it had found no evidence of misuse. Some law-firm pages put the national total at 348,416 and attribute it to a regulatory filing; we could not find that number on any state registry we checked, and Lennar has not published one. The figure in the August 24 complaint, “at least 61,295” people, equals, to the person, the two Texas lines added together.
What the letters offer is two years of Kroll identity monitoring — single-bureau credit monitoring, fraud consultation and identity theft restoration — activated at enroll.krollmonitoring.com with the membership number printed in the letter, before an activation deadline also printed in the letter. The hotlines are (844) 958-8940 for Lennar Corporation and (844) 958-8939 for Lennar Mortgage, weekdays 9:00 a.m. to 6:30 p.m. Eastern. Both letters carry the line “This notification was not delayed as a result of a law enforcement investigation.” This is the third Lennar breach notice in three years: the California registry also lists a Lennar Corporation incident dated July 20, 2023, which Multifamily Dive reported at the time as affecting 7,448 customers' names and Social Security numbers, with Experian monitoring offered.
Nine complaints, four judges, one chief judge
The docket sheets on CourtListener show nine cases naming Lennar Corporation and/or Lennar Mortgage filed in the Southern District of Florida between August 14 and August 28, 2026: Ramkissoon (No. 1:26-cv-25518, August 14, Dynamis LLP, assigned to Chief Judge Altonaga); Stewart (1:26-cv-25529, August 14, Aylstock, Witkin, Kreis & Overholtz); DiMeglio (1:26-cv-25575, August 17, Robbins Geller Rudman & Dowd, assigned to Judge Becerra); Gordon (9:26-cv-81016, August 18, Morgan & Morgan and Srourian Law Firm, Judge Artau); Sharrard (1:26-cv-25616, August 18); David (1:26-cv-25731, August 21, Maxey Law Firm); Bensfield (1:26-cv-25763, August 24, Federman & Sherwood, Judge Moore); Smedick v. Lennar Mortgage (1:26-cv-25820, August 25); and Todd (1:26-cv-25939, August 28, Aylstock again, Judge Altman). We read the docket sheets and the two orders quoted below in full; we could not read every complaint, because several are not yet in the public archive. CourtListener also lists an Evans v. Lennar Corporation filed August 19 in the Western District of Virginia whose complaint we could not see, so we do not count it.
The reported allegations are the usual data-breach set. Mortgage Professional's account of the August 17 complaint, brought for a South Carolina homebuyer, says it faulted Lennar for not having “adequate employee training on phishing” or a “Zero Trust network architecture,” and for keeping data longer than it needed to. The August 24 complaint, for a buyer in Goodyear, Arizona, pleads negligence, breach of implied contract, unjust enrichment and a count tied to the FTC Act, says notification came almost four months after the first intrusion began, and asks for damages, a security program, outside audits, staff training and credit monitoring the plaintiff prices at more than $200 a year. It attached the notice letter as Exhibit 1.
The procedural story is in two short orders from the chief judge. On August 21 the Ramkissoon plaintiffs moved to consolidate the related cases and to appoint interim co-lead counsel. On August 24 Judge Altonaga denied it: “The Court cannot consolidate an existing case with other cases that are not presently before it. Nevertheless, should any of the Judges with a related case express a willingness to transfer their assigned case, the Court will accept transfer, and thereafter Plaintiffs may renew their requests for consolidation and appointment of class counsel.” The transfers came within a week — Stewart and David were reassigned on August 25 and closed on August 27, Gordon reassigned August 26 and closed August 31, DiMeglio reassigned August 27 and closed August 31. A renewed joint motion for interim co-lead and liaison counsel followed on September 1. On September 2 the chief judge denied that one too, without prejudice, because Lennar had not yet been heard: “Plaintiffs advise that no Defendant has yet appeared in this action, and so the parties cannot confer,” and, in a footnote, “The Court therefore finds it prudent to consider Plaintiffs' request only after Defendants have had an opportunity to state their position.” Lennar's counsel appeared on September 8, filed corporate disclosure statements and asked for more time to respond. Bensfield, Todd, Sharrard and Smedick were still on their own dockets as of that day; Sharrard and Bensfield each carry a notice of related actions.
What is not happening: no settlement, no claim form, no class
Nothing in these dockets is a settlement. No class has been certified; no defendant has answered; the court has not even decided which lawyers will speak for the class. The sequence from here, if it follows the pattern of other breach cases, is consolidation under one caption, an amended consolidated complaint, a motion to dismiss, discovery and — sometimes — a mediated settlement that then needs preliminary approval, notice, a claims window and final approval before a dollar moves. The two data-breach settlements we wrote up this week show how long that takes: Tift Regional Health System's August 2022 attack reached a claims window in July 2026, almost four years later; Community Dental Care's December 2024 breach reached one in twenty months. A Lennar claim form in 2027 would be fast.
That matters because “Lennar settlement” searches are already producing pages that look like claim portals. There is no court-authorised Lennar settlement website, no claim number and no deadline. Anyone asking for your Social Security number or a fee to “register a claim” is not the court, not Lennar and not any of the nine law firms above. The only legitimate action tied to this breach right now is the Kroll enrollment, and it uses the membership number on the letter you were sent — Kroll does not cold-call for it.
What to do with the letter
Keep it. When a settlement does come, the claim form will ask for proof that you are in the class, and the letter is that proof — the August 24 complaint attached the notice letter as Exhibit 1. Activate the monitoring before the deadline printed on it; the letters say two years, and the enrollment code expires. Freeze your credit at all three bureaus, which the letters themselves explain is free and reversible; they list Equifax, Experian and TransUnion with addresses and phone numbers, and note that a freeze can slow down a new mortgage or loan application until you lift it. If you are in the middle of a Lennar mortgage, that is a real trade-off to think about, not a reason to skip the freeze.
Then keep a file. Every breach settlement we cover pays “documented losses” only against receipts — Tift's caps at $5,000, and its notice says self-made notes “alone are not enough” — and several pay for hours spent. Bank statements showing a fraudulent charge, a police report, a credit-freeze confirmation, a receipt for a replacement ID: the file you build now is the claim you file later. If fraud has already happened, report it to the FTC — the letters give the FTC's identity theft clearinghouse at consumer.gov/idtheft and 1-877-IDTHEFT; IdentityTheft.gov is the current portal — and to your local police, and tell the Kroll hotline — restoration is part of what was bought for you. Our Kroll page explains what its enrollment and monitoring emails look like, and the data breach settlement calculator shows how documented losses and lost time are usually paid once a case gets that far. We will update this page when the consolidated case has a name, a lead counsel and a schedule.
The Data Behind This Story
- Companies
- Lennar Corporation (homebuilder, 5505 Waterford District Drive, Miami) and Lennar Mortgage, LLC
- Intrusion 1
- March 24–30, 2026; discovered March 30; review of affected data concluded July 30, 2026 — Lennar Corporation
- Intrusion 2
- May 26–June 1, 2026; discovered June 1; review concluded August 4, 2026 — Lennar Mortgage
- Method
- “Sophisticated social engineering tactics,” per both letters; described by Lennar as two separate and, it believes, unrelated events
- Regulator filings
- California AG: reported August 11 (Corporation) and August 14 (Mortgage), 2026; Texas AG registry: both published August 14, 2026
- Texas count
- 769 (Lennar Corporation) + 60,526 (Lennar Mortgage) = 61,295 Texas residents
- National count
- Not published by Lennar; a 348,416 figure circulating on law-firm pages could not be verified on any state registry we checked
- Data types (Texas registry)
- Name, address, Social Security number, driver's license number, government-issued ID number, financial information (account, credit or debit card number), medical information, date of birth; health insurance information for the Corporation entry
- Offered
- Two years of Kroll identity monitoring (single-bureau credit monitoring, fraud consultation, identity theft restoration); activation code and deadline in the letter
- Hotlines
- (844) 958-8940 Lennar Corporation; (844) 958-8939 Lennar Mortgage — weekdays 9:00 a.m.–6:30 p.m. Eastern
- Lawsuits
- Nine class actions in the U.S. District Court for the Southern District of Florida, filed August 14–28, 2026; a tenth case in W.D. Virginia (Evans, August 19) not verified
- Lead docket
- Ramkissoon v. Lennar Corporation, No. 1:26-cv-25518-CMA — Chief Judge Cecilia M. Altonaga; Stewart, David, Gordon and DiMeglio transferred to her and closed as separate dockets August 27–31; no consolidation order yet
- Consolidation
- First motion denied August 24 (cases before other judges); renewed motion for interim co-lead counsel denied without prejudice September 2 (no defendant had appeared)
- Lennar's appearance
- September 8, 2026 — counsel appeared in Ramkissoon and Sharrard, corporate disclosures filed, extension of time requested
- Settlement
- None. No class certified, no claim form, no deadline, no court-authorised settlement website
- Prior incident
- July 20, 2023 breach reported to the California AG October 10, 2023 — 7,448 customers, names and Social Security numbers (Multifamily Dive)
- Source: California Attorney General data breach registry — Lennar Corporation (breach date March 24, 2026, reported August 11, 2026) and Lennar Mortgage, LLC (breach date May 26, 2026, reported August 14, 2026), with the two sample notice letters (PDF), read September 9, 2026; the 2023 Lennar Corporation entry (breach July 20, 2023)
- Source: Texas Attorney General, Data Security Breach Reports — entries for Lennar Corporation (769 Texans) and Lennar Mortgage, LLC (60,526 Texans), both published August 14, 2026; searched September 9, 2026
- Source: CourtListener / RECAP docket sheets for the nine S.D. Florida cases (1:26-cv-25518, -25529, -25575, 9:26-cv-81016, 1:26-cv-25616, -25731, -25763, -25820, -25939), read September 9, 2026
- Source: Order of August 24, 2026 (ECF 13) and Order of September 2, 2026 (ECF 19), Ramkissoon v. Lennar Corporation, Chief Judge Altonaga — read in full from the RECAP archive
- Source: Mortgage Professional, August 19, 2026 (Tez Romero): the August 17 complaint (Robbins Geller Rudman & Dowd; Zimmerman Reed) and its allegations; August 27, 2026: the August 24 complaint for an Arizona homebuyer, “at least 61,295” affected
- Source: National Mortgage News, August 18, 2026 (Andrew Martinez): Lennar's statement on two separate, unrelated social-engineering events; two years of monitoring; no evidence of misuse
- Source: Multifamily Dive, October 17, 2023 (Mary Salmonsen): the 2023 Lennar breach, 7,448 customers, Experian monitoring
Journalists: these figures are free to cite with attribution to Settlement Insight. Custom data pulls: press@settlementinsight.com.