Skip to main content
Jump to a category page

Lennar Corporation Took More Than Four Months to Tell People a Breach Exposed Their Social Security and Passport Numbers

Lennar Corporation, one of the largest homebuilders in the country, has notified California residents that someone outside the company accessed its information systems using social engineering. Social engineering means tricking a person, often an employee, into giving up access, rather than breaking through a technical security system directly.

According to Lennar’s notice, the unauthorized access happened between March 24 and March 30, 2026. Lennar says it became aware of the issue on March 30, 2026, the same day the access ended. But Lennar did not finish determining whose information was affected and what was exposed until July 30, 2026, exactly four months later. Notices to affected individuals began going out on August 11, 2026, more than four months after Lennar first learned of the problem.

Lennar has not said publicly whether the people affected are homebuyers, employees, job applicants, or another group.

More Than Four Months to Confirm What Was Taken

Lennar knew something was wrong on March 30, 2026. It did not finish its assessment of what data was exposed until July 30, 2026, and did not begin notifying people until August 11, 2026. That is more than four months during which affected individuals had no way to know their Social Security number and passport information were at risk.

A Dangerous Combination: Social Security and Passport Numbers

Lennar’s notice confirms that exposed information may include a person’s name, contact information, Social Security number, passport number, and date of birth. A Social Security number and date of birth are enough on their own to attempt identity theft. Adding a passport number raises the stakes further. It can be used to attempt fraud tied to international travel or identity verification, and unlike a compromised credit card, a passport number cannot simply be canceled and reissued on short notice.

What Information Was Exposed

  • Name
  • Contact information
  • Social Security number
  • Passport number
  • Date of birth

Lennar’s notice describes this as information that “may include” the categories above, so not every affected person’s exposure is necessarily identical.

What Lennar Is Offering

Lennar has secured two years of identity monitoring services through Kroll at no cost to affected individuals. The service includes single-bureau credit monitoring with alerts, unlimited consultation with a Kroll fraud specialist, and identity theft restoration support from a dedicated investigator if needed. Individuals can enroll at enroll.krollmonitoring.com using the membership number included in their notice letter. Lennar’s information line is (844) 958-8940.

Your Information Is at Risk

A Social Security number, date of birth, and passport number together give someone most of what they need to open new accounts, apply for loans, or attempt to impersonate a person in situations that require government identification. This combination is harder to fully protect against than a stolen credit card number, because a Social Security number and passport number typically cannot simply be canceled and reissued the way a card can.

Do You Have Legal Options?

Companies that collect this level of sensitive information have a legal duty to secure it and to notify affected individuals promptly once a breach is discovered. If Lennar’s four-month delay caused you harm, or if your Social Security number, passport number, or other sensitive information was exposed, you may have legal options.

Contact Emery | Reddy, PC today for a Free Case Review. There is no fee unless we recover for you.

Frequently Asked Questions

What happened in the Lennar Corporation data breach?

Lennar says an unauthorized party used social engineering tactics, meaning they tricked someone rather than hacking in directly, to access its systems between March 24 and March 30, 2026.

What information was exposed?

Lennar’s notice says exposed information may include a person’s name, contact information, Social Security number, passport number, and date of birth.

How many people were affected?

Lennar has not publicly disclosed a total number of people affected, including how many are in California.

Why did it take Lennar so long to notify people?

Lennar learned of the issue on March 30, 2026, but did not finish determining what data was exposed until July 30, 2026, and did not begin notifying individuals until August 11, 2026. That is more than four months.

Do I have a legal claim?

If you received a notice from Lennar Corporation that your Social Security number, passport number, or other sensitive information was exposed, you may have a legal claim. Contact Emery | Reddy, PC today for a Free Case Review. There is no fee unless we recover for you.

"Very friendly interview and intake process. I was informed thoroughly about the processes in obtaining a lawyer and was given ample time to make a decision on representation. I’m thankful for everyone’s help and looking forward to working with this Firm on my worker’s compensation claim."

- Darren A.

Receive a
FREE Case Review

Call Now