For years, Foreclosurepedia has reported upon the dangerous state of digital security within the Mortgage Field Services Industry. Recent events have reinforced that belief. Over the past several years we have reported on the breach of all Contractors and Realtors at Assurant; the weeks long collapse of the Mortgage Contracting Services (MCS) website; the hack of Mr Cooper; and the most recent hack of Fidelity which included ServiceLink and LoanCare. With zero transparency pertaining to not only Contractor’s data but homeowners themselves, the reality is that it should come as no surprise that virtually all of the websites powering the Mortgage Field Services Industry are candy bowls for hackers to sample. At the top of the list right now are Property Preservation Wizard, a Verisk company; Aspen Grove Solutions operating as ShieldHub; and the National Association of Mortgage Field Services (NAMFS), all of which operate with PHP as their underlying code.
For years, the vast majority of providers have been relying upon PHP version 7.4 which has been outdated for years. Currently, PHP version 8.1 is the norm as you would see if you flashed this website. The key reason to upgrade PHP is to ensure that you run your eCommerce project on a version that is fully supported and regularly updated for security threats. The threats can be any: DoS, code execution, overflow, memory corruption, XSS, directory traversal, information traversal, and retrieval. Every year, numerous vulnerabilities inherent to older PHP versions become exposed. Some of them will never be fixed.
Fact of the matter is that this Industry has, for years, forced the use of wet signatures in order to obtain background checks from Aspen Grove Solutions. The ABC Number, while no longer universally required of anyone except Wells Fargo, is a one stop shop for hackers to create fraudulent identities, engage in financial criminal activity, and destroy lives. As opposed to proactively engaging in proper security protocols, our Industry takes a let it happen and damage control after the fact stance. And the credit protection offered months later is too little, too late. JGM Property Group is a classic case in point. JGM, a HUD M&M FSM Awardee was infected with directed viruses which were, in turn, used to target many including the International Association of Field Service Technicians (IAFST).
No longer is the risk simply that these financial terrorists will not pay, now Labor’s personally identifiable information (PII) is up for grabs to the highest bidder.
This holiday season, let us join together in demanding not only that our information is protected, but that the Industry goes further by creating an Artificial Intelligence Bill of Rights. Let us rally around the innocent men and women whom are paid $5 for an inspection while $45 is paid to Management. Let us demand better for those cutting the grass on these foreclosures for $35 while Management is paid $525. And let us all come together this coming year to demand transparency from Servicer down to Labor documenting precisely where the money is going and what is being done about the breaches.




