A customer has sued Gold Star Mortgage Financial Group over a ransomware attack, saying in a filing dated Sept. 26 that the lender failed to protect her personal data, which was stolen and later posted on the dark web.

The attack came last week. Cybersecurity Insiders reported that a ransomware gang called BrainCipher hit the Ann Arbor, Mich., mortgage company on Sept. 23, stealing data from its systems and then encrypting its database. Other outlets dated the events slightly differently: Mortgage Professional America reported that the breach occurred on or around Sept. 24, with the suit arriving the next day.

The plaintiff says the exposed information included her full name, Social Security number, home addresses and contact details, according to the lawsuit filing — the kind of data that can feed identity theft, phishing schemes and financial fraud.

After the breach, she says, the spam began. She reported a surge of unsolicited emails, text messages and phone calls, some of them, the filing alleges, tied to cybercriminals pressing victims to pay a ransom.

The theft may have been large. The customer says the BrainCipher group took more than 10,000 files from Gold Star’s systems, and National Mortgage News reported that the gang’s own claim put the haul at more than 10,300 documents. If those files hold borrowers’ personal and financial information, the damage could outlast the disruption of the attack itself.

The suit seeks damages and other relief. A victory for the plaintiff could mean compensatory and punitive damages, along with measures such as closer monitoring of her bank accounts for suspicious transactions.

Mortgage lenders sit on exactly the kind of data criminals want, which has made them recurring ransomware targets. As the investigation and the lawsuit proceed, the case will test what a financial company owes its customers when that data ends up on the dark web.