Freddie Cyber Incident Notification


On Dec. 11, Freddie updated the cyber incident reporting process.


  • Freddie issued Bulletin 2024-17 on updates to My Home by Freddie, servicing transfer checklists, information security, Freddie gateway, and Bank of NY Mellon contact data.
  • Provided a new process for reporting security breaches effective Jan. 1, 2025.
  • My Home
  • Freddie currently provides links to My Home in the additional resources section within letter templates for workout options that Servicers may use when sending out notices.
  • Reported changes to these templates to make it easier for borrowers to access data.
  • Provided updated links on getting help when struggling to make mortgage payments.
  • Added QR code for each letter template that can be used to directly access resources.
  • My Home updates impacted guide Exhibits 93, Form 710 and sections 1100, 1145.
  • Servicing Transfer Checklists
  • Removed outdated Transfer of Servicing best practice documents references, s. 7101.3
  • Included references to recently updated Transfer of Servicing checklists in s. 7101.1.
  • Transferors and Transferees should review and consider adopting the Servicing Transfer Management Checklists that include links to the MISMO Servicing Transfer Catalog.
  • Which includes best practices, servicing transfer instruction checklist, portfolio characteristics, image transfer schedules, required reporting, and reconciliation.
  • Incident Notification
  • Process for reporting Security Incidents (as defined in Section 1302.2) and Privacy Incidents (as defined in Section 1302.2) is being consolidated, effective Jan. 1, 2025.
  • All incidents must be reported via the electronic notification tool; provided FAQs.
  • Timeline for reporting incidents is reduced to no later than 36 hours after discovery.
  • Incidents must be reported immediately if they cause seller/servicer to shut down or disable connection with mortgage originations or servicing on behalf of Freddie.
  • With respect to quarterly reporting of Non-critical Privacy Events (as defined in Section 1302.2), Exhibit 130, Non-critical Privacy Incident Reporting Template, will be retired.
  • Non-critical Privacy Incidents (S. 1302.5) must be reported using the notification tool.
  • Security Updates
  • Effective Mar. 11, 2025, updated topics on data transmission and data loss prevention, vulnerability management, data encryption, incident management, and access.
  • Also updated authentication requirements and guidelines and cloud computing.
  • Added requirements related to business continuity plans (BCPs), including BCP review, policies, and procedures to support the BCPs, and BCP education and training.
  • Finally, added new sections 1302.4 and 1302.6 - 1302.8 on disaster recovery plans, document retention and destruction, third parties, use of AI and machine learning.
  • Freddie Gateway
  • In Bulletin 2024-16 introduced Freddie Gateway as the new single sign-on portal for users who access tools through the Advisor Portal or Servicing Gateway, #235816.
  • Effective Jan. 25, 2025, Loan Advisor Portal and Servicing Gateway will be retired.
  • Existing Seller/Servicer Loan Advisor Portal and Servicing Gateway credentials will still be active to sign into Freddie Gateway; does not impact system-to-system integrations
  • Seller/Servicers will be able to access Gateway, once it launches, via Freddie website.
  • Impacts s.1101.2, 1401.3, 2402.2, 2404.2, 2406.4, 2407.1, 3101.1, 7101.2, 8102.1, 8203.12, 8301.10, 8302.17, 8303.30, 9206.10, 9207.2, 9301.47 and Exhibit 88.
  • Bank of NY Mellon Contact
  • Updated guide to reflect changes to contact information for document custody.
  • Including separate e-mail addresses for document release requests in Directory 4.
  • These updates impacted the Guide Directory 4, Exhibit 43 and Form 1035DC.
  • Effectiveness
  • Bank of NY Mellon contact information changes effective as of Sep. 23, 2024.
  • Introduction of Freddie Mac Gateway becomes effective on Jan. 25, 2025.
  • Security updates effective Mar. 11, 2025; incident notification effective Jan. 1, 2025.

Regulators Freddie
Entity Types Bank; CU; MG Orig; Servicer; Thrift
Reference Bul 2024-17, 12/11/2024
Functions BCS; Compliance; Cyber; Financial; Legal; Operations; Outsourcing; Record Retention; Reporting; Technology; Training
Countries United States of America
Category
State
Products AI; Banking; Loan; Mortgage
Regions Am
Rule Type Final
Rule Date 12/11/2024
Effective Date 1/1/2025
Rule Id 236899
Linked to Rule :235816
Reg. Last Update 12/11/2024
Report Section US Banking

Last substantive update on 12/16/2024