DisclosureLens
Social EngineeringFinancial ServicesFinancePhishingStolen CredentialsCustomer Data InvolvedTargetedGovernment IDIdentity (basic)Financial accountMediumActive

WEI Mortgage

bd_037cff157a88481d · schema v1 · pii pii-v1

Severity

Medium

Discovered

Sep 20, 2017

Filed

Jan 3, 2018

To disclose

15 weeks

Affected

51state residents only

Linked

6 filings

Confidence

64%
Full breach record for WEI Mortgage2 incidents on file

WEI Mortgage LLC filed a supplemental notice with the New Hampshire Attorney General regarding a phishing attack that compromised employee email accounts. Unauthorized access occurred between September 13-28, 2017. The incident affected 51 New Hampshire residents, exposing SSNs, DOBs, bank account info, names, and addresses. WEI Mortgage engaged forensic investigators, notified law enforcement, and offered 24 months of credit monitoring.

Incident timeline

undetected · 7 days
discovery → filing · 15 weeks / 105 days

Sep 13, 2017

Begins

Sep 20, 2017

Discovered

Jan 3, 2018

Filed

vs. sector median

+7 wks slower

This filing is one of 6 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (5) · sorted by filing gap

Show 1 more filingup to 26d gap

Filing propagation · 6 filings · 5 states

View merged incident ↗
California State AGDec 8 · first
Montana State AGDec 8 · first
New Hampshire State AG+26d · this page

Pattern: first filing Dec 8 (NH), last Jan 3 (NH) — a 26-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.