DisclosureLens
FEDERALItem 8.01 · voluntaryHackingFinancial ServicesFinanceCustomer Data InvolvedPIICriticalContained

LOANDEPOT, INC.

bd_094a336ad6b79913 · schema v1 · pii pii-v1

Severity

Critical

Financial impact

$14.50M

Discovered

Filed

Feb 27, 2024

To disclose

Affected

16,900,000

Linked

3 filings

Confidence

67%
Full breach record for LOANDEPOT, INC.6 incidents on file

loanDepot, Inc. filed an amended 8-K (Amendment No. 2) regarding a cybersecurity incident it has contained. The company identified unauthorized access to sensitive personal information, impacting up to 16.9 million individuals. The company is notifying affected individuals and offering free credit monitoring. The incident is expected to result in $12-17 million in Q1 2024 expenses, net of insurance. Law enforcement and regulatory engagement continues.

Incident timeline — partial

? — ?

Breach window unknown

Feb 27, 2024

Filed

Corroborated · see linked filings

Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.

This filing is one of 3 about the same incident.View merged incident

Linked disclosures

Why this link?

Ransomware claims (1)

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings

View merged incident ↗
SEC 8-KJan 8 · first
SEC 8-K+50d · this page

Pattern: first filing Jan 8, last Feb 27 — a 50-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filing

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statementThis record

Unlocks: materiality, stated response, full audit trail. Ceiling removed.