HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
LOANDEPOT.COM, LLC
bd_0b32cb6f0fca79b2 · schema v1 · pii pii-v1
Full breach record for LOANDEPOT.COM, LLC →loanDepot.com, LLC disclosed a data breach occurring between January 3-5, 2024, where an unauthorized third party accessed systems containing names, addresses, SSNs, financial account numbers, and dates of birth. The company contained the incident, contacted law enforcement, and engaged forensic experts. Affected individuals are offered 24 months of credit monitoring and identity protection services via Experian.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_39ba2cb6b3e56f4eOregon State AGfiled 2024-02-23Verified
- bd_5b190ad591b51f15California State AGfiled 2024-02-23Verified
- bd_7cde8b7bcc15bb46Maine State AGfiled 2024-02-23Verified
- bd_95ba1e9481b2f508Montana State AGfiled 2024-02-23Verified
Show 3 more filings ↓Show fewer ↑up to 8d gap
- bd_a6ec3f5c17e3b485Hawaii State AGfiled 2024-02-23Verified
- bd_bc15e3eca6436d47Indiana State AGfiled 2024-02-23Verified
- bd_6e8924c1e600fc5bWashington State AGfiled 2024-02-15(8d gap)Candidate
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2024/03/EXPERIAN_K7315_LOANDEPOT.COM-LLC_L01_SAS_2.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 23, 2024
- Raw hash
- 4544e0608fa2883b4ea3190cd445620ecd60c1d2de894a1992ee7207591739f3
Reporting entity
- Name
- LOANDEPOT.COM, LLCnorm: loandepotcom
Victim entity
- Name
- LOANDEPOT.COM, LLCnorm: loandepotcom
Incident
- Discovered
- Jan 4, 2024
- Materiality determined
- —
- Notification sent
- Feb 23, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- contact law enforcement
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 7 weeks(50 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.