HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSMediumActive
Stanwich Mortgage Loan Trust A, C, and D
bd_0bbd6e6baa17c075 · schema v1 · pii pii-v1
Full breach record for Stanwich Mortgage Loan Trust A, C, and D →Stanwich Mortgage Loan Trust A, C, and D reported a data breach involving unauthorized access to cloud servers operated by third-party vendor OpticsML (via Ascension Data & Analytics). The incident, occurring between February 2018 and January 2019, potentially exposed personal information including SSNs, driver's license numbers, and financial account details of California residents. Stanwich engaged forensic experts, took systems offline, and provided two years of free credit monitoring through Kroll.
California clockDiscovered Jan 15, 2019 → Notified Feb 12, 201928d ✓ CA 60-day OK28 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-144635
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 12, 2019
- Raw hash
- 40b0ae8d15601d35deb390cee4dcefc260d94b2219a251ba58413add875e193a
Reporting entity
- Name
- Stanwich Mortgage Loan Trust A, C, and Dnorm: stanwich mortgage loan trust a c and d
Victim entity
- Name
- Stanwich Mortgage Loan Trust A, C, and Dnorm: stanwich mortgage loan trust a c and d
Incident
- Discovered
- Jan 15, 2019
- Materiality determined
- Feb 1, 2019
- Notification sent
- Feb 12, 2019
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Submitted breach notification to California Office of the Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 28 days(28 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 28d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jan 15, 2019→ Notified: Feb 12, 201928d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.