MalwareRansomwareData EncryptedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
PACIFIC RESIDENTIAL MORTGAGE, LLC
bd_0fd90a90441dd7ed · schema v1 · pii pii-v1
Full breach record for PACIFIC RESIDENTIAL MORTGAGE, LLC →Pacific Residential Mortgage, LLC reported a ransomware incident to the Maryland Attorney General on March 25, 2025. The company detected the ransomware lockdown on February 10, 2025. The breach impacted 7 Maryland residents, exposing names, addresses, SSNs, driver's license numbers, and financial account information. Pac Res engaged a cybersecurity firm, recovered systems from backups, notified law enforcement, and provided 12 months of credit monitoring via TransUnion/Cyberscout.
Leak gap clock✗ Leak >180d15 months discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed7 affectedView incident
A leak claim by lynx about this victim predates this filing by 438 days.View originating leak claim
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376756.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 23, 2026
- Raw hash
- 052979c15e2b9309ea459978b5f8481b304b0d281db454c114934d4026a674f3
Reporting entity
- Name
- TAFT STETTINIUS & HOLLISTER LLPnorm: taft stettinius hollister
Victim entity
- Name
- PACIFIC RESIDENTIAL MORTGAGE, LLCnorm: pacific residential mortgage
- Domain
- pacresmortgage.com
- Industry
- financial_services
Incident
- Discovered
- Feb 10, 2025
- Materiality determined
- —
- Notification sent
- Mar 25, 2025
- Affected individuals
- 7
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- providing written notice of this incident to relevant state regulators
Compliance
- Time to disclose
- 15 months(437 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.