MalwareRansomwareData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Sage Home Loans Corp. f/k/a Lenox Financial Mortgage Corp.
bd_10436a912d2bb188 · schema v1 · pii pii-v1
Full breach record for Sage Home Loans Corp. f/k/a Lenox Financial Mortgage Corp. →Sage Home Loans Corporation (f/k/a Lenox Financial Mortgage Corporation) experienced a ransomware attack. An unauthorized actor gained access to the network on December 5, 2023, and exfiltrated data on December 19, 2023. The incident was discovered on December 19, 2023. Affected data may include personal information such as names and financial account details. The company secured its network, reset passwords, and offered identity protection services.
California clockDiscovered Dec 19, 2023 → Notified Feb 2, 202445d ✓ CA 60-day OK6 weeks discovery → filing
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_0b1039e5f599d58fWashington State AGfiled 2024-02-02Candidate
- bd_15279357b6b8bb89Oregon State AGfiled 2024-02-02Verified
- bd_dad6161c956a08abIndiana State AGfiled 2024-02-02Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-580472
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 2, 2024
- Raw hash
- 8e8374f51e9647dceffdaca35e80b63cdb960bbfd8c7347d4240d3f28e74ddc8
Reporting entity
- Name
- Sage Home Loans Corp. f/k/a Lenox Financial Mortgage Corp.norm: sage home loans corp f k a lenox financial mortgage
Victim entity
- Name
- Sage Home Loans Corp. f/k/a Lenox Financial Mortgage Corp.norm: sage home loans corp f k a lenox financial mortgage
Incident
- Discovered
- Dec 19, 2023
- Materiality determined
- —
- Notification sent
- Feb 2, 2024
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
Compliance
- Time to disclose
- 6 weeks(45 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 45d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Dec 19, 2023→ Notified: Feb 2, 202445d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.