ON Q FINANCIAL, LLC
bd_2460fbf06e71ff54 · schema v1 · pii pii-v1
Full breach record for ON Q FINANCIAL, LLC →2 incidents on fileThreat-actor claim — not a regulatory filing
This row is a claim by the ransomware group BianLian on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
On Q Financial is a Mortgage Company specializing in new home financing and existing home refinancing.
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Feb 20, 2024
Claim posted
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Claim → filing
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Sitebianlianbd_ee592bde892a7b022024-04-06 · +46dVerified by operator
Regulatory filings (9) · sorted by filing gap
- Illinois State AGbd_bca121f6a23d98442024-04-01 · +41dVerified by operator
- Washington State AGbd_32dae1ae6ad3e6f42024-04-02 · +42dCandidate
- California State AGbd_47866e35155e8f932024-04-02 · +42dVerified by operator
- Maine State AGbd_70331c336a1897252024-04-02 · +42dVerified by operator
Show 5 more filings ↓Show fewer ↑up to 51d gap
- Montana State AGbd_bfba92634c81bbdc2024-04-02 · +42dVerified by operator
- South Carolina State AGbd_5fb90898a6e95a8e2024-04-03 · +43dVerified
- New Hampshire State AGbd_a5faead4f3404bf82024-04-03 · +43dVerified by operator
- Massachusetts State AGbd_d4ea7af3e6261a2d2024-04-03 · +43dVerified
- Oregon State AGbd_b11839235c04d95c2024-04-11 · +51dVerified
Showing first 10 of 13 linked disclosures.
Filing propagation · 10 filings · 9 states
View merged incident ↗Pattern: first filing Feb 20, last Apr 11 (OR) — a 51-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Cascade drawn from the first 10 linked disclosures of 13 — the full spread may be wider.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- actor name
- victim claim
- ransom/leak status
- discovery date
- materiality
- notification
- affected count
- confirmed data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
bianlian
According to ransomware.live, BianLian ransomware operations began in late 2021. The group practices multi-pronged extortion, demanding payment for a decryptor, as well as the non-release of stolen data. The ransomware group hosts a public, TOR-based, blog to post victim identities and stolen data. Somewhat unique to BianLian at the time of their launch was their inclusion of an I2P mirror for their blog.