HackingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Broadview Mortgage Corporation
bd_3a7f9734f40dba23 · schema v1 · pii pii-v1
Full breach record for Broadview Mortgage Corporation →Broadview Mortgage Corporation notified customers of a data breach discovered on July 28, 2016, when a third-party IT provider identified unauthorized administrative accounts on a branch server. The incident potentially exposed mortgage application data including names, addresses, driver's license numbers, dates of birth, Social Security numbers, and financial account numbers. The company disabled the accounts, enhanced security procedures, and offered one year of credit monitoring.
California clockDiscovered Jul 28, 2016 → Notified Oct 17, 201681d ✗ CA 60-day late12 weeks discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-64437
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 17, 2016
- Raw hash
- 0dc900551f490f74f797d4ab9933027826ee974be13fa14955700cde0565e1be
Reporting entity
- Name
- Broadview Mortgage Corporationnorm: broadview mortgage
Victim entity
- Name
- Broadview Mortgage Corporationnorm: broadview mortgage
Incident
- Discovered
- Jul 28, 2016
- Materiality determined
- —
- Notification sent
- Oct 17, 2016
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Third party
- via third-party information technology provider
- Initial access
- trusted_relationship
Compliance
- Time to disclose
- 12 weeks(81 days from discovery to filing)
- Compliance flags
- CA 60-day late · 81d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jul 28, 2016→ Notified: Oct 17, 201681d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.