HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSHEALTH_BASICMediumContained
MFA FINANCIAL, INC.
bd_3d0f6290fb557c9c · schema v1 · pii pii-v1
Full breach record for MFA FINANCIAL, INC. →MFA Financial, Inc. reported a cybersecurity incident occurring between February 12, 2021, and March 10, 2021, involving unauthorized access to a legacy file server. The breach affected personal information of employees, contractors, and loan owners, including names, SSNs, and financial/health data. MFA engaged forensic investigators, notified law enforcement, and offered two years of credit monitoring.
California clockDiscovered Mar 10, 2021 → Notified Sep 1, 2021175d ✗ CA 60-day late25 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_37dc58d5b56ea2c5Maine State AGfiled 2021-09-01Candidate
- bd_700c956799a87eceMontana State AGfiled 2021-09-01Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-544766
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 1, 2021
- Raw hash
- bb76ca01b6b6e59fa260bfc3d5dc4eb9f67ce05b6438a95cbf7bde546e8eaaaf
Reporting entity
- Name
- MFA FINANCIAL, INC.norm: mfa financial
Victim entity
- Name
- MFA FINANCIAL, INC.norm: mfa financial
Incident
- Discovered
- Mar 10, 2021
- Materiality determined
- —
- Notification sent
- Sep 1, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified federal law enforcement authorities
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 25 weeks(175 days from discovery to filing)
- Compliance flags
- CA 60-day late · 175d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 10, 2021→ Notified: Sep 1, 2021175d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.