NATIONSTAR MORTGAGE LLC
bd_57eb457f3eb2112d · schema v1 · pii pii-v1
Full breach record for NATIONSTAR MORTGAGE LLC →Nationstar Mortgage LLC (dba Mr. Cooper) detected suspicious activity on October 31, 2023, leading to the discovery of unauthorized access to certain systems between October 30 and November 1, 2023. An unauthorized party obtained files containing personal information including names, addresses, phone numbers, Social Security numbers, dates of birth, and bank account numbers. The company shut down systems to contain the incident, engaged cybersecurity experts, and contacted law enforcement. Approximately 47,818 Rhode Island residents were affected. The company is offering 24 months of credit monitoring and fraud assistance.
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_1649a1b2c61961c4Delaware State AGfiled 2023-12-15Candidate
- bd_533f8c10b6714aefDelaware State AGfiled 2023-12-15Verified
- bd_5d5578f4cbaaad52Montana State AGfiled 2023-12-15Verified
- bd_94029d67f539973dMaine State AGfiled 2023-12-15Verified
Show 4 more filings ↓Show fewer ↑up to 98d gap
- bd_bcd8a251801840a2Oregon State AGfiled 2023-12-15Verified
- bd_ec18ec8370ea5376Washington State AGfiled 2023-12-15Verified
- bd_66a3873bc3c9facfNew Hampshire State AGfiled 2023-12-19(4d gap)Verified
- bd_0b70ea800f866612California State AGfiled 2024-03-22(98d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-578028
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 15, 2023
- Raw hash
- 2a7c66220d3c11aa387fbb8c7af19ed5a04a7b0dc92cd404d528cc2b29319488
Reporting entity
- Name
- NATIONSTAR MORTGAGE LLCnorm: nationstar mortgage
Victim entity
- Name
- NATIONSTAR MORTGAGE LLCnorm: nationstar mortgage
Incident
- Discovered
- Oct 31, 2023
- Materiality determined
- —
- Notification sent
- Dec 1, 2023
- Affected individuals
- 47,818
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
Compliance
- Time to disclose
- 6 weeks(45 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 31d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Oct 31, 2023→ Notified: Dec 1, 202331d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.