HackingCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
LOANDEPOT.COM, LLC
bd_5b190ad591b51f15 · schema v1 · pii pii-v1
Full breach record for LOANDEPOT.COM, LLC →loanDepot.com, LLC notified the California Attorney General of a data breach where an unauthorized third party accessed systems between January 3 and January 5, 2024. The incident was identified on January 4, 2024. Affected data includes names, addresses, emails, phone numbers, dates of birth, social security numbers, and financial account numbers. The company contained the incident, engaged forensic experts, and offered 24 months of identity protection services via Experian.
California clockDiscovered Jan 4, 2024 → Notified Feb 23, 202450d ✓ CA 60-day OK7 weeks discovery → filing
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_0b32cb6f0fca79b2Delaware State AGfiled 2024-02-23Verified
- bd_39ba2cb6b3e56f4eOregon State AGfiled 2024-02-23Verified
- bd_7cde8b7bcc15bb46Maine State AGfiled 2024-02-23Verified
- bd_95ba1e9481b2f508Montana State AGfiled 2024-02-23Verified
Show 3 more filings ↓Show fewer ↑up to 8d gap
- bd_a6ec3f5c17e3b485Hawaii State AGfiled 2024-02-23Verified
- bd_bc15e3eca6436d47Indiana State AGfiled 2024-02-23Verified
- bd_6e8924c1e600fc5bWashington State AGfiled 2024-02-15(8d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-581431
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 23, 2024
- Raw hash
- 6f15d93a020e8fea910c905dacd0d9b841cfd3531a2b19d3e184b50491f5ee89
Reporting entity
- Name
- LOANDEPOT.COM, LLCnorm: loandepotcom
Victim entity
- Name
- LOANDEPOT.COM, LLCnorm: loandepotcom
Incident
- Discovered
- Jan 4, 2024
- Materiality determined
- —
- Notification sent
- Feb 23, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unknown
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
Compliance
- Time to disclose
- 7 weeks(50 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 50d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jan 4, 2024→ Notified: Feb 23, 202450d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.