HackingStolen CredentialsData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
CITYWIDE HOME LOANS, LLC
bd_5b65411c4f7f434c · schema v1 · pii pii-v1
Full breach record for CITYWIDE HOME LOANS, LLC →Citywide Home Loans, LLC reported a cybersecurity incident where an unauthorized person gained remote access to its computer network between November 18 and December 2, 2020. The breach exposed personal information including names, addresses, phone numbers, dates of birth, and potentially Social Security numbers. Citywide engaged law enforcement and third-party experts, eliminated access, and provided two years of free identity monitoring through Kroll to affected individuals.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_d0e27bedc188f9fbMontana State AGfiled 2021-02-12(4d gap)Verified
- bd_2702f95acf3ad78eMaine State AGfiled 2021-02-11(5d gap)Candidate
- bd_6a666b75ee10fc92Washington State AGfiled 2021-03-19(31d gap)Verified
- bd_cabec36232263204Oregon State AGfiled 2021-03-19(31d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 37d gap
- bd_e8ea5bf83df4ef80Maine State AGfiled 2021-03-19(31d gap)Verified
- bd_bd7db8214abdd3baMaine State AGfiled 2021-03-25(37d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-538034
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 16, 2021
- Raw hash
- 21a4ae016a4d09d30e22bdec5159fc72e6110a5c2a7374d3b2566cc1c6b1b96d
Reporting entity
- Name
- CITYWIDE HOME LOANS, LLCnorm: citywide home loans
- Domain
- citywidehomeloans.com
Victim entity
- Name
- CITYWIDE HOME LOANS, LLCnorm: citywide home loans
- Domain
- citywidehomeloans.com
Incident
- Discovered
- Nov 29, 2020
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 11 weeks(79 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.