HackingVulnerability ExploitCapture Stored DataZero-DaySupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
PennyMac Loan Services, LLC
bd_5c5b03f9e2615787 · schema v1 · pii pii-v1
Full breach record for PennyMac Loan Services, LLC →Sovos Compliance, LLC, a vendor for PennyMac Loan Services, LLC, experienced a security incident on May 30, 2023, when unauthorized actors exploited a previously unknown vulnerability in Progress Software's MOVEit Transfer application. The attackers downloaded a file containing personal information of PennyMac customers. Sovos took the application offline, activated incident response, retained experts, and notified law enforcement. Credit monitoring services are being offered to affected individuals.
California clockDiscovered May 30, 2023 → Notified Jul 28, 202359d ✓ CA 60-day OK13 weeks discovery → filing
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_793c69dd334ac06aMontana State AGfiled 2023-08-21(7d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-572503
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 28, 2023
- Raw hash
- beb692388e919a23e91bf1fcfdf405bf40deff2723cda41e8a5e018505e2ff10
Reporting entity
- Name
- Sovos Compliance, LLCnorm: sovos compliance
Victim entity
- Name
- PennyMac Loan Services, LLCnorm: pennymac loan
Incident
- Discovered
- May 30, 2023
- Materiality determined
- —
- Notification sent
- Jul 28, 2023
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified the California Attorney General
- Initial access
- supply_chain
Compliance
- Time to disclose
- 13 weeks(90 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 59d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 30, 2023→ Notified: Jul 28, 202359d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.