MFA FINANCIAL, INC.
bd_700c956799a87ece · schema v1 · pii pii-v1
Full breach record for MFA FINANCIAL, INC. →2 incidents on fileMFA Financial, Inc. disclosed a cybersecurity incident in its legacy environment where unauthorized access occurred between Feb 12 and Mar 10, 2021. The attacker accessed and removed personal information (name, address, DOB, SSN) of loan/mortgage owners. MFA engaged forensic investigators, notified law enforcement, and offered 2 years of credit monitoring. Notices were sent on Sep 1, 2021.
J jump to incidentP pin to compareR raw source
Incident timeline
Feb 12, 2021
Begins
Mar 10, 2021
Discovered
Sep 1, 2021
Filed
vs. sector median
+16 wks slower
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- Maine State AGbd_37dc58d5b56ea2c52021-09-01Candidate
- California State AGbd_3d0f6290fb557c9c2021-09-01Verified
- Indiana State AGbd_b8c682cfed093f5d2021-09-01Verified
Filing propagation · 4 filings · 4 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.