HackingEmployee Data InvolvedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumResolved
ACADEMY MORTGAGE CORPORATION
bd_7a0d1938864b9a74 · schema v1 · pii pii-v1
Full breach record for ACADEMY MORTGAGE CORPORATION →Academy Mortgage Corporation detected a network security incident on March 21, 2023, where an unauthorized third party accessed and disabled systems. The investigation concluded in November 2023, determining that personal information (names, SSNs, dates of birth) of employees and mortgage applicants may have been accessed. No evidence of misuse was found. The company engaged forensic specialists, notified law enforcement, rebuilt systems, and offered credit monitoring.
California clockDiscovered Mar 21, 2023 → Notified Dec 20, 2023274d ✗ CA 60-day late43 weeks discovery → filing
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_6ec09ae80601c340Leak Sitealphvfiled 2023-05-14(246d gap)Verified by operator
Regulatory filings (5) · sorted by filing gap
- bd_a04b7d44352861c2Maine State AGfiled 2024-01-15Verified by operator
- bd_d76d3319b21c6f7bOregon State AGfiled 2024-01-05(10d gap)Verified by operator
- bd_e728b3b38da97809California State AGfiled 2024-01-05(10d gap)Verified by operator
- bd_3b5884dbff92d2bbMontana State AGfiled 2023-12-27(19d gap)Verified by operator
Show 1 more filing ↓Show fewer ↑up to 19d gap
- bd_e304b68c35220b07Washington State AGfiled 2023-12-27(19d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-579377
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 15, 2024
- Raw hash
- abcf44756eb586eff5c3ea8377f9493590807c9518124e588bb1ca96c32c593b
Reporting entity
- Name
- ACADEMY MORTGAGE CORPORATIONnorm: academy mortgage
Victim entity
- Name
- ACADEMY MORTGAGE CORPORATIONnorm: academy mortgage
Incident
- Discovered
- Mar 21, 2023
- Materiality determined
- —
- Notification sent
- Dec 20, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- Threat actor
- External
Compliance
- Time to disclose
- 43 weeks(300 days from discovery to filing)
- Compliance flags
- CA 60-day late · 274dLeak >180d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 21, 2023→ Notified: Dec 20, 2023274d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.