MalwareRansomwareVulnerability ExploitLockBitLockBit 3.xData ExfiltratedRansom DemandedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
PLANET HOME LENDING, LLC
bd_83e14e9833c126bd · schema v1 · pii pii-v1
Full breach record for PLANET HOME LENDING, LLC →Planet Home Lending, LLC experienced a ransomware attack by the threat actor LockBit on November 15, 2023. The attacker exploited a vulnerability known as 'Citrix Bleed' in Citrix software to gain unauthorized access to a read-only data folder containing customer loan files. Affected data included names, addresses, Social Security numbers, loan numbers, and financial account numbers. The company contained the threat, notified the FBI, and is offering 24 months of credit monitoring to affected individuals.
California clockDiscovered Nov 15, 2023 → Notified Jan 24, 202470d ✗ CA 60-day late12 weeks discovery → filing
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (2)
- bd_6ec063e7e1ee7543Leak Sitelockbit_3filed 2023-11-17(84d gap)Candidate
- bd_6c12ff4afe178526Leak Sitelockbit_3filed 2023-11-15(86d gap)Verified
Regulatory filings (3) · sorted by filing gap
- bd_4a3e4f7501222204Maine State AGfiled 2024-02-09Verified by operator
- bd_8d3bd14ff0d366f5Oregon State AGfiled 2024-02-09Verified
- bd_36716702cdea2f82Montana State AGfiled 2024-01-24(16d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-580833
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 9, 2024
- Raw hash
- 2b852a3838a4da48f15fba2a9d44b5e8681a366448c35483769ca8e8e410d150
Reporting entity
- Name
- PLANET HOME LENDING, LLCnorm: planet home lending
- Domain
- planethomelending.com
Victim entity
- Name
- PLANET HOME LENDING, LLCnorm: planet home lending
- Domain
- planethomelending.com
Incident
- Discovered
- Nov 15, 2023
- Materiality determined
- —
- Notification sent
- Jan 24, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Ransomware· LockBit
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- LockBitExternalFinancial
- Regulator citations
- Notified the FBI
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 12 weeks(86 days from discovery to filing)
- Compliance flags
- CA 60-day late · 70dLeak >180d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Nov 15, 2023→ Notified: Jan 24, 202470d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.