MalwareRansomwareData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedPIIIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSEMPLOYMENTMINORMediumContained
Sage Home Loans Corp. f/k/a Lenox Financial Mortgage Corp.
bd_973d23e1c8f06adf · schema v1 · pii pii-v1
Full breach record for Sage Home Loans Corp. f/k/a Lenox Financial Mortgage Corp. →Sage Home Loans Corporation (f/k/a Lenox Financial Mortgage Corporation) experienced a ransomware attack. An unauthorized actor gained access to the network on December 5, 2023, and exfiltrated data on December 19, 2023. The incident was discovered on December 19, 2023. Affected data may include names, addresses, SSNs, dates of birth, financial account information, and employment data. The company engaged cybersecurity experts, secured its network, and is offering identity theft protection services.
California clockDiscovered Dec 19, 2023 → Notified Feb 2, 202445d ✓ CA 60-day OK40 weeks discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-592239
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 22, 2024
- Raw hash
- 1411c2a4479b0e970dc296f5f2259b400d63494721a38e40deee8105c485ca0d
Reporting entity
- Name
- Sage Home Loans Corp. f/k/a Lenox Financial Mortgage Corp.norm: sage home loans corp f k a lenox financial mortgage
Victim entity
- Name
- Sage Home Loans Corp. f/k/a Lenox Financial Mortgage Corp.norm: sage home loans corp f k a lenox financial mortgage
Incident
- Discovered
- Dec 19, 2023
- Materiality determined
- —
- Notification sent
- Feb 2, 2024
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSEMPLOYMENTMINOR
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- External
Compliance
- Time to disclose
- 40 weeks(278 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 45d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Dec 19, 2023→ Notified: Feb 2, 202445d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.