HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
LAKEVIEW LOAN SERVICING, LLC
bd_98b80bde8f39d0ee · schema v1 · pii pii-v1
Full breach record for LAKEVIEW LOAN SERVICING, LLC →Lakeview Loan Servicing, LLC disclosed a security incident involving unauthorized access to file servers from Oct 27 to Dec 7, 2021. Access was gained by an unauthorized person, likely via stolen credentials. Exposed data included names, addresses, loan numbers, SSNs, and loan application details. Lakeview engaged Kroll to provide one year of free identity monitoring to affected individuals.
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_024bd16b3d3b4497Oregon State AGfiled 2022-03-18Candidate
- bd_41ad0a8a0d8aba6cNew Hampshire State AGfiled 2022-03-18Verified
- bd_42663a23254ec78fWashington State AGfiled 2022-03-18Verified
- bd_580e820b56eaa008Hawaii State AGfiled 2022-03-18Verified
Show 4 more filings ↓Show fewer ↑up to 3d gap
- bd_5baf31fbfbb62bc2Montana State AGfiled 2022-03-18Verified
- bd_60eb6485a6ad6028Maine State AGfiled 2022-03-18Verified
- bd_fd9ae7962cd74757California State AGfiled 2022-03-18Verified
- bd_126967eedc4c01b7South Carolina State AGfiled 2022-03-21(3d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2022/03/Lakeview-Delaware-Notice.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 18, 2022
- Raw hash
- f8371c4b015c67ad779d536b31a2834cb1695ffa672f1a96ff16e8967830cd63
Reporting entity
- Name
- LAKEVIEW LOAN SERVICING, LLCnorm: lakeview loan servicing
Victim entity
- Name
- LAKEVIEW LOAN SERVICING, LLCnorm: lakeview loan servicing
Incident
- Discovered
- Dec 1, 2021
- Materiality determined
- —
- Notification sent
- Mar 1, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- notify law enforcement
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 15 weeks(107 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.