Social EngineeringPhishingCustomer Data InvolvedPIIIDENTITY_BASICLowContained
Citadel Servicing Corporation
bd_9985eb9443c3b9c2 · schema v1 · pii pii-v1
Full breach record for Citadel Servicing Corporation →Citadel Servicing Corporation (dba Acra Lending) reported a data security incident involving unauthorized access to email accounts. The breach occurred between March 31, 2021, and August 24, 2021. The incident involved phishing leading to email compromise, exposing customer names. The company engaged forensic investigators, contained the accounts, and offered 12 months of credit monitoring via TransUnion.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-551893
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 22, 2022
- Raw hash
- c83543de753d20db0856aa3600688dfd1587578e51839eae74269e446ec2148d
Reporting entity
- Name
- Citadel Servicing Corporationnorm: citadel servicing
Victim entity
- Name
- Citadel Servicing Corporationnorm: citadel servicing
Incident
- Discovered
- Feb 18, 2022
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- External
- Regulator citations
- Filed breach notification with California Office of the Attorney General
- Initial access
- phishing_link
Compliance
- Time to disclose
- 5 weeks(32 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.