MalwareRansomwareLockBitLockBit 3.xData ExfiltratedCustomer Data InvolvedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
PLANET HOME LENDING, LLC
bd_9a07f8813460f791 · schema v1 · pii pii-v1
Full breach record for PLANET HOME LENDING, LLC →Planet Home Lending, LLC disclosed a ransomware incident involving the LockBit threat actor. The attack exploited the 'Citrix Bleed' vulnerability (CVE-2023-46805) in Citrix software on November 15, 2023. The actor accessed a read-only folder containing loan files with PII, including names, addresses, SSNs, and financial account numbers. Planet notified the FBI, contained the threat, and is offering 24 months of credit monitoring. No ransom was paid.
Leak gap clock✗ Leak >180d10 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 4 about the same incident.View merged incident
A leak claim by cl0p about this victim predates this filing by 183 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_ea73c1985b4e24abIndiana State AGfiled 2024-01-25Verified
- bd_6a67d4bb7edefa9bMaine State AGfiled 2024-01-26(1d gap)Verified
- bd_6076d03c1a327fbbWashington State AGfiled 2024-01-23(2d gap)Candidate
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2024/02/EXPERIAN_K7176_Planet-Home-Lending_L01_SAS_1.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 25, 2024
- Raw hash
- ac22aa9e1875d53c7276bfbb9b49cdfc4af0ccdab664100c8d87c97f9e7bbb09
Reporting entity
- Name
- PLANET HOME LENDING, LLCnorm: planet home lending
- Domain
- planethomelending.com
Victim entity
- Name
- PLANET HOME LENDING, LLCnorm: planet home lending
- Domain
- planethomelending.com
Incident
- Discovered
- Nov 15, 2023
- Materiality determined
- —
- Notification sent
- Jan 24, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access· LockBit
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1486 Data Encrypted for Impact
- Threat actor
- LockBitExternalFinancial
- Regulator citations
- Notified the FBI
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 10 weeks(71 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.