Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedMulti-Stage ChainPIIIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
VISTA POINT MORTGAGE, LLC
bd_ad9b2d6f611cafc5 · schema v1 · pii pii-v1
Full breach record for VISTA POINT MORTGAGE, LLC →Vista Point Mortgage, LLC notified New Hampshire residents of a data incident where unauthorized access to two employee email accounts occurred between May 21 and June 5, 2024. The breach likely resulted from phishing, compromising valid credentials. The company investigated, secured systems, and offered credit monitoring to affected individuals.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_2e15cc8799d39d60Indiana State AGfiled 2024-11-18Verified
- bd_7ee9599b17047967Maine State AGfiled 2024-11-18Candidate
- bd_9a6faaa8041f7e55California State AGfiled 2024-11-18Verified
- bd_e05d422e5108d090Montana State AGfiled 2024-11-18Verified by operator
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/vista-point-mortgage-20241118.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 18, 2024
- Raw hash
- 99f560f4d86c38d54576ddf2f79889973dde24303541d947f2f67f8298c2bfb8
Reporting entity
- Name
- VISTA POINT MORTGAGE, LLCnorm: vista point mortgage
- Domain
- vistapointmtg.com
Victim entity
- Name
- VISTA POINT MORTGAGE, LLCnorm: vista point mortgage
- Domain
- vistapointmtg.com
Incident
- Discovered
- Jan 1, 2024
- Materiality determined
- Sep 27, 2024
- Notification sent
- Nov 18, 2024
- Affected individuals
- 10
- Data types
- PIIIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- providing written notice of this incident to relevant state and federal regulators, as necessary, and to the three (3) major credit reporting agencies, Equifax, Experian, and TransUnion
- Initial access
- phishing_link
Compliance
- Time to disclose
- 46 weeks(322 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.