DisclosureLens
HackingFinancial ServicesFinanceStolen CredentialsCustomer Data InvolvedIdentity (basic)Government IDFinancial accountMediumContained

CoreLogic Credco

bd_ae7148805dec2de7 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Aug 7, 2017

Filed

Aug 29, 2017

To disclose

22 days

Affected

Not disclosed

Linked

3 filings

Confidence

64%
Full breach record for CoreLogic Credco3 incidents on file

CoreLogic Credco reported that an unauthorized user accessed its systems between July 21 and August 7, 2017, obtaining consumer credit information including names, addresses, Social Security numbers, dates of birth, and account numbers. The company disabled the unauthorized access on August 7, 2017, and deployed enhanced authentication measures. Affected consumers were offered 24 months of identity protection services.

California clockDiscovered Aug 7, 2017Notified Aug 29, 201722d CA 60-day OK22 days discovery → filing

Incident timeline

undetected · 17 days
discovery → filing · 22 days

Jul 21, 2017

Begins

Aug 7, 2017

Discovered

Aug 29, 2017

Filed

vs. sector median

5 wks faster

This filing is one of 3 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (2) · sorted by filing gap

Filing propagation · 3 filings · 3 states

View merged incident ↗
Montana State AGAug 28 · first
California State AG+1d · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.