HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Community Loan Servicing
bd_bd7781afa1180b0c · schema v1 · pii pii-v1
Full breach record for Community Loan Servicing →Community Loan Servicing LLC experienced unauthorized access to file servers containing mortgage loan data from October 27, 2021, to December 7, 2021. The breach exposed names, Social Security numbers, and loan application details. The company engaged law enforcement and forensic investigators, contained the incident, and provided one year of complimentary identity monitoring via Kroll to affected individuals.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_12b6867755eea3a1Montana State AGfiled 2022-08-19Candidate
- bd_638d85ff9c9775f8Oregon State AGfiled 2022-08-19Verified by operator
- bd_88940eaf560a23b8Delaware State AGfiled 2022-08-19Verified
- bd_fad7aa2f9c7e8e86Washington State AGfiled 2022-08-19Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-556436
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 19, 2022
- Raw hash
- cba8714229a5150df9a24ff379f0c2e1cba3637d3db9aa0c81c4c1392a10333a
Reporting entity
- Name
- Community Loan Servicingnorm: community loan servicing
Victim entity
- Name
- Community Loan Servicingnorm: community loan servicing
Incident
- Discovered
- Dec 7, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 36 weeks(255 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.