HackingCustomer Data InvolvedData ExfiltratedIDENTITY_GOVERNMENTIDENTITY_BASICHighContained
NATIONS DIRECT MORTGAGE, LLC
bd_c4a4f6b7a046c47f · schema v1 · pii pii-v1
Full breach record for NATIONS DIRECT MORTGAGE, LLC →Nations Direct Mortgage, LLC reported an external system breach (hacking) occurring on December 30, 2023. The incident compromised the names and Social Security Numbers of 83,108 individuals, including 3 Maine residents. The company notified affected consumers electronically on March 6, 2024, and provided 24 months of credit monitoring and identity theft protection services through Kroll.
Maine clockDiscovered Dec 30, 2023 → Filed with AG Mar 14, 202475d ⏱ ME AG >30d11 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_bb32ed931456f8b1California State AGfiled 2024-03-14Verified
- bd_350dcf1c22ba0641Washington State AGfiled 2024-03-07(7d gap)Candidate
- bd_94972eb2a4784718Indiana State AGfiled 2024-03-06(8d gap)Verified
- bd_5e078e2946202a00Oregon State AGfiled 2024-04-29(46d gap)Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/1ee1929d-4e0f-4b9e-b202-59cb6d9e567d.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 14, 2024
- Raw hash
- 488a5ad965ef630bf952f5a5ef13d8b750794f39b505e49ecd4b1bfd3756cf0e
Reporting entity
- Name
- NATIONS DIRECT MORTGAGE, LLCnorm: nations direct mortgage
Victim entity
- Name
- NATIONS DIRECT MORTGAGE, LLCnorm: nations direct mortgage
Incident
- Discovered
- Dec 30, 2023
- Materiality determined
- —
- Notification sent
- Mar 6, 2024
- Affected individuals
- 83,108
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed data breach notice with Maine Office of the Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 11 weeks(75 days from discovery to filing)
- Compliance flags
- ME AG >30d · 75dME resident >60d · 67d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Dec 30, 2023→ Filed with AG: Mar 14, 202475d 30 days (soft) ME AG >30d Maine Discovered: Dec 30, 2023→ Notified: Mar 6, 202467d 60 days (analyst band; statutory cap is 30 days) ME resident >60d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.