Social EngineeringPhishingStolen CredentialsData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedDelayed DiscoveryIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTHEALTH_BASICCREDENTIALSHighContained
Guaranteed Rate, Inc
bd_ce105c14a20cc03e · schema v1 · pii pii-v1
Full breach record for Guaranteed Rate, Inc →Guaranteed Rate, Inc. reported a phishing incident affecting email accounts between June 9 and October 2, 2017. Unknown actors accessed accounts and viewed/downloaded PII including SSNs, driver's licenses, financial account info, health info, and credentials. 23,427 California residents were notified on Jan 12, 2018. Remediation included password resets, phishing training, and 2 years of credit monitoring.
California clockDiscovered Sep 13, 2017 → Notified Jan 12, 2018121d ✗ CA 60-day late17 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_1ab523da01910300Montana State AGfiled 2018-01-12Candidate
- bd_aef4207386017ce2Oregon State AGfiled 2018-01-12Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-132638
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 12, 2018
- Raw hash
- 975cc6ec9e8216a19685f47ca354c4d4753d49098f3c043d2eaf5c48184a69fc
Reporting entity
- Name
- Guaranteed Rate, Incnorm: guaranteed rate
Victim entity
- Name
- Guaranteed Rate, Incnorm: guaranteed rate
Incident
- Discovered
- Sep 13, 2017
- Materiality determined
- —
- Notification sent
- Jan 12, 2018
- Affected individuals
- 23,427
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTHEALTH_BASICCREDENTIALS
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Provided written notice to other state regulatorsProvided written notice to the three major consumer reporting agenciesProvided written notice to the FBIProvided written notice to the United States Secret Service
- Initial access
- phishing_link
Compliance
- Time to disclose
- 17 weeks(121 days from discovery to filing)
- Compliance flags
- CA 60-day late · 121d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Sep 13, 2017→ Notified: Jan 12, 2018121d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.