HackingStolen CredentialsCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICHighContained
CMG MORTGAGE, INC.
bd_d28f503238f6ba55 · schema v1 · pii pii-v1
Full breach record for CMG MORTGAGE, INC. →CMG Mortgage Inc. reported an external system breach (hacking) occurring on March 18, 2022, discovered on March 22, 2022. The incident affected 1,989 individuals, including 4 Maine residents. Acquired data included names and Social Security Numbers. CMG Mortgage, represented by outside counsel Cooley LLP, sent written notifications on March 30, 2022, and offered identity theft protection services.
Maine clockDiscovered Mar 22, 2022 → Filed with AG Mar 30, 20228d ✓ ME AG ≤30d8 days discovery → filing
⚠ AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_689d17e982b3d18cMontana State AGfiled 2022-03-31(1d gap)Verified
- bd_47cebf94e996f099Maine State AGfiled 2022-03-29(1d gap)Candidate
- bd_bd4d0113d89043fcNew Hampshire State AGfiled 2022-04-04(5d gap)Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/cb17fa1b-62ea-41a1-b48e-a75d545f5aec.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 30, 2022
- Raw hash
- 11f1a8039b6d77946c89db16747237573aff869d896491e370a43a4b1f420325
Reporting entity
- Name
- CMG MORTGAGE, INC.norm: cmg mortgage
- Industry
- Financial Services
Victim entity
- Name
- CMG MORTGAGE, INC.norm: cmg mortgage
- Industry
- Financial Services
Incident
- Discovered
- Mar 22, 2022
- Materiality determined
- —
- Notification sent
- Mar 30, 2022
- Affected individuals
- 1,989
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Filed data breach notice with Maine Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 8 days(8 days from discovery to filing)
- Compliance flags
- ME AG ≤30d · 8d
- Discovery-date grounding
- AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Mar 22, 2022→ Filed with AG: Mar 30, 20228d 30 days ME AG ≤30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.