HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
SN Servicing Corporation
bd_d772c960f49e9ed8 · schema v1 · pii pii-v1
Full breach record for SN Servicing Corporation →SN Servicing Corporation discovered unauthorized access to its network on October 15, 2020. An investigation concluded that an unauthorized party exfiltrated files containing sensitive personal information for some borrowers, including names, contact info, dates of birth, SSNs, and loan information. SN terminated access, engaged forensic investigators, and offered complimentary credit monitoring to affected individuals. Notices were sent in April 2021.
California clockDiscovered Oct 15, 2020 → Notified Apr 27, 2021194d ✗ CA 60-day late39 weeks discovery → filing
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_4bc6fb5649261ccfLeak Siteegregorfiled 2020-10-15(274d gap)Verified
Regulatory filings (5) · sorted by filing gap
- bd_376b6357c22f175fMaine State AGfiled 2021-07-16Verified
- bd_d479dd57d0545f1fOregon State AGfiled 2021-07-16Verified
- bd_7b8b73c450e5945fSouth Carolina State AGfiled 2021-07-26(10d gap)Verified
- bd_0424e3f59662bb0dCalifornia State AGfiled 2021-01-29(168d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 182d gap
- bd_62f5a428547a502dMaine State AGfiled 2021-01-15(182d gap)Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-542995
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 16, 2021
- Raw hash
- f925acb35cf43b6b2ec56fa841f1dc340207ab4160e66e968105749d41c900de
Reporting entity
- Name
- SN Servicing Corporationnorm: sn servicing
Victim entity
- Name
- SN Servicing Corporationnorm: sn servicing
Incident
- Discovered
- Oct 15, 2020
- Materiality determined
- —
- Notification sent
- Apr 27, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1041 Exfiltration Over C2 Channel
- Threat actor
- External
Compliance
- Time to disclose
- 39 weeks(274 days from discovery to filing)
- Compliance flags
- CA 60-day late · 194dLeak >180d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Oct 15, 2020→ Notified: Apr 27, 2021194d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.