HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Pingora Loan Servicing, LLC
bd_dc39405a4003c9b9 · schema v1 · pii pii-v1
Full breach record for Pingora Loan Servicing, LLC →Pingora Loan Servicing, LLC notified Delaware residents of a security incident involving unauthorized access to file servers from October 27, 2021, to December 7, 2021. The breach exposed names, addresses, loan numbers, and Social Security numbers for some individuals, with additional loan-related data for others. Pingora engaged law enforcement and forensic investigators, contained the incident, and offered one year of complimentary identity monitoring through Kroll.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_3204996119abee85New Hampshire State AGfiled 2022-04-06Verified
- bd_625fef58856fbcdcMontana State AGfiled 2022-04-06Candidate
- bd_638543a08cfb9f9fCalifornia State AGfiled 2022-04-06Verified
- bd_af92f7dd267474c4Washington State AGfiled 2022-04-06Verified
Show 1 more filing ↓Show fewer ↑
- bd_bdb38b23603d3ef5Oregon State AGfiled 2022-04-06Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2022/05/Pingora_DE-Sample.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 6, 2022
- Raw hash
- 96e34de78832a36a981630f18e092d1c86537ae14dfe9110b047591fdb2306fe
Reporting entity
- Name
- Pingora Loan Servicing, LLCnorm: pingora loan servicing
Victim entity
- Name
- Pingora Loan Servicing, LLCnorm: pingora loan servicing
Incident
- Discovered
- Dec 1, 2021
- Materiality determined
- —
- Notification sent
- May 1, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 18 weeks(126 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.