HackingFinancial ServicesTechnologyFinanceVulnerability ExploitCapture Stored DataZero-DayData ExfiltratedSupply Chain (3P Vendor)Customer Data InvolvedPIILowContained
ROUNDPOINT MORTGAGE SERVICING LLC
bd_dfdcbd784dfec32a · schema v1 · pii pii-v1
Full breach record for ROUNDPOINT MORTGAGE SERVICING LLC →Sovos Compliance, LLC notified individuals on behalf of RoundPoint Mortgage Servicing LLC regarding a security incident stemming from the MOVEit Transfer zero-day vulnerability announced by Progress Software on May 31, 2023. Unauthorized actors exploited the vulnerability to download files containing personal information. Sovos took the affected application offline and offered two years of complimentary credit monitoring through Kroll.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-572536
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 29, 2023
- Raw hash
- 66526c03daea0b5ee499ac7e61e8e9c7a1220bfaa2d7a7dd0efce1ee5b3ef278
Reporting entity
- Name
- ROUNDPOINT MORTGAGE SERVICING LLCnorm: roundpoint mortgage servicing
Victim entity
- Name
- ROUNDPOINT MORTGAGE SERVICING LLCnorm: roundpoint mortgage servicing
- Industry
- Financial ServicesllmTechnologyllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PII
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified law enforcement
- Third party
- via Sovos Compliance, LLC
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.