DisclosureLens
Social EngineeringFinancial ServicesFinancePhishingStolen CredentialsCustomer Data InvolvedTargetedIdentity (basic)Government IDFinancial accountMediumContained

Wintrust Mortgage

bd_e6a7b075116e430a · schema v1 · pii pii-v1

Severity

Medium

Discovered

Dec 31, 2017

Filed

Feb 2, 2018

To disclose

5 weeks

Affected · nationwide

751 in this filing

Confidence

66%
Full breach record for Wintrust Mortgage3 incidents on file

Wintrust Mortgage notified the NH AG of a phishing attack on an employee in early Dec 2017. The incident exposed customer PII (names, SSNs, DOBs, driver's licenses, financial account numbers) via the compromised email. 75 customers were notified, including 1 NH resident. Wintrust locked the account, investigated, and provided 24 months of credit monitoring.

Incident timeline

undetected · 30 days
discovery → filing · 5 weeks / 33 days

Dec 1, 2017

Begins

Dec 31, 2017

Discovered

Feb 2, 2018

Filed

vs. sector median

4 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed75 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.