HackingEmployee Data InvolvedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumResolved
ACADEMY MORTGAGE CORPORATION
bd_e728b3b38da97809 · schema v1 · pii pii-v1
Full breach record for ACADEMY MORTGAGE CORPORATION →Academy Mortgage Corporation detected a network security incident on March 21, 2023, where an unauthorized third party accessed and disabled systems. The investigation concluded in November 2023, determining that personal information (names, SSNs, dates of birth) of current/former employees and mortgage applicants may have been accessed. No evidence of misuse was found. The company engaged forensic specialists, notified law enforcement, rebuilt systems, and offered credit monitoring.
California clockDiscovered Mar 21, 2023 → Notified Dec 20, 2023274d ✗ CA 60-day late41 weeks discovery → filing
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_6ec09ae80601c340Leak Sitealphvfiled 2023-05-14(236d gap)Verified by operator
Regulatory filings (5) · sorted by filing gap
- bd_d76d3319b21c6f7bOregon State AGfiled 2024-01-05Verified by operator
- bd_3b5884dbff92d2bbMontana State AGfiled 2023-12-27(9d gap)Verified by operator
- bd_e304b68c35220b07Washington State AGfiled 2023-12-27(9d gap)Verified
- bd_7a0d1938864b9a74California State AGfiled 2024-01-15(10d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 10d gap
- bd_a04b7d44352861c2Maine State AGfiled 2024-01-15(10d gap)Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-578941
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 5, 2024
- Raw hash
- 41580c2f55e4ac709c396f8688d55676d5b2480bd5015d7dc600fcb35708d9ed
Reporting entity
- Name
- ACADEMY MORTGAGE CORPORATIONnorm: academy mortgage
Victim entity
- Name
- ACADEMY MORTGAGE CORPORATIONnorm: academy mortgage
Incident
- Discovered
- Mar 21, 2023
- Materiality determined
- —
- Notification sent
- Dec 20, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- Threat actor
- External
Compliance
- Time to disclose
- 41 weeks(290 days from discovery to filing)
- Compliance flags
- CA 60-day late · 274dLeak >180d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 21, 2023→ Notified: Dec 20, 2023274d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.