loanDepot, Inc.
ent_019de19e04d52e8eccb41c86f79b2ac9
Disclosures
6
SEC 8-K · Leak Site · State AG · 4 jurisdictions
Incidents
2
filings grouped by incident
Max affected reported
16,900,000
nationwide · SEC 8-K FEDERAL
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- loanDepot, Inc.
- Normalized
- loandepot— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 5493003261L42OH8RK59
- SEC EDGAR CIK
- 0001831631
- Domain
- loandepot.com
Disclosure history (6)newest first
- FEDERALSEC 8-Kas victim2024-02-27
loanDepot, Inc. filed an amended 8-K (Amendment No. 2) regarding a cybersecurity incident it has contained. The company identified unauthorized access to sensitive personal information, impacting up to 16.9 million individuals. The company is notifying affected individuals and offering free credit monitoring. The incident is expected to result in $12-17 million in Q1 2024 expenses, net of insurance. Law enforcement and regulatory engagement continues.
- GLOBALLeak Siteas victim2024-02-16
LoanDepot, is an Irvine, California-based nonbank holding company which sells mortgage and non-mortgage lending products.
- FEDERALSEC 8-Kas victim2024-01-22
loanDepot, Inc. filed an amended Form 8-K (Amendment No. 1) on January 22, 2024, providing supplemental information regarding a cybersecurity incident affecting certain systems. The Company stated it has not yet determined if the incident is material. A press release dated January 22, 2024, was attached as Exhibit 99.1. The filing does not specify the nature of the breach, data types affected, or number of individuals impacted.
- FEDERALSEC 8-Kas victim2024-01-08
loanDepot, Inc. disclosed on Form 8-K (Item 8.01) a cybersecurity incident affecting certain systems. Unauthorized third-party activity included access to Company systems and the encryption of data. The Company contained the incident, shut down certain systems, engaged cybersecurity experts, and notified regulators and law enforcement. Investigation is ongoing; materiality assessment continuing.
- 🦞Maine State AGas victim2023-05-05
loanDepot, Inc. reported an external system breach that occurred on August 2, 2022, and was discovered the following day. The breach compromised the names and Social Security numbers of 1,361 individuals, including 9 residents of Maine. Affected individuals were notified on May 8, 2023, and offered 24 months of credit monitoring and identity theft protection services from Experian.
- 🦬Montana State AGas victim2023-05-05
loanDepot reported a data breach to the Montana Attorney General. The breach was reported on 2023-05-05. The breach occurred from 8/2/2022 to 8/3/2022. 2 Montana residents were affected.
Subsidiary disclosures (8)filed by group companies
◈ These filings were made by or about subsidiaries of loanDepot, Inc. — not by loanDepot, Inc. itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- 💎Delaware State AGvia LOANDEPOT.COM, LLC2024-02-23
loanDepot.com, LLC disclosed a data breach occurring between January 3-5, 2024, where an unauthorized third party accessed systems containing names, addresses, SSNs, financial account numbers, and dates of birth. The company contained the incident, contacted law enforcement, and engaged forensic experts. Affected individuals are offered 24 months of credit monitoring and identity protection services via Experian.
- 🦫Oregon State AGvia LOANDEPOT.COM, LLC2024-02-23
loanDepot.com, LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2024-02-23. The breach occurred during 1/3/2024 - 1/5/2024. The breach was discovered on 1/4/2024. 16,924,071 individuals were affected. Notice was sent on 2/23/2024.
- 🐻California State AGvia LOANDEPOT.COM, LLC2024-02-23
loanDepot.com, LLC notified the California Attorney General of a data breach where an unauthorized third party accessed systems between January 3 and January 5, 2024. The incident was identified on January 4, 2024. Affected data includes names, addresses, emails, phone numbers, dates of birth, social security numbers, and financial account numbers. The company contained the incident, engaged forensic experts, and offered 24 months of identity protection services via Experian.
- 🦞Maine State AGvia LOANDEPOT.COM, LLC2024-02-23
loanDepot.com, LLC reported a data breach affecting 16,924,071 individuals, which occurred between January 3, 2024, and January 5, 2024. The breach was discovered on January 4, 2024, and involved an external system breach (hacking). The compromised data included names and Social Security numbers. Affected individuals were notified on February 23, 2024, and offered 24 months of complimentary credit monitoring and identity theft protection services through Experian.
- 🦬Montana State AGvia LOANDEPOT.COM, LLC2024-02-23
loanDepot.com, LLC reported a data breach to the Montana Attorney General. The breach was reported on 2024-02-23. The breach occurred from 1/3/2024 to 1/4/2024. 49,134 Montana residents were affected.
- 🌺Hawaii State AGvia LOANDEPOT.COM, LLC2024-02-23
loanDepot.com, LLC notified Hawaii residents of a data breach occurring between January 3-5, 2024. An unauthorized third party accessed systems containing names, addresses, SSNs, financial account numbers, and dates of birth. loanDepot contained the incident, contacted law enforcement, and engaged forensic experts. Affected individuals were offered 24 months of credit monitoring and identity protection via Experian.
- 🏎️Indiana State AGvia LOANDEPOT.COM, LLC2024-02-23
loanDepot.com, LLC reported a data breach to the Indiana Attorney General. The breach occurred on 2024-01-03 and was reported on 2024-02-23. 302,021 Indiana residents were affected. 16,924,071 individuals affected in total.
- 🌲Washington State AGvia LOANDEPOT.COM, LLC2024-02-15
loanDepot.com, LLC, a finance sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2024-01-03 and filed notice on 2024-02-15. 502,513 Washington residents were affected. 43 days elapsed between awareness and notification. 0 days to identify the breach. 2 days to contain the breach.