MR. COOPER GROUP INC.
ent_019e628ab4929a0c9e37a4bc24d84329
Disclosures
8
State AG · SEC 8-K · 6 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
55,958
as filed · State AG HI
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- MR. COOPER GROUP INC.
- Normalized
- mr cooper— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300KD8C6DPXYC2M26
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (8)newest first
- Delaware State AGas victim2024-03-26
Mr. Cooper (Nationstar Mortgage LLC) disclosed a data breach occurring between October 30 and November 1, 2023, involving unauthorized access to systems containing personal information of approximately 47,818 Rhode Island residents. The incident involved the exfiltration of names, addresses, SSNs, dates of birth, and bank account numbers. Mr. Cooper shut down systems, engaged cybersecurity experts, and notified law enforcement. Affected individuals were offered 24 months of credit monitoring and fraud assistance.
- FEDERALSEC 8-Kas victim2023-12-15
Mr. Cooper Group Inc. filed an amended 8-K disclosing a cybersecurity incident that occurred on October 31, 2023, where an unauthorized third party accessed technology systems. Personal information of substantially all current and former customers was obtained. The company is offering two years of complimentary identity protection and credit monitoring. Forensic review and litigation are ongoing. Estimated vendor expenses related to the incident are updated to $25 million.
- Hawaii State AGas reporting2023-12-05
Nationstar Mortgage LLC (dba Mr. Cooper) disclosed a data breach where unauthorized access occurred between Oct 30 and Nov 1, 2023. Suspicious activity was detected on Oct 31, 2023. Personal information including names, SSNs, DOBs, and bank account numbers were accessed. The company shut down systems, engaged forensic experts, and notified law enforcement. Credit monitoring services were offered to affected individuals.
- FEDERALSEC 8-Kas victim2023-11-09
Mr. Cooper Group Inc., a residential mortgage servicer, disclosed via Form 8-K/A on November 9, 2023 that on October 31, 2023 it detected unauthorized third-party access to certain technology systems. The company shut down systems precautiously, disrupting customer payments and account access from November 1-4, 2023. Preliminary analysis found certain customer data was exposed; scope still under investigation. The company estimated $5-10 million of additional Q4 vendor costs and notified law enforcement and regulators.
- FEDERALSEC 8-Kas victim2023-11-02
Mr. Cooper Group Inc. determined on October 31, 2023 that it had experienced a cybersecurity incident in which an unauthorized third party gained access to certain technology systems. The company initiated containment measures, shut down systems, engaged cybersecurity experts, and notified law enforcement. The investigation was ongoing as of the filing date.
- New Hampshire State AGas victim2021-08-27
LERETA, LLC, a provider of real estate tax and flood zone determination services, notified the New Hampshire Attorney General of a data incident affecting Mr. Cooper. On May 28, 2020, an unauthorized third party gained access to LERETA systems, potentially exposing names and Social Security numbers of 45 New Hampshire residents. LERETA engaged forensic experts, secured systems, and offered complimentary identity protection services through IDX to affected individuals.
- Montana State AGas reporting2018-01-05
Nationstar Mortgage LLC (d/b/a Mr. Cooper) disclosed an inadvertent mailing error occurring on or about October 9, 2017, where borrowers received another borrower's personal information (names, addresses, loan numbers). The company offered one year of complimentary credit monitoring and identity theft protection services.
- California State AGas victim2017-08-30
Mr. Cooper (Nationstar Mortgage LLC) disclosed that on July 5, 2017, an incident occurred where a borrower's loan number and property address were inadvertently populated on another borrower's letter. The company is offering complimentary credit monitoring through Assurant ID Fraud Solutions to affected individuals.