Mr. Cooper Group Inc. disclosed a cybersecurity incident on October 31, 2023, where an unauthorized third party gained access to certain technology systems. The company initiated containment measures, shut down systems, engaged cybersecurity experts, and notified law enforcement. The investigation was ongoing as of the filing date.
SEC 4-day OK · 2d
🇺🇸FEDERALSEC 8-Klinked via same-victim cross-source · 95%
Mr. Cooper Group Inc., a residential mortgage servicer, disclosed via Form 8-K/A on November 9, 2023 that on October 31, 2023 it detected unauthorized third-party access to certain technology systems. The company shut down systems precautiously, disrupting customer payments and account access from November 1-4, 2023. Preliminary analysis found certain customer data was exposed; scope still under investigation. The company estimated $5-10 million of additional Q4 vendor costs and notified law enforcement and regulators.
🌺Hawaii State AGlinked via same-victim cross-source · 95%
Mr. Cooper (Nationstar Mortgage LLC) notified Hawaii residents of a data breach occurring between October 30 and November 1, 2023. Unauthorized access resulted in the exfiltration of personal information including names, addresses, SSNs, dates of birth, and bank account numbers. Approximately 47,818 Rhode Island residents were specifically identified. The company shut down systems, engaged forensic experts, and notified law enforcement. Affected individuals were offered 24 months of credit monitoring.
🇺🇸FEDERALSEC 8-KMost recentlinked via same-victim cross-source · 95%
Mr. Cooper Group Inc. filed an amended 8-K disclosing a cybersecurity incident discovered on October 31, 2023, where an unauthorized third party accessed technology systems. Personal information of substantially all current and former customers was obtained. The company is offering two years of complimentary identity protection and credit monitoring. Forensic review and litigation are ongoing. Estimated vendor expenses related to the incident are updated to $25 million.
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.