Back to all incidents

LoanDepot

loandepot.com
CONFIRMED

LoanDepot filed Form 8-K Item 1.05 disclosing a major ransomware extortion attack encrypting mortgage servicing systems and compromising 16.6 million customers.

Observable Status CONFIRMED
Industry / Sector Financial Services
Incident Classification Ransomware Extortion & Encryption
Attributed Threat Actor Unknown / Unattributed
Affected Population 16,600,000 records
First Seen 2024-01-08
Last Updated 2024-01-22
Social Security Numbers (SSNs) Mortgage Applications & Financial Statements Bank Account Numbers Personal Identifiable Information (PII) Mortgage Applications Customer PII
OPEN WEIGHTS TELEMETRY • DETERMINISTIC CONFIDENCE

Confidence & Source Corroboration

98% CONFIDENCE
1. Primary Authority CONFIRMED BY REGULATOR Base weight: 65%
2. Evidence Specificity +23% Statutory Filing Verified
3. Corroboration Curve +7% 2 independent domains
4. Timeline & Staleness +3% 3 milestones logged
Corroborated Source Domains:
loandepot.com sec.gov
STATUTORY REGULATORY DISCLOSURES

Official Regulatory Filings & Legal Compliance Records

1 Verified Statutory Filing
Regulatory Ground Truth Standard: The disclosures below represent formal statutory filings and enforcement records submitted to government regulatory authorities (SEC, State Attorneys General, HHS OCR, CISA). In accordance with repository principles, this data is captured exactly as filed by the reporting entity and is never modified, overridden, or synthesized by AI models.
U.S. Securities and Exchange Commission (SEC)

Form 8-K Item 1.05 (Material Cybersecurity Incidents)

CONFIRMED BY REGULATOR
Docket / Accession ID 0001831631-24-000002
Statutory Filing Date 2024-01-08
Disclosed Impact 16,600,000 records
Evidence Standard Regulatory Ground Truth
Statutory Filing Details & Summary (Preserved As Filed):

Item 1.05 Material Cybersecurity Incident disclosure filed by loanDepot, Inc. confirming unauthorized third-party ransomware attack encrypting company servers and exfiltrating 16.9M customer records.

View Official Regulatory Filing Document https://www.sec.gov/Archives/edgar/data/1831631/000183163124000002/lndi-20240108.htm

Technical Forensic Briefing

Incident Overview

LoanDepot filed Form 8-K Item 1.05 disclosing a major ransomware extortion attack encrypting mortgage servicing systems and compromising 16.6 million customers.

Compromised Assets & Data Scope

  • Primary Data Classes: Social Security Numbers (SSNs), Mortgage Applications & Financial Statements, Bank Account Numbers, Personal Identifiable Information (PII).
  • Disclosed Affected Population: Approximately 16,600,000 individuals or records.

Statutory Disclosures & Compliance

  • Statutory filing submitted to SEC (Form 8-K (Item 1.05)) under accession 0001831631-24-000002.

Milestone Timeline (3 events logged)

2024-01-08 15:00 UTC
CONFIRMED BY TARGET

LoanDepot detects unauthorized cyber incident that encrypted company systems and took loan servicing portals offline.

2024-01-11 17:15 UTC
CONFIRMED BY REGULATOR

LoanDepot files Form 8-K Item 1.05 confirming unauthorized third-party access and ransomware encryption.

2024-01-22 18:00 UTC
CONFIRMED BY REGULATOR

Form 8-K Item 1.05 amendment confirms sensitive personal data of approximately 16.6 million individuals was exfiltrated.

Have updated information or a new verifiable source?

This incident record is a flat Markdown file tracked in Git. Propose an update or add a milestone via Pull Request.

Propose Update via GitHub