Ransomware
BleepingComputer
Primary Source βIncident Details
California-based mortgage lender LoanDepot was attacked by the ALPHV/BlackCat ransomware gang between January 3-5, 2024. Approximately 16.9 million customers had their personal data exfiltrated, including Social Security numbers, financial account numbers, dates of birth, and contact information. LoanDepot filed an SEC 8-K on January 22, 2024. The gang claimed ransom negotiations included a $6 million demand. Total incident costs approached $27 million. ALPHV was subsequently disrupted by law enforcement in early 2024.
Technical Details
- Initial Attack Vector
- CWE-522: Insufficiently Protected Credentials
- Vendor / Product
- LoanDepot mortgage platform
- Malware Family
- ALPHV/BlackCat ransomware
Timeline
- 2024-01-04 Breach occurred
- 2024-01-22 Publicly disclosed
- 2024-05-09 Customers notified