Ransomware

BleepingComputer

πŸ“… 2024-01-04 🏒 LoanDepot mortgage platform 🦠 ALPHV/BlackCat ransomware
Primary Source β†—

Incident Details

California-based mortgage lender LoanDepot was attacked by the ALPHV/BlackCat ransomware gang between January 3-5, 2024. Approximately 16.9 million customers had their personal data exfiltrated, including Social Security numbers, financial account numbers, dates of birth, and contact information. LoanDepot filed an SEC 8-K on January 22, 2024. The gang claimed ransom negotiations included a $6 million demand. Total incident costs approached $27 million. ALPHV was subsequently disrupted by law enforcement in early 2024.

Technical Details

Initial Attack Vector
CWE-522: Insufficiently Protected Credentials
Vendor / Product
LoanDepot mortgage platform
Malware Family
ALPHV/BlackCat ransomware

Timeline

  1. 2024-01-04 Breach occurred
  2. 2024-01-22 Publicly disclosed
  3. 2024-05-09 Customers notified