California Regulator Fines Mortgage Company $825K Over 2023 Ransomware Breach
On August 13, the California Department of Financial Protection and Innovation (DFPI) issued a consent order against a Utah-based mortgage company, imposing an $825,000 penalty for failing to safeguard the personal data of over 284,000 individuals including more than 34,000 California residents. The breach, which occurred in March 2023, involved a threat actor infiltrating the company’s network, deploying malware, stealing employee credentials, and disabling security systems before launching a ransomware attack.
A DFPI examination revealed systemic cybersecurity and governance failures predating the incident. Key deficiencies included:
- Inadequate risk assessments from 2021 to 2023.
- No formal cybersecurity audits between 2017 and 2023.
- Weak vulnerability and patch management, poor access controls, and an incomplete asset inventory.
- Lack of documented remediation for issues identified in penetration testing.
- Insufficient board-level oversight and strategic planning.
The DFPI also determined the company failed to produce a written forensic report detailing the breach’s root cause or corrective actions. These lapses violated the Gramm-Leach-Bliley Act (GLBA) Safeguards Rule, California Civil Code § 1798.100(e), and the state’s Residential Mortgage Lending Act.
Under the consent order accepted without admission of wrongdoing the company must pay the fine, provide affected California borrowers with 12 months of free identity theft insurance, and immediately rectify its recordkeeping and cybersecurity practices.
Source: https://www.jdsupra.com/legalnews/california-dfpi-orders-mortgage-company-2583787/
SecurityNational Mortgage Company cybersecurity rating report: https://www.rankiteo.com/company/securitynational-mortgage-company-3116
"id": "SEC1787590381",
"linkid": "securitynational-mortgage-company-3116",
"type": "Ransomware",
"date": "3/2023",
"severity": "100",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '284,000+ individuals (34,000+ '
'California residents)',
'industry': 'Financial Services',
'location': 'Utah, USA',
'name': 'Utah-based mortgage company (name not '
'disclosed)',
'type': 'Mortgage Company'}],
'attack_vector': 'Malware, Credential Theft',
'customer_advisories': 'Affected California borrowers provided with 12 months '
'of free identity theft insurance',
'data_breach': {'number_of_records_exposed': '284,000+',
'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High (personally identifiable '
'information)',
'type_of_data_compromised': 'Personal data'},
'date_detected': '2023-03',
'date_publicly_disclosed': '2024-08-13',
'description': 'On August 13, the California Department of Financial '
'Protection and Innovation (DFPI) issued a consent order '
'against a Utah-based mortgage company, imposing an $825,000 '
'penalty for failing to safeguard the personal data of over '
'284,000 individuals including more than 34,000 California '
'residents. The breach involved a threat actor infiltrating '
'the company’s network, deploying malware, stealing employee '
'credentials, and disabling security systems before launching '
'a ransomware attack.',
'impact': {'data_compromised': 'Personal data of over 284,000 individuals',
'financial_loss': '$825,000 (fine)',
'identity_theft_risk': 'High (12 months of free identity theft '
'insurance provided to affected borrowers)',
'legal_liabilities': 'Violation of GLBA Safeguards Rule, '
'California Civil Code § 1798.100(e), and '
'California’s Residential Mortgage Lending '
'Act',
'operational_impact': 'Disabling of security systems'},
'investigation_status': 'Completed (DFPI examination)',
'lessons_learned': 'Systemic cybersecurity and governance failures, including '
'inadequate risk assessments, lack of formal cybersecurity '
'audits, weak vulnerability and patch management, poor '
'access controls, incomplete asset inventory, and '
'insufficient board-level oversight.',
'post_incident_analysis': {'corrective_actions': 'Pay fine, provide identity '
'theft insurance, rectify '
'recordkeeping and '
'cybersecurity practices',
'root_causes': 'Inadequate risk assessments, no '
'formal cybersecurity audits, weak '
'vulnerability and patch '
'management, poor access controls, '
'incomplete asset inventory, lack '
'of documented remediation, '
'insufficient board-level '
'oversight'},
'ransomware': {'data_encryption': 'Yes'},
'recommendations': 'Implement formal cybersecurity audits, conduct regular '
'risk assessments, improve vulnerability and patch '
'management, strengthen access controls, maintain a '
'complete asset inventory, document remediation efforts, '
'and enhance board-level oversight and strategic planning.',
'references': [{'date_accessed': '2024-08-13',
'source': 'California Department of Financial Protection and '
'Innovation (DFPI)'}],
'regulatory_compliance': {'fines_imposed': '$825,000',
'legal_actions': 'Consent order issued by DFPI',
'regulations_violated': ['GLBA Safeguards Rule',
'California Civil Code § '
'1798.100(e)',
'California’s Residential '
'Mortgage Lending Act']},
'response': {'remediation_measures': 'Rectify recordkeeping and cybersecurity '
'practices'},
'title': 'California Regulator Fines Mortgage Company $825K Over 2023 '
'Ransomware Breach',
'type': 'Ransomware',
'vulnerability_exploited': 'Inadequate risk assessments, weak vulnerability '
'and patch management, poor access controls, '
'incomplete asset inventory'}