Skip to main content

Planet Home Lending Discloses Ransomware Attack

Jan 31, 2024
cybesecurity
News Director

Company attributes cybersecurity breach to vulnerability in third-party vendor software; provides credit monitoring for affected customers.

Months after a ransomware attack that occurred on Nov. 15, 2023, Planet Home Lending is reporting the incident to nearly 200,000 customers and offering two years of credit monitoring and identity theft services.  

In a letter filed with the Maine Attorney General's office dated January 25, it blamed a third-party vendor for the vulnerability that allowed the incident to happen. The lender sent the same notice to customers affected by the recent data security incident the day prior. 

"Planet was one of many companies around the world whose information security systems were compromised by the threat actor LockBit in connection with one of its recent global ransomware campaigns. The root cause of the incident was a vulnerability (which has been termed “Citrix Bleed”) existing in a software program that Planet purchased from Citrix Systems, Inc., a worldwide leader in technology solutions," the letter states. "While Planet had implemented multiple layers of security tools designed to prevent this type of unauthorized access, the threat actor was able to exploit this Citrix Bleed vulnerability to bypass these protections."

The personally identifiable information taken included customers' names, addresses, SSNs, loan numbers and financial account numbers. 

The company tells customers that it immediately took action following the discovery of the breach. 

"Upon learning of this incident, we promptly secured our environment, conducted a full forensic investigation to determine the nature and scope of the compromise, and notified the FBI. In accordance with the
standard recommendation of the FBI and financial regulators, we have not paid, and do not anticipate paying, any ransom amount to the threat actor," the letter continues. 

In recent months, four financial services companies — First American, Fidelity National Financial, Mr. Cooper, and loanDepot  — have each disclosed separate incidents involving cybersecurity breaches and ransomware attacks. All four companies have notified government authorities and impacted parties.

Meanwhile, Connecticut-based Planet Financial Group, LLC, the parent company of Planet Home Lending, announced it ended the year with residential origination volume at $25 billion, down 5% from 2022. Mortgage servicing rights ended the year at $104.69 billion, up 42% from 2022. 

About the author
Christine Stuart is the news director at NMP.
Published
Jan 31, 2024
It's A Buyers' Market In Texas And Florida!!!

Redfin says sellers are cutting their asking prices in the two southern states.

Apr 26, 2024
Pending Home Sales Climbed 3.4% In March

National Association of Realtors reports gains in Northeast, South and West, with a slight drop in the Midwest

Apr 26, 2024
Mortgage Rates Continue Their Ascent

The 30-year FRM averaged 7.17% as of April 25, 2024, up from last week, when it averaged 7.10%.

Apr 26, 2024
February Delinquency Rates Remain Historically Low

Most homeowners with a mortgage still able to make their payments on time in February, CoreLogic report shows.

Apr 26, 2024
Homebuying Excitement Is Up Among Veterans

Survey results indicate optimism about housing market among U.S. veterans and service members

Apr 25, 2024
U.S. Economy Grew At 1.6% Rate In Q1

The slowdown comes at the same time that the Federal Reserve's efforts to combat inflation have stalled.

Apr 25, 2024