PennyMac Loan Services, LLC Impacted by MOVEit Data Breach at Sovos Compliance

Console and Associates, P.C.
Contact

On August 28, 2023, Sovos Compliance, LLC (“Sovos”) filed notice with the Attorney General of California on behalf of PennyMac Loan Services, LLC (“PennyMac”). In this notice, Sovos explains that the incident resulted in an unauthorized party being able to access PennyMac customers’ sensitive information. Upon completing its investigation, PennyMac began sending out data breach notification letters to all individuals whose information was affected by the recent data security incident.

If you received a data breach notification from Sovos Compliance discussing information you provided to PennyMac Loan Services, LLC, it is essential you understand what is at risk and what you can do about it. A data breach lawyer can help you learn more about how to protect yourself from becoming a victim of fraud or identity theft, as well as discuss your legal options following the Sovos / PennyMac Loan Services data breach. For more information, please see our recent piece on the topic here.

What Caused the Data Breach Affecting PennyMac Loan Services Customers?

The Sovos data breach impacting PennyMac customers was only recently announced, and more information is expected in the near future. However, Sovos’ filing with the Attorney General of California provides some important information on what led up to the breach. According to this source, Sovos acts as a vendor to financial services companies, providing them with certain services. In the normal course of business, Sovos uses a third-party application called MOVEit, which is created by Progress Software.

On May 31, 2023, Progress Software announced a previously unknown vulnerability in its MOVEit Transfer application. In response, Sovos took its MOVEit application offline and launched an investigation with the assistance of outside data security experts.

On July 28, 2023, the Sovos investigation confirmed that certain information belonging to PennyMac customers was compromised when hackers exploited the vulnerability in Sovos’ instance of MOVEit. The incident did not involve hackers gaining access to any of PennyMac’s systems.

After learning that sensitive consumer data was accessible to an unauthorized party, PennyMac Loan Services reviewed the compromised files to determine what information was leaked and which consumers were impacted.

On August 28, 2023, Sovos Compliance sent out data breach letters on behalf of PennyMac to all customers who were affected by the recent data security incident. These letters should provide victims with a list of what information belonging to them was compromised.

More Information About PennyMac Financial Services, Inc. and Sovos Compliance

PennyMac Financial Services, Inc. is a residential mortgage company based out of Westlake Village, California. One of the largest residential mortgage lenders in the United States, PennyMac operates through two subsidiaries, PennyMac Loan Services, LLC and PNMAC Capital Management, LLC. PennyMac Loan Services has worked with over four million homeowners over the past 15 years. PennyMac Loan Services employs more than 6,000 people and generates approximately $2.8 billion in annual revenue.

Founded in 1979, Sovos Compliance LLC is a financial software company based out of Wilmington, Massachusetts. Sovos creates software solutions for tax determination, continuous transaction control compliance, and tax & regulatory reporting. Sovos Compliance employs more than 2,400 people and generates approximately $504 million in annual revenue.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations. Attorney Advertising.

© Console and Associates, P.C.

Written by:

Console and Associates, P.C.
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Console and Associates, P.C. on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide