BlackCat/ALPHV claimed responsibility for attacks on loanDepot and Prudential Financial, SecurityWeek reported on February 19, 2024. That is a reported claim by a criminal group—not an attribution made in the company filings reviewed. The companies’ disclosures also describe materially different incidents: loanDepot reported encrypted systems and exposure affecting millions of people, while Prudential later reported limited data exfiltration and said it had found no evidence of ransomware or malware.
What BlackCat claimed—and what the filings establish
SecurityWeek reported that BlackCat/ALPHV had taken credit for attacks on both financial companies. The group’s claim should not be treated as independently verified proof that it carried out either intrusion. The company filings document each company’s own incident findings; they do not attribute the incidents to BlackCat/ALPHV. SecurityWeek’s February 19, 2024 report covers the group’s claim.
The distinction matters especially for Prudential: its later filing said the company had found no evidence of ransomware or malware. A ransomware group claiming an attack does not by itself establish that ransomware was deployed.
How the incidents differed
| Question | loanDepot | Prudential Financial |
|---|---|---|
| When did the company report the incident? | loanDepot disclosed unauthorized system activity on January 8, 2024. | Prudential said it detected unauthorized access on February 5, 2024, and that access began February 4. |
| What did the company report about access and data? | It reported unauthorized access and encryption, then disclosed that sensitive personal information had been accessed. | Its February 21 amendment reported exfiltration of limited platform data, including some client information and personally identifiable information, plus company administrative and user data. |
| Did the company report encryption or ransomware? | loanDepot said data had been encrypted. | Prudential said it had found no evidence of malware or ransomware in its February 21 amendment. |
| What scale of personal information was described? | Approximately 16.6 million individuals in its January 22 update; up to approximately 16.9 million in a later SEC amendment. | The amendment described a limited amount of client and personal information, but did not state a number of affected individuals. |
loanDepot: encryption, personal-data exposure and recovery
January 8: unauthorized activity and encrypted data
In an SEC filing dated January 8, 2024, loanDepot said unauthorized activity involved access to company systems and encryption of data. The company said it shut down certain systems while it secured operations and restored service.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minute#1 Best Overall
January 22: approximately 16.6 million people
In a company update dated January 22, 2024, loanDepot said its investigation found unauthorized access to sensitive personal information of approximately 16.6 million individuals. It said it would notify those individuals and provide credit monitoring and identity protection at no cost. The update also described restoration work on loan origination and servicing systems, including the MyloanDepot and servicing customer portals. CEO Frank Martell said, “We sincerely regret any impact to our customers.”
February: up to approximately 16.9 million and estimated expenses
A later SEC amendment said loanDepot expected to notify up to approximately 16.9 million people whose sensitive personal information was affected. The amendment also estimated first-quarter 2024 incident expenses of approximately $12 million to $17 million, net of expected insurance recovery. These are the company’s dated estimates and disclosures, not a final audited total or an independently calculated figure.
The January and February counts have different dates and wording: the earlier update reported approximately 16.6 million individuals, while the later amendment gave an expected notification count of up to approximately 16.9 million. They should not be presented as a single settled count.
Prudential: initial disclosure later updated
February 5: unauthorized access detected
Prudential’s initial SEC filing said it detected unauthorized access on February 5, 2024, with access beginning February 4. At that point, the company said it had no evidence that the threat actor had taken customer or client data.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchRank #3
February 21: limited data exfiltration identified
The initial statement was later supplemented by a February 21 SEC amendment. Prudential said its investigation had identified exfiltration from a platform of limited data, including some client information and personally identifiable information. It also said company administrative and user data had been accessed and exfiltrated, and that a small percentage of employee and contractor user accounts had been accessed.
As of that amendment, Prudential said it had found no evidence of malware, ransomware, destruction or alteration of data, or ongoing attacker access. The later filing therefore changes the data-theft picture from the initial disclosure, but it does not support describing the incident as a confirmed ransomware deployment.
Rank #4
What affected customers should take from the disclosures
loanDepot said it would notify affected individuals and offer credit monitoring and identity protection at no cost. That was the company’s offer in its January 22, 2024 update; the cited statement does not establish that the offer remains available to everyone today. Anyone seeking that assistance should rely on direct notices from loanDepot or contact the company through its official channels rather than assuming the historical offer can be newly enrolled in.
For Prudential, the February amendment confirms that some client and personally identifiable information was exfiltrated, but the reviewed filing does not give a count of affected clients. Affected people should follow any direct notice and instructions from Prudential, since the public disclosure does not identify every potentially affected individual.
Quick Recap
Best Value
How to read the claims accurately
- BlackCat/ALPHV taking credit was a reported group claim, not an attribution by either company in the filings described here.
- loanDepot’s disclosures establish that the company reported encryption and later reported access to sensitive personal information affecting millions of people.
- Prudential’s February 21 amendment updates its earlier statement: it reported limited data exfiltration, while saying it had found no evidence of ransomware or malware.
- The filings and company update are records of disclosures made in 2024; they do not establish any later investigation outcome, legal result or remedy.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




