Incident Score: Analysis & Impact (COR1772749753)
The details regarding individual company incidents & reports gives you full view from every side.
Rankiteo Score Impact Analysis
Key Highlights From The Incident Analysis
- Timeline of Cornerstone First Mortgage, LLC's Breach and lateral movement inside company's environment.
- Overview of affected data sets, including SSNs and PHI, and why they materially increase incident severity.
- How Rankiteo’s incident engine converts technical details into a normalized incident score.
- How this cyber incident impacts Cornerstone First Mortgage, LLC Rankiteo cyber scoring and cyber rating.
- Rankiteo’s MITRE ATT&CK correlation analysis for this incident, with associated confidence level.
Full Incident Analysis Transcript
In this Rankiteo incident briefing, we review the Cornerstone First Mortgage, LLC breach identified under incident ID COR1772749753.
The analysis begins with a detailed overview of Cornerstone First Mortgage, LLC's information like the linkedin page: https://www.linkedin.com/company/cornerstone-first-mortgage, the number of followers: 5356, the industry type: Banking and the number of employees: 567 employees
After the initial compromise, the video explains how Rankiteo's incident engine converts technical details into a normalized incident score. The incident score before the incident was 756 and after the incident was 684 with a difference of -72 which is could be a good indicator of the severity and impact of the incident.
In the next step of the video, we will analyze in more details the incident and the impact it had on Cornerstone First Mortgage, LLC and their customers.
On 05 March 2026, Cornerstone First Mortgage disclosed Data Breach issues under the banner "Cornerstone First Mortgage Discloses 2023 Data Breach Affecting 73 Massachusetts Residents".
Cornerstone First Mortgage reported a data breach impacting at least 73 Massachusetts residents who provided personal information to the company or its predecessor.
The disruption is felt across the environment, and exposing Social Security numbers and other sensitive data, with nearly 73 records at risk.
In response, and began remediation that includes Offering 24 months of complimentary credit monitoring and identity protection services, and stakeholders are being briefed through Advising affected customers to monitor financial accounts, review credit reports, and consider placing fraud alerts or security freezes.
The case underscores how Ongoing, with advisories going out to stakeholders covering Affected individuals must enroll by May 11, 2026, using activation codes provided directly by the company. Advised to monitor financial accounts, review credit reports, and consider placing fraud alerts or security freezes.
Finally, we try to match the incident with the MITRE ATT&CK framework to see if there is any correlation between the incident and the MITRE ATT&CK framework.
The MITRE ATT&CK framework is a knowledge base of techniques and sub-techniques that are used to describe the tactics and procedures of cyber adversaries. It is a powerful tool for understanding the threat landscape and for developing effective defense strategies.
MITRE ATT&CK® Correlation Analysis
Rankiteo's analysis has identified several MITRE ATT&CK tactics and techniques associated with this incident, each with varying levels of confidence based on available evidence. Under the Initial Access tactic, the analysis identified Valid Accounts (T1078) with moderate confidence (60%), supported by evidence indicating breach occurred between July and August 2023 but was not discovered until September 2025 and Exploit Public-Facing Application (T1190) with moderate confidence (50%), supported by evidence indicating company has not disclosed the cause of the breach. Under the Credential Access tactic, the analysis identified Unsecured Credentials (T1552) with moderate to high confidence (70%), supported by evidence indicating social Security numbers and other sensitive data exposed and OS Credential Dumping (T1003) with moderate confidence (50%), supported by evidence indicating prolonged window of potential exposure (July-Aug 2023 to Sept 2025). Under the Collection tactic, the analysis identified Data from Local System (T1005) with moderate to high confidence (80%), supported by evidence indicating social Security numbers and other sensitive data compromised. Under the Exfiltration tactic, the analysis identified Exfiltration Over C2 Channel (T1041) with moderate to high confidence (70%), supported by evidence indicating data breach impacting 73 Massachusetts residents and Transfer Data to Cloud Account (T1537) with moderate confidence (50%), supported by evidence indicating company has not disclosed the cause of the breach. Under the Impact tactic, the analysis identified Data Destruction (T1485) with lower confidence (40%), supported by evidence indicating prolonged window of potential exposure (July-Aug 2023 to Sept 2025) and Data Manipulation: Stored Data Manipulation (T1565.001) with lower confidence (30%), supported by evidence indicating company has not disclosed the cause of the breach. Under the Defense Evasion tactic, the analysis identified Indicator Removal (T1070) with moderate confidence (60%), supported by evidence indicating breach was not discovered until September 2025 and Hide Artifacts (T1564) with moderate confidence (50%), supported by evidence indicating company has not identified the responsible party. These correlations help security teams understand the attack chain and develop appropriate defensive measures based on the observed tactics and techniques.
Sources & References
- Cornerstone First Mortgage, LLC Rankiteo Cyber Incident Details: https://www.rankiteo.com/company/cornerstone-first-mortgage/incident/COR1772749753
- Cornerstone First Mortgage, LLC CyberSecurity Rating page: https://www.rankiteo.com/company/cornerstone-first-mortgage
- Cornerstone First Mortgage, LLC Rankiteo Cyber Incident Blog Article: https://blog.rankiteo.com/cor1772749753-cornerstone-first-mortgage-inc-cornerstone-first-mortgage-breach-july-2023/
- Cornerstone First Mortgage, LLC CyberSecurity Score History: https://www.rankiteo.com/company/cornerstone-first-mortgage/history
- Cornerstone First Mortgage, LLC CyberSecurity Incident Source: https://www.claimdepot.com/data-breach/cornerstone-first-mortgage-2026
- Rankiteo A.I CyberSecurity Rating methodology: https://www.rankiteo.com/Images/rankiteo_algo.pdf
- Rankiteo TPRM Scoring methodology: https://static.rankiteo.com/model/rankiteo_tprm_methodology.pdf