Comparison Overview

loanDepot Wholesale/Correspondent

VS

Shriram Finance Limited

loanDepot Wholesale/Correspondent

2600 Michelson Drive, Irvine, CA, 92612, US
Last Update: 2025-02-22 (UTC)
Between 800 and 900

Strong

loanDepot Wholesale is a third-party origination channel of loanDepot, America's lender. Serving mortgage brokers in 48 states and the District of Columbia, the division delivers an integrated and seamless technology-based lending experience for business partners and customers that is transparent and fast. loanDepot Wholesale offers a competitively priced suite of Conventional, FHA, VA, Jumbo and Renovation loan products. loanDepot LLC, NMLS #174457. Learn more at LDWholesale.com.

NAICS: 52
NAICS Definition: Finance and Insurance
Employees: 59
Subsidiaries: 1
12-month incidents
0
Known data breaches
2
Attack type number
2

Shriram Finance Limited

Wockhardt Towers, Level-3, West Wing, Bandra (East), Mumbai, 400051, IN
Last Update: 2025-03-05 (UTC)

Excellent

Between 900 and 1000

Shriram Finance is the countryโ€™s biggest retail NBFC offering credit solutions for commercial vehicles, two-wheeler loans, car loans, home loans, gold loans, personal and small business loans. We are part of the 50-year-old Shriram Group, a financial conglomerate that has emerged as a trusted partner in creating transformative experiences and lasting impressions in customersโ€™ lives. In November 2022, Shriram Groupโ€™s entities โ€“ Shriram Transport Finance Company Limited, Shriram City Union Finance Limited , and Shriram Capital Limited โ€“ merged to form Shriram Finance Limited . As on September 30, 2024, with a network of 3,149 branches and a workforce of more than 77,764, Shriram Finance has combined Assets Under Management (AUM) worth โ‚น243,042 crores.

NAICS: 52
NAICS Definition:
Employees: 30,254
Subsidiaries: 0
12-month incidents
0
Known data breaches
0
Attack type number
0

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/ldwholesale.jpeg
loanDepot Wholesale/Correspondent
โ€”
ISO 27001
Not verified
โ€”
SOC 2
Not verified
โ€”
GDPR
No public badge
โ€”
PCI DSS
No public badge
https://images.rankiteo.com/companyimages/stfcconnect.jpeg
Shriram Finance Limited
โ€”
ISO 27001
Not verified
โ€”
SOC 2
Not verified
โ€”
GDPR
No public badge
โ€”
PCI DSS
No public badge
Compliance Summary
loanDepot Wholesale/Correspondent
100%
Compliance Rate
0/4 Standards Verified
Shriram Finance Limited
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs Financial Services Industry Average (This Year)

No incidents recorded for loanDepot Wholesale/Correspondent in 2025.

Incidents vs Financial Services Industry Average (This Year)

No incidents recorded for Shriram Finance Limited in 2025.

Incident History โ€” loanDepot Wholesale/Correspondent (X = Date, Y = Severity)

loanDepot Wholesale/Correspondent cyber incidents detection timeline including parent company and subsidiaries

Incident History โ€” Shriram Finance Limited (X = Date, Y = Severity)

Shriram Finance Limited cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/ldwholesale.jpeg
loanDepot Wholesale/Correspondent
Incidents

Date Detected: 1/2024
Type:Breach
Blog: Blog

Date Detected: 01/2024
Type:Cyber Attack
Blog: Blog

Date Detected: 8/2022
Type:Breach
Attack Vector: Unauthorized Access
Blog: Blog
https://images.rankiteo.com/companyimages/stfcconnect.jpeg
Shriram Finance Limited
Incidents

No Incident

FAQ

Shriram Finance Limited company company demonstrates a stronger AI risk posture compared to loanDepot Wholesale/Correspondent company company, reflecting its advanced AI governance and monitoring frameworks.

loanDepot Wholesale/Correspondent company has historically faced a number of disclosed cyber incidents, whereas Shriram Finance Limited company has not reported any.

In the current year, Shriram Finance Limited company and loanDepot Wholesale/Correspondent company have not reported any cyber incidents.

Neither Shriram Finance Limited company nor loanDepot Wholesale/Correspondent company has reported experiencing a ransomware attack publicly.

loanDepot Wholesale/Correspondent company has disclosed at least one data breach, while the other Shriram Finance Limited company has not reported such incidents publicly.

loanDepot Wholesale/Correspondent company has reported targeted cyberattacks, while Shriram Finance Limited company has not reported such incidents publicly.

Neither loanDepot Wholesale/Correspondent company nor Shriram Finance Limited company has reported experiencing or disclosing vulnerabilities publicly.

loanDepot Wholesale/Correspondent company has more subsidiaries worldwide compared to Shriram Finance Limited company.

Shriram Finance Limited company employs more people globally than loanDepot Wholesale/Correspondent company, reflecting its scale as a Financial Services.

Latest Global CVEs (Not Company-Specific)

Description

Mbed TLS before 3.6.5 allows a local timing attack against certain RSA operations, and direct calls to mbedtls_mpi_mod_inv or mbedtls_mpi_gcd.

Description

Lack of application manifest sanitation could lead to potential stored XSS.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

Risk Information
cvss4
Base: 10.0
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 8.2.5 via the wp_ajax_import_elementor_template action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

Risk Information
cvss3
Base: 5.0
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Description

GeoVision embedded IP devices, confirmed onย GV-BX1500 andย GV-MFD1501, contain a remote command injection vulnerability viaย /PictureCatch.cgi that enables an attacker to execute arbitrary commands on the device. VulnCheck has observed this vulnerability being exploited in the wild as of 2025-10-19 08:55:13.141502 UTC.

Risk Information
cvss4
Base: 9.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in The Wikimedia Foundation MediaWiki WatchAnalytics extension allows SQL Injection.This issue affects MediaWiki WatchAnalytics extension: 1.43, 1.44.

Risk Information
cvss4
Base: 7.5
Severity: HIGH
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:C/RE:M/U:Amber