SMC A.I CyberSecurity Scoring
SMC
Company Information
Website:http://www.snmc.com
Employees number:828
Number of followers:5,445
NAICS:52
Industry Type:Financial Services
Homepage:snmc.com
SMC Risk Score (AI oriented)
Between 600 and 649
SMCFinancial Services
Updated:
24/08/2026
24/08/2026
645/1000
Poor
Caa
SMC Global Score (TPRM)
xxxx
SMCFinancial Services
Score locked

SMCPoor
Current Score
645Caa (POOR)
01000
1 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
645
JULY 2026
643
JUNE 2026
641
MAY 2026
639
APRIL 2026
636
MARCH 2026
634
FEBRUARY 2026
631
JANUARY 2026
629
DECEMBER 2025
627
NOVEMBER 2025
624
OCTOBER 2025
621
SEPTEMBER 2025
619
MARCH 2023
758
Ransomware
01 Mar 2023 • SMC
Utah-based mortgage company: California DFPI orders mortgage company to pay $825K for alleged cybersecurity failures preceding ransomware attack
California Regulator Fines Mortgage Company $825K Over 2023 Ransomware Breach
504
CRITICAL-254
SEC1787590381
California Regulator Fines Mortgage Company $825K Over 2023 Ransomware Breach
On August 13, the California Department of Financial Protection and Innovation (DFPI) issued a consent order against a Utah-based mortgage company, imposing an $825,000 penalty for failing to safeguard the personal data of over 284,000 individuals including more than 34,000 California residents. The breach, which occurred in March 2023, involved a threat actor infiltrating the company’s network, deploying malware, stealing employee credentials, and disabling security systems before launching a ransomware attack.
A DFPI examination revealed systemic cybersecurity and governance failures predating the incident. Key deficiencies included:
- Inadequate risk assessments from 2021 to 2023.
- No formal cybersecurity audits between 2017 and 2023.
- Weak vulnerability and patch management, poor access controls, and an incomplete asset inventory.
- Lack of documented remediation for issues identified in penetration testing.
- Insufficient board-level oversight and strategic planning.
The DFPI also determined the company failed to produce a written forensic report detailing the breach’s root cause or corrective actions. These lapses violated the Gramm-Leach-Bliley Act (GLBA) Safeguards Rule, California Civil Code § 1798.100(e), and the state’s Residential Mortgage Lending Act.
Under the consent order accepted without admission of wrongdoing the company must pay the fine, provide affected California borrowers with 12 months of free identity theft insurance, and immediately rectify its recordkeeping and cybersecurity practices.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for SMC ??
What was SMC's A.I Rankiteo Cyber Score in July 2026 ??
What was SMC's A.I Rankiteo Cyber Score in June 2026 ??
What was SMC's A.I Rankiteo Cyber Score in May 2026 ??
What was SMC's A.I Rankiteo Cyber Score in April 2026 ??
What was SMC's A.I Rankiteo Cyber Score in March 2026 ??
What was SMC's A.I Rankiteo Cyber Score in February 2026 ??
What was SMC's A.I Rankiteo Cyber Score in January 2026 ??
What was SMC's A.I Rankiteo Cyber Score in December 2025 ??
What was SMC's A.I Rankiteo Cyber Score in November 2025 ??
What was SMC's A.I Rankiteo Cyber Score in October 2025 ??
What was SMC's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on SMC's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with SMC ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view SMC's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?