MeridianLink confirmed a cyberattack after ALPHV reported it to the SEC

Organization
MeridianLink
Exploit
Ransomware
Industry
Financial Software

MeridianLink, a California company that supplies lending and account opening software to banks, credit unions and mortgage lenders, confirmed in mid November 2023 that it had been hit by a cyberattack. The company said it identified the intrusion on November 10 and acted immediately to contain it.

The ALPHV/BlackCat ransomware group added MeridianLink to its dark web leak site and threatened to publish stolen files. It then took an unusual escalation step, posting a screenshot of a complaint it said it had filed with the U.S. Securities and Exchange Commission, alleging that MeridianLink had failed to file a Form 8-K disclosing a material breach.

The complaint carried no weight at the time. The SEC's cyber incident disclosure rule had been adopted earlier in 2023, but the Form 8-K reporting requirement did not become binding on most registrants until mid December, and it applies only to incidents a company judges material. The Record reported the rules were not yet in effect, while ThreatDown noted the rule had technically taken effect in September with a later compliance date.

MeridianLink said it had engaged third-party experts, found no evidence of unauthorized access to its production platforms and had seen no indication that consumer personal information was involved. It described the business interruption as minimal. No ransom figure was made public.

Sources