ResourcesTexas Breach Tracker › Westlake Financial Partners (TX Operations)
Other Exfil Actor: MOVEit/Clop Remediated

Westlake Financial Partners (TX Operations)
Breach Analysis

Westlake Financial was among hundreds of organizations globally compromised via the MOVEit Transfer supply-chain attack attributed to the Clop ransomware group. Texas operations data for 178,000 customers was affected.

Incident Date
2024-06-03
Records Exposed
178,000
Attack Type
Exfil
Threat Actor
MOVEit/Clop

How they got in

Supply-chain attack via MOVEit Transfer zero-day (CVE-2023-34362). Clop ransomware group exploited the SQL injection vulnerability in MOVEit's web-facing interface to exfiltrate data before the patch was widely applied. No encryption deployed — pure data theft.

Sentinel / Fortress / Command coverage

Fortress Emergency patch deployment: Fortress SLA requires perimeter-facing app patches within 72 hours of CVSS ≥8 advisory — MOVEit patch available before mass exploitation
Sentinel Web application firewall rules updated within hours of CISA advisory to block CVE-2023-34362 exploit pattern
Command Third-party software inventory: MOVEit usage flagged in vendor risk register; emergency patching triggered on discovery of vulnerability

Sentinel ($89/ep/mo) — 24/7 SOC + SIEM. Fortress ($109/ep/mo) — Sentinel + EDR management + vulnerability management. Command ($129/ep/mo) — Fortress + vCISO + compliance mapping + IR plan. See full tier comparison →

Regulatory exposure

Regime Standard / Citation Gap Identified
GLBA Safeguards Rule §314.4(f) Third-party service provider oversight — vendor patch timeline not contractually enforced
TDPA Tex. B&C Code §521.053 TX customer notification required; delayed notification triggered regulatory scrutiny

5-point hardening list

CoreRecon cites verifiable public sources only. No speculation on unverified attribution is published. Threat actor attribution appears only where publicly confirmed by law enforcement or the organization.

Is your organization hardened against this attack vector?

Free $2,500 security posture assessment for Texas organizations. We map your gaps against the same attack vectors used in this incident. No contract, no commitment.