Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

Cyberattack Disrupts Operations of First American, Subsidiaries

A cyberattack appears to have caused significant disruption to the systems and operations of title insurer First American and its subsidiaries.

The systems and operations of First American Financial Corporation and several of its subsidiaries appear to have been significantly disrupted by a cyberattack. 

First American provides title insurance and settlement services to the real estate and mortgage industries. It’s one of the largest title insurance companies in the United States. 

The company revealed on December 21 that it had taken certain systems offline as a result of a “cybersecurity incident”.

In an update shared the next day, the company said email systems had also been taken offline and warned customers to be on the lookout for potentially malicious emails purporting to come from First American, First American Title or FirstAm.com.

The company told the Securities and Exchange Commission (SEC) that it isolated some systems from the internet on December 20 in an effort to contain, remediate and assess the incident. 

“The Company is working diligently to restore those systems and resume normal operations as soon as possible, but cannot estimate the duration or extent of the disruption at this time,” First American said. “The Company has retained leading experts, is working with law enforcement and notified certain regulatory authorities. During the disruption, the Company’s primary website may be inaccessible or inoperative.”

Advertisement. Scroll to continue reading.

One week after the breach was discovered, First American’s main website remains offline, and so are the sites of a few subsidiaries. 

Several individuals have complained on social media about financial losses indirectly resulting from the downtime, as well as the company’s handling of the incident and communication with customers.

While no information has been shared on the attack itself, the incident has the hallmarks of a ransomware attack. However, no known ransomware group appears to have taken credit for it.

Related: Australian Finance Company Refuses Hackers’ Ransom Demand 

Related: 4.8 Million Impacted by Data Breach at TMX Finance

Related: Major Massachusetts Health Insurer Hit by Ransomware Attack, Member Data May Be Compromised

Related: Ransomware Attack Hits Health Insurer Point32Health

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required.

Register

People on the Move

Geoff Belknap has joined HubSpot as Chief Trust Officer.

Zero Networks has named Yossi Dagan as Chief Financial Officer.

Manifold has appointed Joe Sullivan to its Board of Directors.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.