Connect with us

Hi, what are you looking for?


Data Breaches

Cyberattack Disrupts Operations of First American, Subsidiaries

A cyberattack appears to have caused significant disruption to the systems and operations of title insurer First American and its subsidiaries.

The systems and operations of First American Financial Corporation and several of its subsidiaries appear to have been significantly disrupted by a cyberattack. 

First American provides title insurance and settlement services to the real estate and mortgage industries. It’s one of the largest title insurance companies in the United States. 

The company revealed on December 21 that it had taken certain systems offline as a result of a “cybersecurity incident”.

In an update shared the next day, the company said email systems had also been taken offline and warned customers to be on the lookout for potentially malicious emails purporting to come from First American, First American Title or

The company told the Securities and Exchange Commission (SEC) that it isolated some systems from the internet on December 20 in an effort to contain, remediate and assess the incident. 

“The Company is working diligently to restore those systems and resume normal operations as soon as possible, but cannot estimate the duration or extent of the disruption at this time,” First American said. “The Company has retained leading experts, is working with law enforcement and notified certain regulatory authorities. During the disruption, the Company’s primary website may be inaccessible or inoperative.”

One week after the breach was discovered, First American’s main website remains offline, and so are the sites of a few subsidiaries. 

Several individuals have complained on social media about financial losses indirectly resulting from the downtime, as well as the company’s handling of the incident and communication with customers.

Advertisement. Scroll to continue reading.

While no information has been shared on the attack itself, the incident has the hallmarks of a ransomware attack. However, no known ransomware group appears to have taken credit for it.

Related: Australian Finance Company Refuses Hackers’ Ransom Demand 

Related: 4.8 Million Impacted by Data Breach at TMX Finance

Related: Major Massachusetts Health Insurer Hit by Ransomware Attack, Member Data May Be Compromised

Related: Ransomware Attack Hits Health Insurer Point32Health

Written By

Eduard Kovacs (@EduardKovacs) is a managing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.


Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Gain valuable insights from industry professionals who will help guide you through the intricacies of industrial cybersecurity.


Join us for an in depth exploration of the critical nature of software and vendor supply chain security issues with a focus on understanding how attacks against identity infrastructure come with major cascading effects.


Expert Insights

Related Content

Data Breaches

OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an...


Zendesk is informing customers about a data breach that started with an SMS phishing campaign targeting the company’s employees.

Data Breaches

LastPass DevOp engineer's home computer hacked and implanted with keylogging malware as part of a sustained cyberattack that exfiltrated corporate data from the cloud...

CISO Strategy

Okta is blaming the recent hack of its support system on an employee who logged into a personal Google account on a company-managed laptop.

Data Breaches

Sony shares information on the impact of two recent unrelated hacker attacks carried out by known ransomware groups. 

Data Breaches

A group of hackers has leaked Atlassian employee records and floorplans, information that was obtained from third-party workplace platform Envoy.

Data Breaches

Delta Dental of California says over 6.9 million individuals were impacted by a data breach caused by the MOVEit hack.

Data Breaches

KFC and Taco Bell parent company Yum Brands says personal information was compromised in a January 2023 ransomware attack.