Data Breaches

Cyberattack Disrupts Operations of First American, Subsidiaries

A cyberattack appears to have caused significant disruption to the systems and operations of title insurer First American and its subsidiaries.

A cyberattack appears to have caused significant disruption to the systems and operations of title insurer First American and its subsidiaries.

The systems and operations of First American Financial Corporation and several of its subsidiaries appear to have been significantly disrupted by a cyberattack. 

First American provides title insurance and settlement services to the real estate and mortgage industries. It’s one of the largest title insurance companies in the United States. 

The company revealed on December 21 that it had taken certain systems offline as a result of a “cybersecurity incident”.

In an update shared the next day, the company said email systems had also been taken offline and warned customers to be on the lookout for potentially malicious emails purporting to come from First American, First American Title or FirstAm.com.

The company told the Securities and Exchange Commission (SEC) that it isolated some systems from the internet on December 20 in an effort to contain, remediate and assess the incident. 

“The Company is working diligently to restore those systems and resume normal operations as soon as possible, but cannot estimate the duration or extent of the disruption at this time,” First American said. “The Company has retained leading experts, is working with law enforcement and notified certain regulatory authorities. During the disruption, the Company’s primary website may be inaccessible or inoperative.”

Advertisement. Scroll to continue reading.

One week after the breach was discovered, First American’s main website remains offline, and so are the sites of a few subsidiaries. 

Several individuals have complained on social media about financial losses indirectly resulting from the downtime, as well as the company’s handling of the incident and communication with customers.

While no information has been shared on the attack itself, the incident has the hallmarks of a ransomware attack. However, no known ransomware group appears to have taken credit for it.

Related: Australian Finance Company Refuses Hackers’ Ransom Demand 

Related: 4.8 Million Impacted by Data Breach at TMX Finance

Related: Major Massachusetts Health Insurer Hit by Ransomware Attack, Member Data May Be Compromised

Related: Ransomware Attack Hits Health Insurer Point32Health

Related Content

Data Breaches

A hacker claims to have stolen 7.5 million customer records after breaching the company’s systems.

Data Breaches

Hackers exploited a vulnerability in a VPN product to steal the personal information of roughly 240,000 people.

Data Breaches

The company unintentionally disclosed users’ information to a third party impersonating a government agency.

Data Breaches

Stolen credentials were used in a multi-month campaign to access subscriber personal data and billing records.

Data Breaches

Hackers compromised the Brevo marketing platform and used that access to send phishing emails to users of Trezor, BitBox, and CoinTracking.

Data Breaches

A misconfigured test server containing engineering material, including internal configurations, was accessed by threat actors.

Data Breaches

In June 2026, hackers stole personal, health, and insurance information from AdaptHealth’s systems.

Data Breaches

Hackers stole the information of students, teachers, staff, and parents/guardians from a self-hosted Metabase instance.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version