{"id":15402,"date":"2019-05-25T10:45:05","date_gmt":"2019-05-25T18:45:05","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2019\/05\/25\/news-9151\/"},"modified":"2019-05-25T10:45:05","modified_gmt":"2019-05-25T18:45:05","slug":"news-9151","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2019\/05\/25\/news-9151\/","title":{"rendered":"885 Million First American Financial Records Exposed Online"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/5ce866c8887f515526ddc50e\/master\/pass\/Houses-529307522.jpg\"\/><\/p>\n<p><strong>Credit to Author: Lily Hay Newman| Date: Fri, 24 May 2019 22:49:31 +0000<\/strong><\/p>\n<p><span class=\"lede\">After a solid <\/span>decade of <a href=\"https:\/\/www.wired.com\/story\/worst-hacks-2018-facebook-marriott-quora\/\">nonstop corporate data breaches<\/a> and <a href=\"https:\/\/www.wired.com\/story\/collection-one-breach-email-accounts-passwords\/\">exposures<\/a>, you&#x27;d think large organizations would have at least <a href=\"https:\/\/www.wired.com\/story\/how-to-stop-breaches-equifax\/\">fixed the most basic<\/a> and obviously damaging types of data mishandling. But there&#x27;s clearly still a long way to go. On Friday, <a href=\"https:\/\/krebsonsecurity.com\/2019\/05\/first-american-financial-corp-leaked-hundreds-of-millions-of-title-insurance-records\/\" target=\"_blank\">independent security journalist Brian Krebs revealed<\/a> that the real estate and title insurance giant First American had 885 million sensitive customer financial records, going back to 2003, exposed on its website for anyone to access. And while there isn&#x27;t currently evidence that anyone actually found and stole the information, it was so easy to grab\u2014and so obviously <a href=\"https:\/\/www.wired.com\/story\/facebook-hack-data-spammers\/\">valuable to scammers<\/a>\u2014that it&#x27;s hard to rule out that possibility.<\/p>\n<p class=\"paywall\"><a href=\"https:\/\/krebsonsecurity.com\/2019\/05\/first-american-financial-corp-leaked-hundreds-of-millions-of-title-insurance-records\/\" target=\"_blank\">Krebs reports<\/a> that the exposed records included <a href=\"https:\/\/www.wired.com\/story\/social-security-number-replacement\/\">Social Security numbers<\/a>, driver&#x27;s license images, bank account numbers and statements, mortgage and tax documents, and wire transaction receipts\u2014an absolute treasure trove for any scammer or identity thief. An attacker who figured out the format of the company&#x27;s document URLs could have input any &quot;record number&quot; they wanted\u2014beginning with &quot;000000075,&quot; according to Krebs\u2014and pull up the documents associated with that customer case. First American took down the site that populated the records at 2 pm ET on Friday. Krebs notified the company of the situation earlier this week.<\/p>\n<p class=\"paywall\">\u201cFirst American has learned of a design defect in an application that made possible unauthorized access to customer data,&quot; the company said in a statement. &quot;The company took immediate action to address the situation and shut down external access to the application. We are currently evaluating what effect, if any, this had on the security of customer information. We will have no further comment until our internal review is completed.\u201d<\/p>\n<p class=\"paywall\">First American did not answer questions from WIRED about how long the records were exposed online. The company says it has hired a forensic firm to assess whether customer data was ever stolen. First American, which is based in Santa Ana, California, is a Fortune 500 company with more than 18,000 employees.<\/p>\n<p class=\"paywall\">Well, lots of people! First American is the top title insurance firm in the United States, which means the company is often party to both the buyer and lender sides of real estate transactions across the country. And the detailed financial and personal information involved in closings potentially involves information about both buyers and sellers.<\/p>\n<p class=\"paywall\">While the hope is that the data was never actually stolen, millions of people may have been impacted if it was. If you&#x27;ve bought or sold a house in the past several years, there&#x27;s a decent chance First American had a hand in it.<\/p>\n<p class=\"paywall\">The First American exposure is a major incident, because it underscores just how little progress many institutions have made on locking down customer data. Perfect security is impossible, but the stakes are incredibly high and many large organizations still overlook basic errors.<\/p>\n<p class=\"paywall\">The good news is that exposed data does not necessarily mean stolen data. There&#x27;s a chance that no one stumbled across this trove before the company had the chance to secure it. But unlike other data leaks of <a href=\"https:\/\/www.wired.com\/story\/collection-one-breach-email-accounts-passwords\/\">similar scale<\/a>, which largely involve password and username combinations, the data in the First American haul would have devastating long-term consequences for potential victims.<\/p>\n<p class=\"paywall\">If you\u2019re a First American customer or think you were party to a transaction that also involved the company there isn\u2019t a lot you can do to <a href=\"https:\/\/www.wired.com\/story\/how-to-protect-yourself-after-the-next-big-corporate-hack\/\">protect yourself against the possibility<\/a> that your data was stolen as a result of this exposure. But watch your bank and credit card statements for suspicious activity. Consider purchasing credit monitoring or, better yet, avail yourself of a free credit monitoring offer from another security incident your data was involved in. By this point, you&#x27;ve almost certainly qualified for it. You can also consider a <a href=\"https:\/\/www.consumer.ftc.gov\/articles\/0497-credit-freeze-faqs\" target=\"_blank\">credit freeze<\/a>.<\/p>\n<p class=\"paywall\">Security practitioners always hope that major security incidents, like the notorious Equifax breach, will be a wake up call to all companies. But the consequences for such missteps are only first starting to appear. On Wednesday, for example, Moody\u2019s <a href=\"https:\/\/www.cnbc.com\/2019\/05\/22\/moodys-downgrades-equifax-outlook-to-negative-cites-cybersecurity.html\" target=\"_blank\">downgraded<\/a> its ratings outlook for Equifax. A spokesperson said, \u201cIt\u2019s the first time that cyber has been a named factor in an outlook change.&quot; Until other dramatic economic motivators emerge, disasters like First American, or worse, will continue.<\/p>\n<p class=\"related-cne-video-component__dek\">It seems like every time you turn around there&#39;s a new breach of personal information. Follow these steps to minimize the damage.<\/p>\n<p><a href=\"https:\/\/www.wired.com\/story\/first-american-data-exposed\" target=\"bwo\" >https:\/\/www.wired.com\/category\/security\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/5ce866c8887f515526ddc50e\/master\/pass\/Houses-529307522.jpg\"\/><\/p>\n<p><strong>Credit to Author: Lily Hay Newman| Date: Fri, 24 May 2019 22:49:31 +0000<\/strong><\/p>\n<p>Real estate giant First American left Social Security numbers, tax documents, and more publicly available.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10607],"tags":[714,21358],"class_list":["post-15402","post","type-post","status-publish","format-standard","hentry","category-security","category-wired","tag-security","tag-security-cyberattacks-and-hacks"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/15402","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=15402"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/15402\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=15402"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=15402"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=15402"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}