First American Financial Title Insurance Cybersecurity Incident
Key Facts
- Legal Status: SETTLED in U.S. Securities and Exchange Commission EDGAR.
- Primary Target Sector: Financial Services & Real Estate.
- Documented Financial Loss: $60.0 million.
- 2 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Unauthorized intrusion into internal corporate network segments supporting core title production and escrow systems.
Operational & Financial Fallout
Forced nationwide shutdown of real estate closing and title insurance operations for over two weeks, leading to an SEC Form 8-K Item 1.05 filing and NYDFS consent order.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Unauthorized intrusion into internal corporate network segments supporting core title production and escrow systems.
Adversary Kill Chain Flow
5 Documented PhasesThreat actors breached internal network segments supporting title plant and escrow document repositories.
Upon detecting unauthorized activity, First American took core transactional systems offline to contain lateral traversal.
Shutdown of title plant systems halted mortgage loan closings, wire transfers, and property deed filings across the country.
First American filed Form 8-K Item 1.05 with the SEC, acknowledging a material cybersecurity incident that disrupted customer operations.
Core title processing and wire systems were systematically restored, followed by regulatory compliance consent agreements.
Forced nationwide shutdown of real estate closing and title insurance operations for over two weeks, leading to an SEC Form 8-K Item 1.05 filing and NYDFS consent order.
Procedural & Incident Timeline
First American identifies unauthorized activity and isolates critical transactional network systems.
First American files Form 8-K Item 1.05 with the SEC acknowledging material cybersecurity incident.
Core title processing, escrow systems, and customer portal services return to full operations.
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1489 | "In response to unauthorized network access, First American took certain of its systems offline to contain the activity, severing customer title plant access." | First American Form 8-K Disclosures | reviewed | |
| T1078 | Valid Accounts Defense Evasion | "Threat actors accessed network shares and document storage containing escrow instructions and personal financial records." | NYDFS Enforcement Consent Order | reviewed |