Saturday, December 14, 2024
HomeComputer SecurityFirst American Leaked 885 Million Most Sensitive Financial Data Online

First American Leaked 885 Million Most Sensitive Financial Data Online

Published on

SIEM as a Service

First American Financial Corp, a U.S based financial services company leaked Hundreds of Million of Most sensitive records online that related to real estate and mortgage industries.

First American Fin corp is one of the oldest company the U.S and the company running its operation nearly 130 years with the core services of real property records and image, valuation products and services, home warranty products, property and casualty insurance, and banking, trust, and investment advisory services, etc.

Leaked data includes some of the highly sensitive data such as mortgage and tax records, Social Security numbers, wire transaction receipts, and drivers license images, bank account numbers and statements.

- Advertisement - SIEM as a Service

Most importantly, Due to the lacking of security measures, the data were available to access anyone through the browser without any authentication.

Ben Shoval, A Real Estate developer recently uncovered the portion of First American owned web firstam.com that leaked hundreds of millions of records.

He reported to kerbs that says, “anyone who knew the URL for a valid document at the Web site could view other documents just by modifying a single digit in the link.

After the Further investigation, Kerbs confirms that the First American’s Web site exposed approximately 885 million files, the earliest dating back more than 16 years.

Tons of Exposed files contain some of the sensitive financial records, including the data about the wire transactions with bank account numbers and other information from home or property buyers and sellers.

Ben said. “The title insurance agency collects all kinds of documents from both the buyer and seller, including Social Security numbers, drivers licenses, account statements, and even internal corporate documents if you’re a small business. You give them all kinds of private information and you expect that to stay private.”

First American released a statement that says, “First American has learned of a design defect in an application that made possible unauthorized access to customer data.  At First American, security, privacy, and confidentiality are of the highest priority and we are committed to protecting our customers’ information. The company took immediate action to address the situation and shut down external access to the application. We are currently evaluating what effect if any, this had on the security of customer information. We will have no further comment until our internal review is completed.”

It’s unclear how long the data were being in the online left open to access by anyone and any attacker stolen this First American’s financial information.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.

Also Read:

49 Million Instagram Influencers, Celebrities Personal Data Leaked Online

Box Data Leak – Terabytes of Data Exposed from Companies Using cloud based Box Accounts

SBI Data Leak – Millions of Customers Data Leaked From Unsecured Server

NASA Data Leak – Internal App Leaked NASA Staff and Project Sensitive data

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

“Password Era is Ending,” Microsoft to Delete 1 Billion Passwords

Microsoft has announced that it is currently blocking an astounding 7,000 password attacks every...

Over 300,000 Prometheus Servers Vulnerable to DoS Attacks Due to RepoJacking Exploit

The research identified vulnerabilities in Prometheus, including information disclosure from exposed servers, DoS risks...

Reyee OS IoT Devices Compromised: Over-The-Air Attack Bypasses Wi-Fi Logins

Researchers discovered multiple vulnerabilities in Ruijie Networks' cloud-connected devices. By exploiting these vulnerabilities, attackers...

New Android Banking Malware Attacking Indian Banks To Steal Login Credentials

Researchers have discovered a new Android banking trojan targeting Indian users, and this malware...

API Security Webinar

72 Hours to Audit-Ready API Security

APIs present a unique challenge in this landscape, as risk assessment and mitigation are often hindered by incomplete API inventories and insufficient documentation.

Join Vivek Gopalan, VP of Products at Indusface, in this insightful webinar as he unveils a practical framework for discovering, assessing, and addressing open API vulnerabilities within just 72 hours.

Discussion points

API Discovery: Techniques to identify and map your public APIs comprehensively.
Vulnerability Scanning: Best practices for API vulnerability analysis and penetration testing.
Clean Reporting: Steps to generate a clean, audit-ready vulnerability report within 72 hours.

More like this

“Password Era is Ending,” Microsoft to Delete 1 Billion Passwords

Microsoft has announced that it is currently blocking an astounding 7,000 password attacks every...

Over 300,000 Prometheus Servers Vulnerable to DoS Attacks Due to RepoJacking Exploit

The research identified vulnerabilities in Prometheus, including information disclosure from exposed servers, DoS risks...

Reyee OS IoT Devices Compromised: Over-The-Air Attack Bypasses Wi-Fi Logins

Researchers discovered multiple vulnerabilities in Ruijie Networks' cloud-connected devices. By exploiting these vulnerabilities, attackers...