May 24, 2019

First American mortgage data exposure leaked 885 million files

A web design flaw in First American Financial Corporation's document transfer system left around 885 million files exposed on the web with no security, reports independent reporter Brian Krebs.

Why it matters: Krebs notes that the documents, which date back to 2003, include "bank account numbers and statements, mortgage and tax records, Social Security numbers, wire transaction receipts, and drivers license images."

Details: The flaw, which has been repaired, appears to have been in an online system the firm used to link to files in private communications. Users would be sent to a website whose web address included a file number.

  • However, the files themselves were not individually protected. By changing the file number, you could access any one of the documents.
  • Krebs was alerted to the data exposure by developer Ben Shoval.

Threat level: There's no public evidence at this point that anyone maliciously accessed the files, though First American is investigating with the help of an outside forensics firm.

What they're saying:

  • In a statement, First American wrote "Security, privacy and confidentiality are of the highest priority and we are committed to protecting our customers’ information. Therefore, the company took immediate action to address the situation and shut down external access to the application."
Go deeper