First American Financial Restores Systems After Cyberattack, Believes Threat Contained – NMP Skip to main content

First American Financial Restores Systems After Cyberattack, Believes Threat Contained

Jan 02, 2024
cybesecurity
News Director

Title insurance giant First American Financial reports progress in recovery efforts following a cyberattack and customer frustrations rise due to service disruptions.

Title insurance giant First American Financial told the Securities and Exchange Commission that it has restored some key systems impacted by a pre-Christmas cyberattack and believes it has "contained the threat" more than a week after shutting down systems to combat the incident. 

While the incident is still under investigation, the company believes the perpetrator accessed specific systems, exfiltrated data, and encrypted data on non-production systems. 

"As of the date of this filing, the company believes it has contained the incident. The company is in the process of restoring access to its systems and resuming normal business operations. Though the incident is still under investigation, the Company believes the perpetrator of the activity accessed certain company systems, exfiltrated data and encrypted data on certain non-production systems. The company continues to assess whether the incident will have a material impact on the Company’s financial condition or results of operations, which at this point cannot be determined.”

The company announced last week that FirstAm.com has been restored and that its bank, First American Trust, “continues to accept incoming wires, and all funds at First American Trust and our third-party partner banks remain secure.”

First American's ACI appraisal system, Charles Jones public records search, and the FraudGuard loan quality assurance platform are back online. 

Customers expressed frustration over the firm's response to the incident, with some citing difficulties in initiating wire transfers, leading to missed closing dates. This isn't the first time First American has faced a cybersecurity attack.

On Nov. 28, 2023, the New York Department of Financial Services announced that First American Title Insurance Company would pay a $1 million penalty for violations of the NYDFS Cybersecurity Regulation in connection with a May 2019 data breach. The NYDFS investigated the company’s response to the data breach and alleged that First American knew of a vulnerability in its technical systems that exposed consumers’ non-public information, but failed to investigate or report the vulnerability until several months later.

The cyberattack of First American follows recent breaches at Fidelity National Financial and Mr. Cooper Group.

About the author
Christine Stuart is the news director at NMP.
Published
Jan 02, 2024
Regulators Propose Risk-Based Vendor Oversight For Community Lenders

Plan could ease reviews of lower-risk mortgage technology while preserving lender responsibility for vendor failures

FHA Sets Jan. 1 Start For FICO 10T And VantageScore 4.0

Lenders will gain competing modern scoring options, but borrowers may not see both offered everywhere

Sep 11, 2026
FHFA Studies Credit-Report Changes To Cut Mortgage Costs

Pulte’s comments could signal either fewer bureau reports or a portable report borrowers could share among lenders, but FHFA has not clarified which approach it is studying

AI Errors Leave Mortgage Trustee Without Brief In Foreclosure Appeal

Outside counsel’s fabricated citations expose a third-party oversight risk for mortgage servicers, trustees, and investors

Sep 10, 2026
CHLA Wants Ginnie Mae Liquidity Backstop Ready Before Next Crisis

Proposed G-TALF facility could help prevent a servicing cash crunch from constraining FHA, VA, and USDA lending

FHFA Opens VantageScore To All GSE Lenders, Eyes Credit Report Overhaul

Pulte removes 50-lender cap while considering bi-merge and single-bureau reports as additional ways to reduce mortgage costs