On May 24, 2019, KrebsOnSecurity reported that First American Financial Corp.’s EaglePro document site was serving about 885 million records to anyone who had one valid link and changed the number at the end of it. The documents dated to 2003 and included bank account numbers and statements, mortgage and tax records, Social Security numbers, wire transaction receipts and driver’s license images. First American took the site down by 2 p.m. that afternoon and filed a Form 8-K four days later.
The flaw had been present since May 2014, according to the New York Department of Financial Services. Archived copies show the documents publicly reachable from at least March 2017. No attacker was ever identified, and whether anyone had systematically scraped the site was never established.
Known Internally, Misclassified, Unfixed
A penetration test in December 2018 found the vulnerability. It was classified as medium severity, then mistakenly as low, and was not remediated. The Securities and Exchange Commission later found that senior executives were never told their own staff had known about the flaw for months before the company issued statements about it. That finding, rather than the exposure itself, was the basis of the SEC’s action.
A Title Insurer’s Data Is Everyone’s Data
A title company sits at the closing of a property transaction and collects the whole file: identity documents, bank details, the wire that pays for the house. The people in those documents were not First American’s customers in any ordinary sense. They were buyers, sellers and lenders in transactions where the company was one intermediary among several. The corpus filed a later attack on the same company’s rival at 23-1119; here the mechanism required no attack at all.
The First Part 500 Case
On July 22, 2020, New York’s financial regulator announced charges under 23 NYCRR Part 500, the state’s cybersecurity regulation for licensed financial firms. It was the first enforcement action under the rule since it took effect in 2017. The department alleged failures in risk assessment, access controls, data governance and training, with a potential penalty of up to $1,000 per violation, each exposed document counting as one. The case settled on Nov. 27, 2023, for $1 million and a remediation program.
The SEC settled separately on June 14, 2021, for $487,616, on the disclosure-controls charge. A securities class action was dismissed. What the file records is that the largest document exposure in the sector’s history produced a combined regulatory penalty under $1.5 million and no finding of who, if anyone, took the data.
Compiled from the original KrebsOnSecurity report, the SEC order and press release, the NYDFS consent order and law-firm summaries of the 2020 charges, listed below. Document counts vary by source (885 million per Krebs, more than 850 million per NYDFS, more than 800 million per SEC) and are attributed accordingly. Graded high. Corrections: corrections@forensicpost.com.
- First American Financial Corp. Leaked Hundreds of Millions of Title Insurance RecordsKrebsOnSecurity
- SEC Charges Issuer With Cybersecurity Disclosure Controls FailuresU.S. Securities and Exchange Commission
- DFS Announces $1 Million Settlement With First American Title Insurance CompanyNew York Department of Financial Services
- Historic Charges: First Enforcement Action Filed by NYDFSSidley Austin