Skip to main content

Millions of real estate records were publicly accessible due to lax security

Stock photo of lock and data
Darwin Laganzon/Pixabay

A major financial services company, First American Corporation, has left millions of records publicly accessible on its servers. The data included bank account details, bank statements, mortgage records, driver’s license images, and Social Security numbers, and was available to access without authorization by anyone who connected to an area of the company’s website.

The company provides title insurance and settlement services, and is a major player in the real estate and mortgage industries. The publicly accessible data was discovered by a real estate developer who reported it to the company but got no response. He then shared the finding with an online security blog.

Recommended Videos

“Closing agencies are supposed to be the only neutral party that doesn’t represent someone else’s interest, and you’re required to have title insurance if you have any kind of mortgage,” Ben Shoval, the developer who discovered the leak, said to KrebsOnSecurity. “The title insurance agency collects all kinds of documents from both the buyer and seller, including Social Security numbers, drivers licenses, account statements, and even internal corporate documents if you’re a small business. You give them all kinds of private information and you expect that to stay private.”

As many as 885 million files were accessible, dating back to 2003. It is not known at this time how long the documents were exposed for, but they were available from at least March 2017. First American Corporation has not confirmed how many people’s data was vulnerable or whether cyber criminals could have been aware of the data before this week.

The company learned about the accessibility of the documents on Friday and reported that it immediately blocked external access to them and began an investigation into any resulting security issues.

“First American has learned of a design defect in an application that made possible unauthorized access to customer data,” a First American spokesperson said in a statement shared with KrebsOnSecurity. “At First American, security, privacy and confidentiality are of the highest priority and we are committed to protecting our customers’ information. The company took immediate action to address the situation and shut down external access to the application. We are currently evaluating what effect, if any, this had on the security of customer information. We will have no further comment until our internal review is completed.”

Georgina Torbet
Georgina has been the space writer at Digital Trends space writer for six years, covering human space exploration, planetary…
The uncertain future cost of Apple’s Emergency SOS feature
Person holding iPhone 14 searching for Emergency SOS satellite.

It's been roughly two years since the launch of the iPhone 14 and its Emergency SOS via satellite feature. You might recall that during the first two years, Apple said it would be free to use but that it might require a subscription after that time, according to MacRumors. Last year, Apple extended the time limit by one more year, so you actually have until November 2025, when the trial period ends.

That's good news. The Emergency SOS feature is, quite literally, lifesaving. During April of this year, three university students lost their way in a canyon and used the feature to call for help. Another story arose in July where the feature came through once more in a moment of crisis. And if you keep digging, you'll find numerous other examples of how this tech is truly beneficial.

Read more
Apple’s smart home display already sounds like a convenience victory
Nest Hub Max

Over the past few weeks, rumors of Apple developing a smart display for home control have picked up pace. The company is said to be developing two versions, and one of them might even feature a robotic arm and revive an iconic Mac’s design. 

Now, Bloomberg has shared some juicy details about how the entry-level option will look and work. The device will offer a 6-inch screen with a square-ish format flanked by sensors, including a FaceTime camera in landscape orientation. 

Read more
Trade group says EV tax incentive helps U.S. industry compete versus China
ev group support tax incentive 201 seer credit eligibility

The Zero Emission Transportation Association (ZETA), a trade group with members including the likes of Tesla, Waymo, Rivian, and Uber, is coming out in support of tax incentives for both the production and sale of electric vehicles (EVs).

Domestic manufacturers of EVs and their components, such as batteries, have received tax incentives that have driven job opportunities in states like Ohio, Kentucky, Michigan, and Georgia, the group says.

Read more