Menu
Sign In
shutterstock_490960141-1

Industry News: ESG5

    Know Your Breach: First American

    Nov 8, 2019 10:09:34 AM

    The target: First American Financial Corp, a Fortune 500 real estate title insurance giant

    The take: 885 million files, including records of wire transactions with bank account numbers, bank statements, mortgage records, tax documents, Social Security numbers and driver’s licenses.

    The attack vector: FA’s webserver used a system of assigning sensitive documents unique web links – however, incrementing the id number in the link returned other, unrelated documents for any user accessing the site via web, with no authentication necessary.

    ‘Security by obscurity’ has no place in the 21st century – it is altogether insufficient to rely on the presumed inability of an attacker to locate sensitive resources left exposed to the public web. Any data which is not for public consumption must be protected with a secure authentication system to ensure that it can only be accessed by the intended audience.

    Read more...

    Topics:Know Your Breach

    About Castle Hall Diligence

    Castle Hall helps investors build comprehensive due diligence programs across hedge fund, private equity and long only portfolios More →

    Subscribe to Cyber Updates