Industry News: Cyber

Know Your Breach: First American

Written by Cybersecurity | Nov 8, 2019 3:09:34 PM

The target: First American Financial Corp, a Fortune 500 real estate title insurance giant

The take: 885 million files, including records of wire transactions with bank account numbers, bank statements, mortgage records, tax documents, Social Security numbers and driver’s licenses.

The attack vector: FA’s webserver used a system of assigning sensitive documents unique web links – however, incrementing the id number in the link returned other, unrelated documents for any user accessing the site via web, with no authentication necessary.

‘Security by obscurity’ has no place in the 21st century – it is altogether insufficient to rely on the presumed inability of an attacker to locate sensitive resources left exposed to the public web. Any data which is not for public consumption must be protected with a secure authentication system to ensure that it can only be accessed by the intended audience.

Read more...