First American security flaw leaked 885 million real estate documents

First American security flaw leaked 885 million real estate documents 1

Due to the nature of its business, those files include a variety of sensitive information, including bank account numbers and statements, mortgage and tax records, Social Security numbers, wire transaction receipts and drivers license images. Ben Shoval, the real estate developer who discovered the vulnerability and who told Krebs about the issue, also said that small business clients might’ve even given First American access to internal documents.

After Shoval contacted Krebs about the issue earlier this week, the security researcher confirmed that the company’s website was returning documents simply by changing digits in the URL. First American ultimately switched off the part of its website that served those files by around 2PM on May 24th. Krebs clarified however, that he has no information suggesting the exposed files were harvested. It’s also unclear when the vulnerability first showed up, though Krebs discovered that it’s been around since at least March 2017 after taking a dive into archive.org.

Best scenario is that no bad actor paid attention to the company’s website, because those documents could be mined for sensitive data to sell in the dark web and could be used for convincing phishing schemes. A spokesperson told the researcher that the real estate giant is currently determining if the flaw affected its customer information in any way (emphasis ours):

“First American has learned of a design defect in an application that made possible unauthorized access to customer data. At First American, security, privacy and confidentiality are of the highest priority and we are committed to protecting our customers’ information. The company took immediate action to address the situation and shut down external access to the application. We are currently evaluating what effect, if any, this had on the security of customer information. We will have no further comment until our internal review is completed.

About the author

E-Crypto News was developed to assist all cryptocurrency investors in developing profitable cryptocurrency portfolios through the provision of timely and much-needed information. Investments in cryptocurrency require a level of detail, sensitivity, and accuracy that isn’t required in any other market and as such, we’ve developed our databases to help fill in information gaps.

Related Posts

E-Crypto News Executive Interviews

Automated trading with HaasBot Crypto Trading Bots

Blockchain/Cryptocurrency Questions and Answers

What Are E-stablecoins And How Do They Operate?
What Are E-Stablecoins And How Do They Operate?
August 11, 2022
How to Choose a Legit Crypto Casino?
August 5, 2022
Spend Crypto
5 Ways to Spend Crypto
August 2, 2022
What Is A DAO LLC?
What Is A DAO LLC?
August 2, 2022
Can Running A Lightning Node Earn You Passive Income?
Can Running A Lightning Node Earn You Passive Income?
July 5, 2022


CryptoCurrencyUSDChange 1hChange 24hChange 7d
? --- 0.00 % 0.00 %

bitcoin
Bitcoin (BTC) $ 21,405.00
ethereum
Ethereum (ETH) $ 1,707.09
tether
Tether (USDT) $ 1.00
usd-coin
USD Coin (USDC) $ 1.00
bnb
BNB (BNB) $ 287.48
binance-usd
Binance USD (BUSD) $ 1.00
xrp
XRP (XRP) $ 0.343631
cardano
Cardano (ADA) $ 0.467806
solana
Solana (SOL) $ 37.30
dogecoin
Dogecoin (DOGE) $ 0.070027