FEDERALItem 1.05 · mandatoryHackingFinancial ServicesFinanceTitle InsuranceData ExfiltratedData EncryptedLowContained
FIRST AMERICAN FINANCIAL CORPORATION
bd_2357f90f46aa5f5e · schema v1 · pii pii-v1
Full breach record for FIRST AMERICAN FINANCIAL CORPORATION →First American Financial Corporation filed an 8-K/A amending its December 22, 2023 disclosure of a cybersecurity incident. The company detected unauthorized activity on its IT systems, elected on December 20, 2023 to isolate systems from the Internet, retained experts, worked with law enforcement, and notified regulators. The company believes the perpetrator accessed certain systems, exfiltrated data, and encrypted data on certain non-production systems. The incident is believed contained; investigation is ongoing.
SEC clockMateriality determined Dec 22, 2023 → Filed Dec 29, 20237d ✗ SEC 4-day late
⚠ no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/1472787/000095017023073848/faf-20231220.htm
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Dec 29, 2023
- Raw hash
- 18c5fd3cabcd4f01fe249c8b2c8ff5fd9b2964b85277fd1ca117a6af459e578b
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- FIRST AMERICAN FINANCIAL CORPORATIONnorm: first american financial
- SEC CIK
- 0001472787
- Domain
- firstam.com
- Industry
- Title insurance and settlement services
Victim entity
- Name
- FIRST AMERICAN FINANCIAL CORPORATIONnorm: first american financial
- SEC CIK
- 0001472787
- Domain
- firstam.com
- Industry
- Title insurance and settlement services
- Industry
- Financial ServicesllmNAICS 524127 · Direct Title Insurance Carriers
Incident
- Discovered
- —
- Materiality determined
- Dec 22, 2023
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- —
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1041 Exfiltration Over C2 ChannelT1486 Data Encrypted for Impact
- Threat actor
- External
- Regulator citations
- Notified certain regulatory authorities
Compliance
- Compliance flags
- SEC 4-day late · 7d
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status SEC Materiality determined: Dec 22, 2023→ Filed: Dec 29, 20237d cal. 4 business days SEC 4-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.