MalwareRansomwareStolen CredentialsRansom DemandedData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICLowContained
FIRST AMERICAN FINANCIAL CORPORATION
bd_383f35344a3929d1 · schema v1 · pii pii-v1
Full breach record for FIRST AMERICAN FINANCIAL CORPORATION →First American Financial Corporation notified the New Hampshire Attorney General of a data event affecting approximately 30 NH residents. Unauthorized activity was identified on Dec 18, 2023, leading to system isolation on Dec 20, 2023, due to an imminent ransomware attack. Personal information was accessed. The company engaged forensic experts, notified law enforcement, and is offering credit monitoring services.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_03c54138ce498d6eMaine State AGfiled 2024-06-10(1d gap)Candidate
- bd_2c2d994f154ddba8Oregon State AGfiled 2024-06-10(1d gap)Verified
- bd_71b5952cfc0bcda6Vermont State AGfiled 2024-06-10(1d gap)Verified
- bd_8859929ee6e3d9cdIndiana State AGfiled 2024-06-10(1d gap)Verified
Show 3 more filings ↓Show fewer ↑up to 1d gap
- bd_925be77b47ede7b0California State AGfiled 2024-06-10(1d gap)Verified
- bd_e54d5f458060513bWashington State AGfiled 2024-06-10(1d gap)Verified
- bd_eb86e3765537060cMontana State AGfiled 2024-06-10(1d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/first-american-financial-20240611.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 11, 2024
- Raw hash
- 28c588d8f2fb787a883480242165d6dac422dd19a5c522f35206a48f5042615e
Reporting entity
- Name
- FIRST AMERICAN FINANCIAL CORPORATIONnorm: first american financial
- Domain
- firstam.com
Victim entity
- Name
- FIRST AMERICAN FINANCIAL CORPORATIONnorm: first american financial
- Domain
- firstam.com
Incident
- Discovered
- Dec 18, 2023
- Materiality determined
- —
- Notification sent
- Jun 10, 2024
- Affected individuals
- 30
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified applicable regulatory authorities
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 25 weeks(176 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.