HackingStolen CredentialsData ExfiltratedTargetedIDENTITY_BASICCREDENTIALSLowContained
FIRST AMERICAN FINANCIAL CORPORATION
bd_71b5952cfc0bcda6 · schema v1 · pii pii-v1
Full breach record for FIRST AMERICAN FINANCIAL CORPORATION →First American Financial Corporation notified Vermont AG of a cybersecurity incident discovered on Dec 18, 2023, involving unauthorized access to IT systems. The breach may have exposed names and other personal info. First American engaged external experts, worked with law enforcement, and offered 24 months of credit monitoring.
Vermont clock✗ VT AG >45 bday25 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_03c54138ce498d6eMaine State AGfiled 2024-06-10Candidate
- bd_2c2d994f154ddba8Oregon State AGfiled 2024-06-10Verified
- bd_8859929ee6e3d9cdIndiana State AGfiled 2024-06-10Verified
- bd_925be77b47ede7b0California State AGfiled 2024-06-10Verified
Show 3 more filings ↓Show fewer ↑up to 1d gap
- bd_e54d5f458060513bWashington State AGfiled 2024-06-10Verified
- bd_eb86e3765537060cMontana State AGfiled 2024-06-10Candidate
- bd_383f35344a3929d1New Hampshire State AGfiled 2024-06-11(1d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-06-10-first-american-financial-corporation-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 10, 2024
- Raw hash
- 30b39b253b850309a8c968a3a78d3141ac1351c03e0b709ecb16548c8526d7c4
Reporting entity
- Name
- FIRST AMERICAN FINANCIAL CORPORATIONnorm: first american financial
- Domain
- firstam.com
Victim entity
- Name
- FIRST AMERICAN FINANCIAL CORPORATIONnorm: first american financial
- Domain
- firstam.com
Incident
- Discovered
- Dec 18, 2023
- Materiality determined
- —
- Notification sent
- Jun 10, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- notified certain regulatory authorities
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 25 weeks(175 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.