FIRST AMERICAN FINANCIAL CORPORATION
ent_019e229f3fdd143a9d3ead1d4c1d3ce2
Disclosures
14
State AG · SEC 8-K · 11 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
44,000
as filed · SEC 8-K FEDERAL
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- FIRST AMERICAN FINANCIAL CORPORATION
- Normalized
- first american financial— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300B6VEZK3N0A1P55
- SEC EDGAR CIK
- 0001472787
- Domain
- firstam.com
Disclosure history (14)newest first
- Massachusetts State AGas victim2024-06-11
First American Financial Corporation reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-06-11. 223 Massachusetts residents were affected.
- New Hampshire State AGas victim2024-06-11
First American Financial Corporation notified the NH Attorney General of a data event affecting approximately 30 New Hampshire residents. On December 18, 2023, the company identified unauthorized activity and detected evidence of a potentially imminent ransomware attack on December 20, 2023. Systems were isolated, and the actor was eradicated. Personal information may have been accessed, but there is no evidence of internet exposure. Credit monitoring services are being offered.
- Maine State AGas victim2024-06-10
First American Financial Corporation reported an external system breach (hacking) that occurred and was discovered on December 18, 2023. The breach affected 55 Maine residents, compromising their names in combination with their driver's license or non-driver identification card numbers. The company notified the affected individuals on June 10, 2024, and offered 24 months of complimentary credit monitoring and identity theft restoration services through Experian.
- Oregon State AGas victim2024-06-10
First American Financial Corporation reported a data breach to the Oregon Attorney General. The breach was reported on 2024-06-10. The breach occurred during 12/18/2023 - 1/2/2024. The breach was discovered on 12/18/2023. 41,638 individuals were affected. Notice was sent on 6/10/2024.
- Vermont State AGas victim2024-06-10
First American Financial Corporation notified Vermont AG of a cybersecurity incident discovered on Dec 18, 2023, involving unauthorized access to IT systems. The breach may have exposed names and other personal info. First American engaged external experts, worked with law enforcement, and offered 24 months of credit monitoring.
- Indiana State AGas victim2024-06-10
First American Financial Corporation reported a data breach to the Indiana Attorney General. The breach occurred on 2023-12-18 and was reported on 2024-06-10. 2,926 Indiana residents were affected. 41,683 individuals affected in total.
- California State AGas victim2024-06-10
First American Financial Corporation reported a data security incident occurring on December 18, 2023. The company retained cybersecurity experts, strengthened network security, and notified law enforcement and regulators. Affected individuals were offered 24 months of credit monitoring and identity theft restoration services via Experian. The specific nature of the breach and data types are not detailed in the provided notification letter excerpt, though identity data is implied by the remediation offered.
- Washington State AGas victim2024-06-10
First American Financial Corporation notified the Washington AG of a ransomware incident discovered on Dec 18, 2023. Systems were isolated on Dec 20. 706 WA residents affected. Data types included PII, SSN, financial accounts, and PHI. Remediation included forensic investigation, law enforcement notification, and 24 months of credit monitoring.
- Montana State AGas victim2024-06-10
First American Financial Corporation notified Montana residents of a cybersecurity incident discovered on December 18, 2023, involving unauthorized access to personal information including names. The company isolated systems, engaged forensic experts, worked with law enforcement, and offered 24 months of credit monitoring.
- Illinois State AGas victim2024-06-01
FIRST AMERICAN FINANCIAL CORPORATION filed a data-breach notice with the Illinois Attorney General in June 2024 (case 24-06-018). The register records the breach as discovered on December 18, 2024. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- FEDERALSEC 8-Kas victim2024-05-28
First American Financial Corp filed a supplemental 8-K disclosing unauthorized access to its IT systems. The investigation concluded that personal information of approximately 44,000 individuals was accessed. The company is notifying affected individuals and offering free credit monitoring and identity protection services.
- FEDERALSEC 8-Kas victim2024-01-12
First American Financial Corporation (NYSE: FAF) filed Amendment No. 2 to a Form 8-K disclosing a material cybersecurity incident under Item 1.05. Upon detecting unauthorized activity on certain IT systems, the company isolated systems from the internet on December 20, 2023, retained experts, worked with law enforcement, and notified regulators. The company believes the incident is contained and business operations have resumed. A material impact on Q4 2023 results of operations is expected, though not on overall financial condition.
- FEDERALSEC 8-Kas victim2023-12-29
First American Financial Corporation filed an 8-K/A amending its December 22, 2023 disclosure of a cybersecurity incident. The company detected unauthorized activity on its IT systems, elected on December 20, 2023 to isolate systems from the Internet, retained experts, worked with law enforcement, and notified regulators. The company believes the perpetrator accessed certain systems, exfiltrated data, and encrypted data on certain non-production systems. The incident is believed contained; investigation is ongoing.
- FEDERALSEC 8-Kas victim2023-12-22
First American Financial Corporation filed an Item 1.05 8-K reporting unauthorized activity on its IT systems. The company isolated systems from the internet on December 20, 2023, and engaged experts and law enforcement. The investigation is ongoing, and the company cannot yet estimate the duration, extent, or material impact of the disruption. No specific data types or affected individual counts were disclosed in this initial filing.