Corporations

First American Title Insurance: The SEC Settlement Over a Data Exposure That Left 885 Million Mortgage Records Publicly Accessible

The SEC charged First American Financial with disclosure violations after finding that executives knew about a vulnerability exposing 885 million mortgage and real estate documents to unauthenticated public access for years — and that the company's public cybersecurity disclosures did not accurately reflect the known risk.

First American Financial Corporation, the title insurance and settlement services company, agreed to a Securities and Exchange Commission settlement resolving charges that the company failed to maintain adequate disclosure controls and procedures in connection with a vulnerability that left approximately 885 million sensitive mortgage documents — including Social Security numbers, bank account records, and property transaction details — accessible online without any authentication requirement for years.DOCUMENTED

The SEC's case was notable for its focus on what executives knew and when: the agency's investigation found that the company's information security personnel had flagged the vulnerability in an internal report months before it became publicly known, and that despite this documented internal warning, the company's public disclosures about cybersecurity risks did not reflect the existence of this known, specific, and unresolved vulnerability.

Key facts
  • Approximately 885 million mortgage documents were publicly accessible without authentication due to a URL-manipulation vulnerability.
  • The SEC found that an internal security report had flagged the vulnerability months before public disclosure.
  • The documents contained highly sensitive financial and personal information including Social Security numbers and bank account details.
  • First American agreed to an SEC settlement that included civil monetary penalties.
  • The New York Department of Financial Services separately pursued enforcement related to the same data exposure.

The Nature of the Vulnerability

The security flaw that exposed First American's document library was a common web application vulnerability called insecure direct object reference. The company's title search and document retrieval system assigned sequential numeric identifiers to documents in its online repository, and those identifiers were embedded directly in the URLs through which documents were accessed. A user who obtained a valid document URL could then access any other document in the system simply by incrementing or changing the numeric identifier in the URL — no authentication, no access control, no verification of whether the requesting user had any legitimate relationship to the document they were retrieving.REVIEWED

When security researchers discovered the vulnerability in 2019 and documented it publicly, the scope of the exposure was staggering: approximately 885 million documents dating back to 2003 were accessible through this mechanism. The documents included real estate transaction records, deed of trust documents, mortgage settlement statements, and the supporting financial and identity documentation that buyers and sellers provide as part of property transactions — Social Security numbers, bank account and routing numbers, wire transfer instructions, and driver's license images.DOCUMENTED

What Executives Knew Before Public Disclosure

The SEC's investigation focused on the gap between what First American executives knew internally and what the company told investors and the public about its cybersecurity posture. The agency found that First American's information security team had conducted a vulnerability assessment that identified the insecure direct object reference flaw and classified it as a high-severity finding. This assessment was documented in an internal report that was distributed to information security personnel and escalated through appropriate channels — meaning that the vulnerability was a known, documented, high-severity issue within the company's security program for months before it became public.REVIEWED

Despite this internal documentation, the company's public cybersecurity disclosures during this period did not disclose the existence of the known vulnerability or its potential significance. The SEC's disclosure violation charges did not require a finding that First American intentionally misled investors — only that the company's disclosure controls and procedures were inadequate to ensure that material cybersecurity information known internally was reflected accurately in public statements and SEC filings. The gap between the internal security report and the external disclosure was the core of the violation the settlement resolved.

The disclosure violation was not that the breach happened — it was that executives had been told about the vulnerability and that knowledge did not make it into the public disclosures investors relied on.

The NYDFS Parallel Action

The New York Department of Financial Services separately pursued enforcement against First American in connection with the same data exposure under New York's cybersecurity regulations for financial services companies, which require covered entities to maintain a cybersecurity program that addresses vulnerability management and to report significant cybersecurity events to the regulator. The NYDFS action resulted in a $1 million penalty — at the time, the first penalty under New York's cybersecurity regulation — establishing that the state's cybersecurity requirements for insurance companies and other financial institutions were enforceable and that the First American exposure constituted a violation.DOCUMENTED

The dual federal-state enforcement response to the First American exposure established a pattern that regulators have applied in subsequent cases: significant data exposures at large financial institutions are likely to face enforcement scrutiny from both securities regulators focused on disclosure adequacy and state financial regulators focused on cybersecurity program compliance, creating overlapping liability exposure for companies that experience major security failures.

Implications for Public Company Cybersecurity Disclosure

The First American case became a reference point for the SEC's subsequent rulemaking on cybersecurity disclosure, which the agency finalized in 2023 and which requires public companies to disclose material cybersecurity incidents within four days of determining materiality, and to disclose annually their cybersecurity risk management processes, governance structures, and the board's oversight role. The rules reflect the SEC's conclusion that investors have a material interest in companies' cybersecurity risk management practices — not only after a breach occurs, but as an ongoing component of the company's operational risk profile.REVIEWED

For companies maintaining large repositories of sensitive customer or transaction data — particularly financial institutions, title insurance companies, mortgage servicers, and other firms that aggregate real estate transaction records — the First American case illustrates the importance of ensuring that known vulnerabilities affecting sensitive data receive prompt remediation and that the gap between what security teams know and what executives disclose publicly is closed rather than allowed to persist. The existence of an internal high-severity finding is not itself a disclosure trigger in all circumstances, but its persistence without remediation — and the failure to reflect it in risk disclosures — is precisely the pattern the SEC identified as a violation.

Steps Toward Better Cybersecurity Disclosure

The First American case has had a lasting impact on how public companies approach cybersecurity risk disclosure. Following the SEC's enforcement action, legal and compliance teams across industries revisited their vulnerability escalation procedures and their processes for ensuring that material cybersecurity findings identified internally are reflected in public filings with appropriate specificity. The SEC's 2023 cybersecurity disclosure rules codified many of the expectations the First American action had signaled — requiring that material cybersecurity incidents be disclosed within four business days of a materiality determination and that annual reports describe the company's cybersecurity risk management framework and governance in terms that give investors a meaningful picture of how the company identifies, manages, and oversees cyber risk. The First American case remains the clearest pre-rule example of what the SEC considers an inadequate cybersecurity disclosure — a known, documented, high-severity vulnerability that was not reflected in the risk disclosures investors were relying on when assessing the company's operational risk profile.

Have documents relevant to this story? Reach us through our tips channel.

Every Watchdog Journal investigation is built on primary documents and classified under our evidence standard.

Browse All Investigations →