Data Breach

First American Data Breach

885.0M records exposed • May 2019

You could find anyone's mortgage documents just by changing numbers in the website address. 885 million documents exposed.

What Happened

885 million mortgage and financial records were exposed through a simple URL manipulation vulnerability.

Attack method: IDOR vulnerability exposing document URLs

What Data Was Exposed

Bank account numbers, Social Security numbers, Mortgage records, Tax documents, Wire transfer info

Is your business exposed?

What to Do If You're Affected

  1. 1.

    Monitor bank accounts for fraud

  2. 2.

    Set up bank account alerts

Lessons for Businesses

  • Basic web security matters
  • IDOR vulnerabilities common
  • Test authorization controls

Is your business exposed?

Check if your company data is circulating on the dark web

Free scan • No credit card required