First American Financial Pays Farcical $500K Fine

In May 2019, KrebsOnSecurity broke the news that the website of mortgage settlement giant First American Financial Corp. [NYSE:FAF] was leaking more than 800 million documents — many containing sensitive financial data — related to real estate transactions dating back 16 years. This week, the U.S. Securities and Exchange Commission settled its investigation into the matter after the Fortune 500 company agreed to pay a paltry penalty of less than $500,000.

First American Financial Corp.

If you bought or sold a property in the last two decades or so, chances are decent that you also gave loads of personal and financial documents to First American. According to data from the American Land Title Association, First American is the second largest mortgage title and settlement company in the United States, handling nearly a quarter of all closings each year.

The SEC says First American derives nearly 92 percent of its revenue from its title insurance segment, earning $7.1 billion last year.

Title insurance protects homebuyers from the prospect of someone contesting their legitimacy as the new homeowner. According to SimpleShowing.com, there are actually two title insurance policies in each transaction — one for the buyer and one for the lender (the latter also needs protection as they’re providing the mortgage to purchase the home).

Title insurance is not mandated by law, but most lenders require it as part of any mortgage transaction. In other words, if you wish to take out a mortgage on a home you will not be able to do so without giving companies like First American gobs of documents about your income, assets and liabilities — including quite a bit of sensitive financial data.

Aside from its core business competency — checking to make sure the property at issue in any real estate transaction is unencumbered by any liens or other legal claims against it — First American basically has one job: Protect the privacy and security of all these documents.

A redacted screenshot of one of many millions of sensitive records exposed by First American’s Web site.

It’s easy to see why companies like First American might not view protecting this data as sacrosanct, as the entire industry’s incentive for safeguarding all those sensitive documents is somewhat misaligned.

That is to say, in the title insurance industry the parties to a real estate transaction aren’t customers, but rather they are are the product. The actual customers of the title insurance companies are principally the banks which back these mortgage transactions.

We see a similar dynamic with social media platforms, where the “user” is not the customer at all but the product whose data is being bought and sold by these platforms.

Roughly five months before KrebsOnSecurity notified First American that anyone with a web browser could view sensitive document in its “Eagle Pro” database online just by changing some characters at the end of a link, an internal security audit at First American flagged the exact same vulnerability.

But the company never acted to fix it until the news media came calling.

The SEC’s administrative proceeding (PDF) explains how things slipped through the cracks. Under First American’s documented vulnerability remediation policies, the data leak was classified as a security weakness with a “level 3” severity, which placed it in the “medium risk” category and required remediation within 45 days.

But rather than recording the vulnerability as a level 3 severity, due to a clerical error the vulnerability was erroneously entered as a level 2 or “low risk” severity in First American’s automated tracking system. Level 2 issues required remediation within 90 days. Even so, First American missed that mark.

The SEC said that under First American’s remediation policies, if the person responsible for fixing the problem is unable to do so based on the timeframes listed above, that employee must have their management contact the company’s information security department to discuss their remediation plan and proposed time estimate.

“If it is not technically possible to remediate the vulnerability, or if remediation is cost prohibitive, the [employee] and their management must contact Information Security to obtain a waiver or risk acceptance approval from the CISO,” the SEC explained. “The [employee] did not request a waiver or risk acceptance from the CISO.”

So, someone within First American accepted the risk, but that person neglected to ensure the higher-ups within the company also were comfortable with that risk. It’s difficult not to hum a tune whenever the phrase “accepted the risk” comes up if you’ve ever seen this excellent infosec industry parody.

The SEC took aim at First American because a few days after our May 24, 2019 story ran, the company issued an 8-K filing with the agency stating First American had no prior indication of any vulnerability.

“That statement demonstrated that First American’s senior management was not properly informed of the prior report of a vulnerability and a failure to remediate the problem,” wrote Michael Volkov, a 30-year federal prosecutor who now runs The Volkov Law Group in Washington, D.C.

Reporting for Reuters Regulatory Intelligence, Richard Satran says the SEC charged First American with violating Rule 13a-15(a) of the Exchange Act.

“The rule broadly requires firms involved in securities issuance to have a compliance process in place to assure material information follows securities laws,” Satran wrote. “The SEC avoided getting into the specific details of the breach and instead focused on the way its disclosure was handled.”

Mark Rasch, also former federal prosecutor in Washington, said the SEC is signaling with this action that it intends to take on more cases in which companies flub security governance in some big way.

“It’s a win for the SEC, and for First America, but it’s hardly justice,” Rasch said. “It’s a paltry fine, and it involves no admission of guilt by First American.”

Rasch said First American’s first problem was labeling the weakness as a medium risk.

“This is lots of sensitive data you’re exposing to anyone with a web browser,” Rasch said. “That’s a high-risk vulnerability. It also means you probably don’t know whether or not anyone has accessed that data. There’s no way to tell unless you can go back through all your logs all those years.”

The SEC said the 800 million+ records had been publicly available on First American’s website since 2013. In August 2019, the company said a third-party investigation into the exposure identified just 32 consumers whose non-public personal information likely was accessed without authorization.

When KrebsOnSecurity asked how long it maintained access logs or how far back in time that review went, First American declined to be more specific, saying only that its logs covered a period that was typical for a company of its size and nature.

However, documents from New York financial regulators show First American was unable to determine whether records were accessed prior to Jun 2018 (one year prior to fixing the weakness).

The records exposed by First American would have been a virtual gold mine for phishers and scammers involved in Business Email Compromise (BEC) scams, which often impersonate real estate agents, closing agencies, title and escrow firms in a bid to trick property buyers into wiring funds to fraudsters. According to the FBI, BEC scams are the most costly form of cybercrime today.

First American is not out of the regulatory woods yet from this enormous data leak. In July 2020, the New York State Department of Financial Services announced the company was the target of their first ever cybersecurity enforcement action in connection with the incident, charges that could bring steep financial penalties. That inquiry is ongoing.

The DFS considers each instance of exposed personal information a separate violation, and the company faces penalties of up to $1,000 per violation. According to the SEC, First American’s EaglePro database contained tens of millions of document images that included non-public personal information.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

A Billion CVS Records Exposed

A Billion CVS Records Exposed

More than a billion records were exposed after a misconfiguration error left a CVS Health cloud database without password protection.

The 240GB of unsecured data was discovered by WebsitePlanet and security researcher Jeremiah Fowler in a cooperative investigation. 

Because of the security oversight by CVS Health, which owns CVS Pharmacy and Aetna, a total of 1,148,327,940 records were exposed.

Information that was left publicly accessible to anyone who knew how to look for it included customers’ search histories detailing their medications, and production records that exposed visitor ID, session ID, and device information (i.e., iPhone, Android, iPad, etc.). 

Personal data was also exposed, with researchers noting that “a sampling search query revealed emails that could be targeted in a phishing attack for social engineering or potentially used to cross reference other actions.”

Researchers said that any threat actors who accessed the database could have gleaned a clear understanding of configuration settings, discovered where data is stored, and accessed a blueprint of how the logging service operates from the backend.

After encountering the unprotected database on March 21, researchers contacted CVS Health, which acted swiftly to restrict public access.

“We were able to reach out to our vendor and they took immediate action to remove the database,” said CVS Health. “Protecting the private information of our customers and our company is a high priority, and it is important to note that the database did not contain any personal information of our customers, members or patients.”

“Misconfigurations like these are becoming all too common. Exposing sensitive data doesn’t require a sophisticated vulnerability, and the rapid growth of cloud-based data storage has exposed weaknesses in processes that leave data available to anyone,” PJ Norris, senior systems engineer at Tripwire, told Infosecurity Magazine.

He continued: “A misconfigured database on an internal network might not be noticed, and if noticed, might not go public, but the stakes are higher when your data storage is directly connected to the internet. Organizations should identify processes for securely configuring all systems, including cloud-based storage, like Elasticsearch and Amazon S3.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Australia Suffers Widespread Internet Outage

Australia Suffers Widespread Internet Outage

Australians’ lives were disrupted on Thursday by a widespread internet outage that impacted the country’s mail service and multiple businesses, including banks and airlines.

The outage began in the early hours and was caused by a problem at Akamai Technologies, a global content delivery network (CDN) and cybersecurity and cloud service provider. 

Akamai, which is based in Cambridge, Massachusetts, has acknowledged the issue, but has not yet disclosed the cause of service disruptions to its hosting platform, which mitigates against Distributed Denial-of-Service (DDoS) attacks. 

Akamai’s Chris Nicholson told NPR: “Akamai can confirm the segment of our Prolexic platform impacted is up and running and we are continuing to validate services. We will share more details of what transpired, but our first priority is ensuring all customer impact is mitigated.”

Three of the country’s four largest banks – ANZ, Westpac, and the Commonwealth Bank (CBA) – were all affected along with many smaller banks and some credit unions.

On Thursday afternoon, banking customers began reporting on social media that they were experiencing access issues when trying to use online banking services and banking apps.

Banks used social media to let their customers know that they were trying to deal with the situation.

CBA tweeted: “We’re aware some of you are experiencing difficulties accessing our services and we’re urgently investigating.”

The Reserve Bank of Australia said on Thursday night: “We have implemented appropriate mitigations and the website is now back up and running.” 

However, ABC News reported that ongoing technical problems led to the cancellation of some market operations between the Reserve Bank and other commercial banks. 

Services were also disrupted at Southwest Airlines, United Airlines, and Virgin Australia, which stated on social media that it was being impacted by a system outage that had affected its website and contact center.

Virgin, whose services were back online shortly after 5pm, stated that it “was one of many organizations to experience an outage with the Akamai content delivery system today and we are working with them to ensure that necessary measures are taken to prevent these outages from reoccurring.”

The national mail service, Australia Post, said that a number of its services had been knocked offline by an “external outage.” The Hong Kong Stock Exchange‘s website was also impacted.

Australians’ lives were disrupted on Thursday by a widespread internet outage that impacted the country’s mail service and multiple businesses including banks and airlines.

The outage began in the early hours and was caused by a problem at Akamai Technologies, a global content delivery network (CDN), cybersecurity and cloud service provider. 

Akamai, which is based in Cambridge, Massachusetts, has acknowledged the issue, but has not yet disclosed the cause of service disruptions to its hosting platform, which mitigates against Distributed Denial-of-Service (DDoS) attacks. 

Akamai’s Chris Nicholson told NPR: “Akamai can confirm the segment of our Prolexic platform impacted is up and running and we are continuing to validate services. We will share more details of what transpired, but our first priority is ensuring all customer impact is mitigated.”

Three of the country’s four largest banks – ANZ, Westpac, and the Commonwealth Bank (CBA) – were all affected along with many smaller banks and some credit unions.

On Thursday afternoon, banking customers began reporting on social media that they were experiencing access issues when trying to use online banking services and banking apps.

Banks used social media to let their customers know that they were trying to deal with the situation.

CBA tweeted: “We’re aware some of you are experiencing difficulties accessing our services and we’re urgently investigating.”

The Reserve Bank of Australia said on Thursday night: “We have implemented appropriate mitigations and the website is now back up and running.” 

However, ABC News reported that ongoing technical problems led to the cancellation of some market operations between the Reserve Bank and other commercial banks. 

Services were also disrupted at Southwest Airlines, United Airlines, and at Virgin Australia, which stated on social media that it was being impacted by a system outage that had affected its website and contact center.

Virgin, whose services were back online shortly after 5pm, stated that it “was one of many organizations to experience an outage with the Akamai content delivery system today and we are working with them to ensure that necessary measures are taken to prevent these outages from reoccurring”.

The national mail service Australia Post said that a number of its services had been knocked offline by an “external outage”. The Hong Kong Stock Exchange‘s website was also impacted.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Hackers Can Spy on Peloton Workouts

Hackers Can Spy on Peloton Workouts

Peloton bike users could be spied on while working out, according to new research by McAfee’s Advanced Threat Research team.

The team discovered a vulnerability (CVE-2021-3387) in the touchscreen of the $2,495 Bike+ that allows it to be controlled remotely by a threat actor without any interference to the equipment’s operating system.

Hackers could exploit the flaw to install malicious apps that spoof Netflix or Spotify to steal personal details and login credentials. 

Researchers also found that the vulnerability allowed bad actors to access the Peloton bike’s microphone and camera to spy on users. 

McAfee said that bikes used in hotels and other public spaces were most at risk because hackers had to physically access the screen and infect it with malicious code stored on a USB drive to exploit the flaw. 

The lower-priced Peloton Bike is not affected by the flaw as the fitness device uses a different type of touchscreen. 

But researchers noted: “Further conversations with Peloton confirmed that this vulnerability is also present on Peloton Tread exercise equipment, however, the scope of our research was confined to the Bike+.”  

The flaw was detected in the Peloton bike’s software. After McAfee shared the discovery with Peloton, the two companies joined forces to “responsibly develop and issue a patch.”

A mandatory software update that fixes the issue was released to users by Peloton earlier this month. 

Adrian Stone, Peloton’s Head of Global Information Security, said: “This vulnerability reported by McAfee would require direct, physical access to a Peloton Bike+ or Tread. Like with any connected device in the home, if an attacker is able to gain physical access to it, additional physical controls and safeguards become increasingly important. 

“To keep our members safe, we acted quickly and in coordination with McAfee. We pushed a mandatory update in early June and every device with the update installed is protected from this issue.”

McAfee’s report is the second security issue to hit Peloton in the past two months. In May, the company released an update to stop the leakage of personal account information, including the age, weight and location of its users.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

LORCA Announces New Intensive Program for Most Promising Cyber Startups

LORCA Announces New Intensive Program for Most Promising Cyber Startups

The London Office for Rapid Cybersecurity Advancement (LORCA) has launched a new initiative designed to propel the growth of UK cyber startups.

LORCA Ignite will see six of the most successful companies that have graduated from the LORCA accelerator program during the past three years participate in a new, intensive program, which will help them achieve rapid scale and commercial growth.

LORCA is a government-backed initiative that started in 2018 to accelerate the growth of UK cyber startups. It is delivered by Plexal at the London-based technology hub Here East and is supported by Deloitte and the Centre for Secure Information Technologies (CSIT) at Queen’s University Belfast. The year-long programs help the selected startups to secure investment, access new markets, and even participate in overseas trade missions, alongside mentoring and training sessions.

LORCA has significantly exceeded expectations during that time, with the 72 cyber startups and scaleups to take part in the program so far raising more than £200m in investment and generating over £37m in revenue. The level of investment achieved at this point is a massive 450% higher than LORCA’s original target that was set in 2018.

The new six-month program will enable the six selected firms to attend commercial and technology validation clinics and a showcase event. These firms have collectively raised £27m in investment and grants in the last three years. Additionally, LORCA Ignite will provide them with access to investors, mentoring services, and national and global networks and connect them to companies and security leaders who may require their products and services.

The cohort will also receive professional services expertise from several LORCA’s corporate partners, including AHL Connect, Outfly, Informed Funding, and Infosec People.

The six companies making up the LORCA Ignite cohort are:

Digital Infrastructure Minister Matt Warman commented: “Good cybersecurity is the bedrock of our digital economy, and our thriving sector will play a vital role in helping the nation build back better and stronger from the pandemic.

“Through our support for LORCA, we are backing our innovative cyber startups to grow their businesses and develop the cutting-edge solutions people and companies need to stay one step ahead of security threats.”

Saj Huq, director of LORCA, outlined: “LORCA Ignite is the evolution of an accelerator program that has demonstrated the extraordinary success of the British startup ecosystem over the last three years. By combining government support with innovation expertise and access to investors and global tech leaders, LORCA has accelerated the growth of a new generation of world-class British cyber startups. LORCA Ignite will continue that growth trajectory for some of the most high-potential businesses that have participated in our program. The UK has a globally competitive cyber ecosystem, and we need to provide support to the cyber scaleups at the forefront of what is quickly becoming a jewel in the UK’s tech crown.”

This week, it was announced that Risk Ledger, one of the companies that will take part in LORCA Ignite, has been chosen by NHS Test and Trace to help it manage its supply chain cybersecurity risks.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Puzzling New Malware Blocks Access to Piracy Sites

Puzzling New Malware Blocks Access to Piracy Sites

Researchers have admitted they’re baffled by a new piece of malware primarily designed to prevent victims from visiting software piracy sites.

Sophos principal researcher, Andrew Brandt, branded the discovery “one of the strangest cases I’ve seen in a while.”

It’s hidden in pirated copies of various software, including security products, and distributed on game chat service Discord and through Bittorent. Once double-clicked, it works by flashing up a bogus error message on the victim’s screen while executing.

The malware apparently blocks infected users from visiting a large number of piracy sites by modifying the HOSTS file on their systems. Brandt described this as a “crude but effective” strategy — crude because although it works, the malware has no persistence mechanism.

This means that anyone can remove the HOSTS file entries and stay removed unless the program is run a second time. Bizarrely, Brandt claimed to have discovered a malware family that behaved almost identically more than a decade ago.

The malware also downloads and executes a second payload, an executable named “ProcessHacker.jpg.”

It’s detected by Sophos as Mal/EncPk-APV.

Brandt said that the malware developer’s end game is still a mystery.

“On the face of it, the adversary’s targets and tools suggest this could be some kind of crudely compiled anti-piracy vigilante operation. However, the attacker’s vast potential target audience — from gamers to business professionals — combined with the curious mix of dated and new tools, techniques and procedures (TTPs) and the bizarre list of websites blocked by the malware, all make the ultimate purpose of this operation a bit murky,” he added.

“There may not even be an overall purpose to this attack at all. However, that doesn’t reduce the level of risk or the potential disruption for victims.”

Brandt urged users to install a robust security solution to spot such threats and avoid downloading pirated or “too good to be true” software.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk