ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Fidelity National Financial says 2023 cyber attack impacted over 1.3 million individuals

Fidelity National Financial, a Florida-based title insurance and settlement services provider to the real estate and mortgage industries, said that a cyber attack it suffered last year compromised the sensitive personal information of 1.3 million individuals.In an 8-K filing with the US Securities and Exchange Commission in November last year, Fidelity National Financial said that immediately after identifying the cyber security incident, it launched an internal investigation, with assistance from third party cyber security experts, to understand the nature and scope of the incident. The company also notified law enforcement authorities and implemented measures to contain the incident.“Among other containment measures, we blocked access to certain of our systems, which resulted in disruptions to our business. For example, the services we provide related to title insurance, escrow and other title-related services, mortgage transaction services, and technology to the real estate and mortgage industries, have been affected by these measures,” the filing read.FNF added that while it continues to investigate the cyber security incident, experts have concluded that the threat actor who infiltrated the network had acquired certain credentials. In a filing with the Office of the Maine Attorney General, LoanCare, an FNF subsidiary, said that the compromised data includes names, addresses, Social Security Numbers, and Loan Numbers.Soon after the filing occurred, the notorious ALPHV BlackCat ransomware group claimed responsibility for the cyber attack on Fidelity National Financial and listed the company as a victim on its data leak site.

 

In another 8-K filing with the U.S Securities and Exchange Commission on Monday, FNF said that as many as 1.3 million individuals were affected by the incident.“We completed our forensic investigation on December 13, 2023. We determined that an unauthorised third-party accessed certain FNF systems, deployed a type of malware that is not self-propagating, and exfiltrated certain data,” FNF said.“The Company has no evidence that any customer-owned system was directly impacted in the incident, and no customer has reported that this has occurred. The last confirmed date of unauthorised third-party activity in the Company’s network occurred on November 20, 2023.“The Company has identified and analyzed the nature and scope of the affected systems and data. The Company has notified its affected customers and applicable state attorneys general and regulators, and approximately 1.3 million potentially impacted consumers; is providing credit monitoring, web monitoring, and identity theft restoration services; and is fielding questions from consumers,” it added.FNF filed a similar notification with the Office of the Maine Attorney General, stating that at least 1,316,938 individuals were impacted by the cyber security incident. It added that several lawsuits have been filed in connection to the incident, but it “will vigorously defend itself against any litigation filed related to the incident.”The company is offering two years of credit monitoring, web monitoring, and identity theft restoration services via Kroll to all the individuals affected by the cyber security incident.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543