article thumbnail

NY Charges First American Financial for Massive Data Leak

Krebs on Security

In May 2019, KrebsOnSecurity broke the news that the website of mortgage title insurance giant First American Financial Corp. had exposed approximately 885 million records related to mortgage deals going back to 2003. The documents were available without authentication to anyone with a Web browser.

Insurance 282
article thumbnail

SEC Announces Settled Charges Against First American for Cybersecurity Disclosure Controls Failures – Lessons Learned

Data Matters

The Order alleges that this vulnerability exposed over 800 million images dating back to 2003, including sensitive personal data, such as Social Security numbers and financial information. See CF Disclosure Guidance: Topic No. 2, Cybersecurity (Oct. 14, 2011). 15, 2020). 2020-0030-C (July 21, 2020).

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Security Compliance & Data Privacy Regulations

eSecurity Planet

Other industry standards too can have the force of “pseudo-law” – notably, the NIST Cybersecurity Framework, which federal regulators often apply to financial-services firms and government contractors. Thus, it can be difficult for even small enterprises to keep up with information security and data privacy compliance.

article thumbnail

Observations on the Cybersecurity Executive Order and Presidential Policy Directive

Hunton Privacy

This aspect of the Executive Order represents a clear update to the previous approach to critical infrastructure identification, prioritization and protection set forth in the Bush Administration’s Homeland Security Presidential Directive 7, published in 2003.

article thumbnail

FTC Seeks Comment on Proposed Changes to GLBA Implementing Rules

HL Chronicle of Data Protection

The Safeguards Rule, which originally went into effect in 2003, is process-oriented. It includes general, high level elements of a security program, but lacks detailed security steps. The proposed amendments follow the FTC’s receipt of public comments in 2016 regarding the Safeguards Rule as part of the FTC’s regular review cycle.

Privacy 40
article thumbnail

Privacy and Cybersecurity Top 10 for 2018

Data Matters

In any event, betting against federal data breach legislation has been the right call every year since California adopted the first state notification law in 2003. In 2017, the New York Department of Financial Services finalized some of the most stringent, and certainly some of the more complex, cybersecurity rules in the country.

article thumbnail

UNRAVELING EternalBlue: inside the WannaCry’s enabler

Security Affairs

Its exploitation can have serious consequences, resulting in data breaches, financial losses, operational disruption, and reputation damage to organizations. The widespread presence increased the potential attack surface and made it a critical concern for security professionals.

Phishing 103