Fidelity National Financial shut down systems after ALPHV ransomware attack

Organization
Fidelity National Financial (FNF)
Exploit
Ransomware
Industry
Title Insurance

Fidelity National Financial, a Fortune 500 title insurance and mortgage services group, told the U.S. Securities and Exchange Commission that it had identified a cybersecurity incident on November 19, 2023. In a Form 8-K made public on November 21, the company said an intruder had accessed certain systems and acquired certain credentials, and that it had blocked access to a number of systems in response.

The containment measures were themselves disruptive. FNF said the shutdown affected title insurance, escrow and other title related services, mortgage transaction services and the technology it supplies to the real estate and mortgage industries. Scheduled home sale closings were delayed around the country, since the group owns dozens of regional title companies.

The ALPHV/BlackCat ransomware operation claimed the attack on November 22 and used its leak site to criticize FNF for bringing in incident responders from Google's Mandiant unit. Security researchers suggested the entry point was the Citrix Bleed vulnerability, CVE-2023-4966, which FNF was reported to have patched some weeks after the October fix was released.

FNF said at the time that it was still assessing whether the incident would have a material impact. Its LoanCare loan subservicing subsidiary later notified 1,316,938 people that their names, addresses, Social Security numbers and loan numbers may have been obtained, and offered two years of identity protection through Kroll.

Updates

  1. LoanCare, a Fidelity National Financial subsidiary, notified 1,316,938 borrowers in late December 2023 that their names, addresses, Social Security numbers and loan numbers had been exposed through the November intrusion into its parent's network.

Sources