This research environment is built for a desktop viewport. Please open it on a laptop or larger display.
Peer comparison
First American Financial Corp vs. choose a peer
Filter
First American Financial CorpFAF
8-K/A · 0000950170-23-073848
Filed 2023-12-29 · Item 1.05 · 9.01
No peer selected. Use the picker above to choose one.
Incident character
Type
Unauthorized activity on information technology systems.
—
Source
Registrant's own systems
—
Disclosure basis
Item 1.05 (mandatory)
—
DOJ delay
Not disclosed by filer in this section
—
Scope
Data classes
Not disclosed by filer in this section
—
Attack vectors
Not disclosed by filer in this section
—
Records affected
Not disclosed by filer in this section
—
Data exfiltrated
Confirmed
—
Unauthorized access
Confirmed
—
Impact
Operational impact
The Company elected to isolate systems from the Internet and is in the process of restoring access to its systems and resuming normal business operations.
—
Financial impact
Not disclosed by filer in this section
—
Materiality
Operational
—Not addressed
—
Financial
◐Pending
—
Verbatim language
The Company continues to assess whether the incident will have a material impact on the Company\atiality_history":[],"doj_delayed":null,"remediation":"The Company took steps to contain, assess and remediate the incident, isolated systems from the Internet, retained leading experts, worked with law enforcement and notified certain regulatory authorities.","citations":{"incident_type":"the Company recently identified unauthorized activity on certain of its information technology systems","incident_source":"unauthorized activity on certain of its information technology systems","attack_vectors":null,"data_classes":null,"data_exfiltrated":"the Company believes the perpetrator of the activity accessed certain Company systems, exfiltrated data and encrypted data on certain non-production systems","unauthorized_access_confirmed":"the Company believes the perpetrator of the activity accessed certain Company systems, exfiltrated data and encrypted data on certain non-production systems","records_affected":null,"financial_impact":null,"operational_impact":"On December 20, 2023, the Company elected to isolate systems from the Internet.","containment_status":"As of the date of this filing, the Company believes it has contained the incident.","controls_mentioned":null,"operational_materiality":null,"financial_materiality":"The Company continues to assess whether the incident will have a material impact on the Company\u2019s financial condition or results of operations, which at this point cannot be determined.","doj_delayed":null,"remediation":"Upon detection of the unauthorized activity, the Company took steps in an effort to contain, assess and remediate the incident."}}
—
Response
Containment
Contained.
—
Controls mentioned
Not disclosed by filer in this section
—
Remediation
The Company took steps to contain, assess and remediate the incident, isolated systems from the Internet, retained leading experts, worked with law enforcement and notified certain regulatory authorities.