2021-06-15 SEC Press press_release 62 KB 2,524 chars

SEC Charges Issuer With Cybersecurity Disclosure Controls Failures

Release
2021-102
Caption
Securities and Exchange Commission v. Brent W. Wilner, et al.
summary

The Securities and Exchange Commission (SEC) announced settled charges against First American Financial Corporation for violating disclosure controls and procedures related to a major cybersecurity vu

paragraph

The Securities and Exchange Commission (SEC) announced settled charges against First American Financial Corporation for violating disclosure controls and procedures related to a major cybersecurity vulnerability. The breach exposed over 800 million sensitive images containing social security numbers and financial data, yet senior executives were not informed that the company had failed to remediate the known vulnerability for several months. Consequently, the company failed to ensure that all relevant information regarding the magnitude of the risk was properly analyzed for public disclosure. Without admitting or denying the findings, First American agreed to a cease-and-desist order and a $487,616 civil penalty.

Enriched metadata

Scheme
cyber-fraud (95%)
Outcome
settled
Civil penalty
$487,616
Classified cyber-fraud(confidence 95%). No EDGAR filing fingerprint (criminal/DOJ-side scheme). detection rule →
Statutes
Rule 13a-15(a)
Parties
brent w. wilnercybersecurity journalistfirst americanfirst american financial corporationsec's investigationsec's orderSecurities and Exchange Commissionsensitive customer informationsettled charges against first american financial corporation
Keywords
americandisclosure controlssecdisclosureordercompanyvulnerabilityinformationorder americancyber unitcontrolscybersecurityissuer cybersecuritycybersecurity disclosurecontrols failures

Exhibits & Attached Documents (1)

Extracted insights

Dollar amounts 1
  • $488K $487,616 $100K–$1M
Entities 9
  • person brent w. wilner
  • person cybersecurity journalist
  • person first american
  • company first american financial corporation
  • agency sec's investigation
  • agency sec's order
  • agency Securities and Exchange Commission
  • person sensitive customer information
  • company settled charges against first american financial corporation
Triples 12
  • Securities And Exchange Commission announced settled charges against First American Financial Corporation
  • First American Financial Corporation exposed sensitive customer information
  • cybersecurity journalist notified First American of a vulnerability
  • First American issued a press statement
  • First American furnished a Form 8-K to the Commission
  • First American's senior executives were not informed that the company's information security personnel had identified the vulnerability
  • First American failed to maintain disclosure controls and procedures
  • SEC's order charges First American with violating Rule 13a-15(a)
  • First American agreed to a cease-and-desist order
  • First American agreed to pay a $487,616 penalty
  • SEC's investigation was conducted by Brent W. Wilner
  • SEC's investigation was supervised by Diana K. Tani and Kristina Littman
PDF (from attached: pdf)
Text layers
Extracted body text (2,524c)
The Securities and Exchange Commission today announced settled charges against real estate settlement services company First American Financial Corporation for disclosure controls and procedures violations related to a cybersecurity vulnerability that exposed sensitive customer information. According to the SEC’s order, on the morning of May 24, 2019, a cybersecurity journalist notified First American of a vulnerability with its application for sharing document images that exposed over 800 million images dating back to 2003, including images containing sensitive personal data such as social security numbers and financial information. In response, according to the order, First American issued a press statement on the evening of May 24, 2019, and furnished a Form 8-K to the Commission on May 28, 2019. However, according to the order, First American’s senior executives responsible for these public statements were not apprised of certain information that was relevant to their assessment of the company’s disclosure response to the vulnerability and the magnitude of the resulting risk. In particular, the order finds that First American’s senior executives were not informed that the company’s information security personnel had identified the vulnerability several months earlier, but had failed to remediate it in accordance with the company’s policies. The order finds that First American failed to maintain disclosure controls and procedures designed to ensure that all available, relevant information concerning the vulnerability was analyzed for disclosure in the company’s public reports filed with the Commission. “As a result of First American’s deficient disclosure controls, senior management was completely unaware of this vulnerability and the company’s failure to remediate it,” said Kristina Littman, Chief of the SEC Enforcement Division’s Cyber Unit. “Issuers must ensure that information important to investors is reported up the corporate ladder to those responsible for disclosures.” The SEC’s order charges First American with violating Rule 13a-15(a) of the Exchange Act. Without admitting or denying the SEC’s findings, First American agreed to a cease-and-desist order and to pay a $487,616 penalty. The SEC’s investigation was conducted by Brent W. Wilner of the Cyber Unit with assistance from Amy J. Longo of the Trial Unit, and was supervised by Diana K. Tani and Ms. Littman of the Cyber Unit. The SEC appreciates the assistance of the New York State Department of Financial Services.
OCR text (2,524c · html-text · 99% conf)
The Securities and Exchange Commission today announced settled charges against real estate settlement services company First American Financial Corporation for disclosure controls and procedures violations related to a cybersecurity vulnerability that exposed sensitive customer information. According to the SEC’s order, on the morning of May 24, 2019, a cybersecurity journalist notified First American of a vulnerability with its application for sharing document images that exposed over 800 million images dating back to 2003, including images containing sensitive personal data such as social security numbers and financial information. In response, according to the order, First American issued a press statement on the evening of May 24, 2019, and furnished a Form 8-K to the Commission on May 28, 2019. However, according to the order, First American’s senior executives responsible for these public statements were not apprised of certain information that was relevant to their assessment of the company’s disclosure response to the vulnerability and the magnitude of the resulting risk. In particular, the order finds that First American’s senior executives were not informed that the company’s information security personnel had identified the vulnerability several months earlier, but had failed to remediate it in accordance with the company’s policies. The order finds that First American failed to maintain disclosure controls and procedures designed to ensure that all available, relevant information concerning the vulnerability was analyzed for disclosure in the company’s public reports filed with the Commission. “As a result of First American’s deficient disclosure controls, senior management was completely unaware of this vulnerability and the company’s failure to remediate it,” said Kristina Littman, Chief of the SEC Enforcement Division’s Cyber Unit. “Issuers must ensure that information important to investors is reported up the corporate ladder to those responsible for disclosures.” The SEC’s order charges First American with violating Rule 13a-15(a) of the Exchange Act. Without admitting or denying the SEC’s findings, First American agreed to a cease-and-desist order and to pay a $487,616 penalty. The SEC’s investigation was conducted by Brent W. Wilner of the Cyber Unit with assistance from Amy J. Longo of the Trial Unit, and was supervised by Diana K. Tani and Ms. Littman of the Cyber Unit. The SEC appreciates the assistance of the New York State Department of Financial Services.