N.Y. Department of Financial Services Announces Cybersecurity Charges Against Leading Title Insurance Provider for Exposing Millions of Documents With Consumers' Personal Information
The
In the statement of charges announced today, the Department alleges that a vulnerability in First American's information systems resulted in exposure of consumers' sensitive personal information over the course of several years, and First American failed to remedy the exposure promptly after it was discovered in
DFS alleges multiple failures in First American's handling of this extraordinary data exposure of sensitive consumer information, including:
* First American failed to follow its own policies, neglecting to conduct a security review and a risk assessment of the flawed computer program and the sensitive data associated with the data vulnerability;
* First American misclassified the vulnerability as "low" severity despite the magnitude of the document exposure, while also failing to investigate the vulnerability within the timeframe dictated by First American's internal cybersecurity policies;
* after the data exposure was discovered by an internal penetration test in
* the title insurer failed to follow the recommendations of its internal cybersecurity team to conduct further investigation into the vulnerability.
DFS alleges that these errors, deficient controls, and other flaws in First American's cybersecurity practices led to the data exposure that persisted for years, including months after it was discovered.
According to the statement of charges, First American violated six provisions of the Cybersecurity Regulation. The Cybersecurity Regulation is implemented pursuant to Section 408 of the Financial Services Law. Any violation of Section 408 with respect to a financial product or service, which includes title insurance, carries penalties of up to
A full copy of the statement of charges and Notice of Hearing can be found on the DFS website.
The hearing will be held at the office of the
DFS's Cybersecurity Regulation became effective in
DFS's Cybersecurity Regulation has served as a model for other regulators, including the
In 2019, Superintendent
Criminal justice a central issue in Wayne County state House primaries
OPINION: Sound Offs for July 23, 2020
Advisor News
Annuity News
Health/Employee Benefits News
Life Insurance News