SAN FRANCISCO — First American Financial Corporation, a provider of title insurance, said Friday that it had fixed a vulnerability in its website that exposed 885 million records related to mortgage deals going back 16 years.
The vulnerability would have allowed anyone to gain access to Social Security numbers, bank account details, drivers license and mortgage and tax records.
The security failure was first reported by Brian Krebs, the cybersecurity writer who last year reported a flaw in the way Facebook was storing hundreds of millions of user passwords.
First American, based in Santa Ana, Calif., said in a statement Friday afternoon that it addressed the security gap after it was notified by Mr. Krebs. “We are currently evaluating what effect, if any, this had on the security of customer information,” the company’s statement said. “We will have no further comment until our internal review is completed.”
The incident was the latest example of an under-the-radar company that retained enormous amounts of sensitive personal and financial data but was not effectively protecting that information.
In 2017, Equifax, one of the three major consumer credit reporting agencies, said the information for more than 145 million consumers — including Social Security numbers — was stolen.
Two years before that, the network of the Office of Personnel Management, which houses sensitive data like the fingerprints and medical histories of United States government employees, was also breached.
Organizations have paid little price for their security mishaps.
Last year, a study found that credit agencies actually profited after the Equifax breach, by charging fees to customers who subsequently chose to freeze their credit. The study, from Wakefield Research, found that $10 freezing fees had added up to about $1.4 billion in revenue for the credit agencies, including Equifax.
But that liability has started to shift. On Wednesday, Moody’s, the ratings agency, cut its outlook on Equifax, the first time a company has been downgraded because of a cybersecurity incident. The move is a signal to companies that losing customers’ data may lead to real costs.
Equifax said this month that it had spent $1.35 billion so far responding to its breach, including $690 million that it recently earmarked to cover some of its anticipated legal settlements.
Thieves are constantly scanning the internet for weaknesses that can be exploited for access to personal data, or financial records, that be used for identity theft and financial fraud.
First American’s shares fell 2 percent on Friday in after-hours trading.
In a presentation to investors in 2015, Dennis Gilmore, First American’s chief executive, was asked about cybersecurity.
[Get the Bits newsletter for the latest from Silicon Valley and the technology industry.]
“We take it very, very serious and first of all, we structure our databases and our operating systems,” Mr. Gilmore said. “It’s an issue that we continue to spend a lot of time on both operating at the board level and at the committee level, something we take very serious and we watch very, very closely.”
Mr. Krebs said he learned of the vulnerability in First American’s website after getting tipped off by Ben Shoval, a real estate developer in Washington State. Mr. Shoval contacted Mr. Krebs, who maintains a well-respected security news site, after getting little response from the company.
Mr. Krebs notified First American and waited for the company to fix the flaw before publicizing it.
All that was needed to exploit the vulnerability was tweaking a single digit in the address of a file reached through the site. No password or other login credentials were required. Most of the 885 million exposed files were wire transactions with bank account numbers, data that First American collects because it is a widely used seller of real estate title insurance.
“This is the kind of weakness that should have been found in a basic security assessment of the company’s website,” Mr. Krebs said.