SEC Settles Charges Against Real Estate Services Company Over Control Failures Related to Cybersecurity Disclosure
Time 2 Minute Read

On June 15, 2021, the SEC announced it settled charges against real estate services company First American Financial Corporation (“First American”) for alleged violation of Rule 13a-15(a) of the Exchange Act. The SEC charged First American with failure to maintain disclosure controls and procedures designed to ensure that all available, relevant information concerning a software vulnerability that led to a cybersecurity incident was filed with the Commission.

On May 24, 2019, a cybersecurity journalist notified First American of a vulnerability in its document transmission software that had exposed over 800 million title and escrow document images containing sensitive personal data, such as Social Security numbers and financial information. The vulnerability allowed access to confidential documents without authorization in the event digits in URLs linking to personal files were altered. In addition, the lack of password protection on certain documents allowed publicly available search engines to cache documents shared via the software.

In response to the journalist’s notice, First American issued a statement and filed a Form 8-K with the SEC. According to the SEC, however, the senior executives responsible for these disclosures lacked information to fully evaluate the company’s cybersecurity responsiveness and the risk from the vulnerability at the time they approved the company’s disclosures. Specifically, the SEC found that the information security staff at First American had discovered the vulnerability months before receiving the journalist’s notice but that (i) the company failed to remediate the defect according to its own vulnerability remediation management policies and (ii) relevant personnel did not inform senior executives responsible for disclosures about these facts until after the company furnished a Form 8-K to the Commission.

The Chief of the SEC Enforcement Division’s Cyber Unit, Kristina Littman, noted, “As a result of First American’s deficient disclosure controls, senior management was completely unaware of this vulnerability and the company’s failure to remediate it. Issuers must ensure that information important to investors is reported up the corporate ladder to those responsible for disclosures.”

First American agreed to cease and desist from committing or causing future violations of Exchange Act Rule 13a-15 and to pay a civil money penalty of $487,616.

You May Also Be Interested In

Time 2 Minute Read

On March 5, 2026, the California Privacy Protection Agency announced that the agency had reached a settlement with Ford Motor Company resolving an enforcement action against the company that alleged noncompliance with the California Consumer Privacy Act’s opt-out of sale/sharing rights.

Time 2 Minute Read

In mid-January 2026, key Senate committees published discussion drafts of market structure legislation for comprehensive federal regulation of digital assets. The Senate Banking Committee’s version of the bill is called the “Digital Asset Market Clarity Act.”  The Senate Agriculture Committee’s version of the bill is called the “Digital Commodity Intermediaries Act.”

Time 2 Minute Read

On December 16, 2025, the Federal Trade Commission announced an enforcement action against Illusory Systems Inc., a Utah-based company doing business as Nomad, following a major data breach in which hackers stole $186 million from consumers.

Time 2 Minute Read

On November 20, 2025, the U.S. Securities and Exchange Commission issued a brief announcement that it filed a joint stipulation with defendants SolarWinds Corporation and its Chief Information Security Officer to dismiss, with prejudice, the SEC’s ongoing civil enforcement action against them.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page