Fortune 500 insurance and mortgage firm FNF shuts down network following cyberattack

real estate agent showing clients around a house
(Image credit: Getty)

Fortune 500 firm Fidelity National Financial (FNF) has suffered a cyberattack that forced it to take many of its services offline - and while the company did not specifically state the incident was a ransomware attack, the way it responded to the incident suggests it just might be.

The news, picked up by TechCrunch, is based on a report filed with the U.S. Securities and Exchange Commission (SEC) which states FNF discovered a security incident that “impacted certain FNF systems”. The company responded by notifying the police, investigating the matter, bringing in “leading experts”, and implementing “certain measures” of containment.

Some of the measures include blocking access to different parts of the system, which resulted in business disruptions, FNF explained. “For example, the services we provide related to title insurance, escrow and other title-related services, mortgage transaction services, and technology to the real estate and mortgage industries, have been affected by these measures,” it says. “Our majority-owned subsidiary, F&G Annuities & Life, a leading provider of insurance solutions, was not impacted by the incident.”


Reader Offer: $50 Amazon gift card with demo

Reader Offer: $50 Amazon gift card with demo
Perimeter 81's Malware Protection intercepts threats at the delivery stage to prevent known malware, polymorphic attacks, zero-day exploits, and more. Let your people use the web freely without risking data and network security.

Preferred partner (What does this mean?

Stealing credentials

FNF’s investigation has determined that an unnamed threat actor accessed some of its endpoints and “acquired certain credentials.” Fidelity National Financial is a Fortune 500 company providing title insurance and settlement services for the real estate and mortgage industry.

TechCrunch’s report says agents and homebuyers were “scrambling for solutions” following the shutdown of FNF’s services, especially because the services needed to complete transactions are expected to be offline until Sunday. The publication was also told that it was the servers in Jacksonville that were compromised in the attack. 

We still don’t know who breached FNF, if this was indeed a ransomware or a malware attack or what their demands are. We also don’t know what type of data was taken in the attack, as FNF is currently not responding to media inquiries.

More from TechRadar Pro

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Ransomware
Lee Enterprises blames cyberattack for encrypting critical systems as US newspaper outages drag on
Red padlock open on electric circuits network dark red background
Newspaper printing across US hit after Lee Enterprises says “cybersecurity event” disrupted operations
Security
American National Insurance Company breach data found online
Ransomware
Fortinet firewall bugs are being targeted by LockBit ransomware hackers
Close up of a person touching an email icon.
Top US mineral firm hit by cyberattack that saw thieves steal $500,000
ransomware avast
Engineering giant ENGlobal confirms hackers hit internal data
Latest in Security
Lock on Laptop Screen
Data breach at Pennsylvania education union potentially exposes 500,000 victims
Spyware
Stalkerware data breach potentially hits over 2 million users, including thousands of Apple devices
An American flag flying outside the US Capitol building against a blue sky
Five Eyes "cannot replace US intel in Ukraine", claims former US Cyber Command Chief
Pirate skull cyber attack digital technology flag cyber on on computer CPU in background. Darknet and cybercrime banner cyberattack and espionage concept illustration.
Criminals are using a virtual hard disk image file to host and distribute dangerous malware
WordPress on a laptop
Over 20,000 WordPress sites hit by damaging malware campaign
Trojan
WhatsApp patches security flaw which let hackers install spyware
Latest in News
Quordle on a smartphone held in a hand
Quordle hints and answers for Friday, March 21 (game #1152)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Friday, March 21 (game #383)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Friday, March 21 (game #649)
The ASSC Assassin's Creed collection.
The Assassin's Creed x Anti Social Social Club drop includes gaming merch that I wouldn't be embarrassed to wear
Lock on Laptop Screen
Data breach at Pennsylvania education union potentially exposes 500,000 victims
Spyware
Stalkerware data breach potentially hits over 2 million users, including thousands of Apple devices