Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Fidelity National Financial (FNF), the title insurance and real-estate services company—not Fidelity Investments—blocked access to some systems after discovering a cyber incident in November 2023. The precaution disrupted title, escrow, mortgage transaction and related technology services. FNF later said the incident was contained, service systems were restored, and its investigation found data had been taken from certain FNF systems.

Why FNF took systems offline

FNF said it became aware of a cybersecurity incident on November 19, 2023. In an initial filing with the U.S. Securities and Exchange Commission (SEC) on November 21, it disclosed that an unauthorized third party had accessed certain systems and acquired credentials. FNF blocked access to some systems while it assessed and contained the incident; the company said those actions caused varying levels of disruption to its businesses. At that stage, its investigation was still underway. (FNF’s November 21, 2023 Form 8-K)

Which services were affected?

The initial filing identified title insurance, escrow and other title-related services, mortgage transaction services, and technology for the real-estate and mortgage industries as affected areas. FNF said its majority-owned subsidiary F&G Annuities & Life was not impacted. The filing did not quantify how many transactions, customers or businesses experienced disruption, or establish an independently measured outage duration.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What FNF’s later investigation found

FNF’s January 9, 2024 SEC amendment supplied findings that were not available in its initial disclosure. The company said the incident was contained on November 26, 2023, its service systems had been restored, and its forensic investigation was completed on December 13. It determined that an unauthorized third party had accessed certain systems, deployed malware that FNF described as “not self-propagating,” and exfiltrated certain data. FNF said the last confirmed date of unauthorized activity on its network was November 20. (FNF’s January 9, 2024 Form 8-K/A)

FNF systems and customer-owned systems are different

FNF reported that it had no evidence customer-owned systems were directly impacted and that no customer had reported such an impact. That statement concerns customer-owned systems; it does not mean no data was taken. In the same amendment, FNF reported that data had been exfiltrated from certain of its own systems.

What the filings do not establish

The reviewed SEC disclosures do not identify the attacker or confirm an attribution to a named criminal group. They also do not establish that the incident was ransomware. FNF’s description of malware and data exfiltration should not be expanded into a more specific attack label without separate, reliable evidence.

What potentially affected consumers were told

FNF said it notified affected customers, relevant state attorneys general and regulators, and approximately 1.3 million potentially impacted consumers. It also said it was providing credit monitoring, web monitoring and identity-theft restoration services, and responding to consumer questions. The approximately 1.3 million figure is FNF’s estimate of potentially impacted consumers—not a count of people confirmed to have suffered identity theft.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Timeline of the incident and recovery

  • November 19, 2023: FNF became aware of a cybersecurity incident affecting certain systems.
  • November 21, 2023: FNF disclosed the incident to the SEC, saying it had blocked access to some systems and that business services were disrupted. The investigation was ongoing.
  • November 26, 2023: FNF later reported that the incident had been contained.
  • December 13, 2023: FNF said its forensic investigation was complete.
  • January 9, 2024: FNF filed an amendment with investigation findings, consumer-notification details and information about offered services.

What this means if a closing or mortgage transaction was affected

FNF’s filings explain why title, escrow and mortgage-related services were disrupted, but they do not identify individual transactions or say whether a particular home closing was delayed. Anyone trying to establish the status of a specific historical transaction would need to contact the title, escrow, lender or other service provider involved. The reported restoration describes the status FNF gave in its January 2024 filing; it is not a statement about current system status.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

FNF’s assessment of business impact

In its January 2024 amendment, FNF said, “At this time, we do not believe that the incident will have a material impact on the Company.” This was management’s contemporaneous assessment, not an independent determination of the incident’s ultimate financial or legal consequences.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.