CSIDB logo
Incident

Fidelity National Financial

Incident posture

Attack window
Apr 2014
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2026-01-19 23:02

Linked entities

Victim
Fidelity National Financial
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Apr 2014
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Fidelity National Financial experienced a targeted phishing attack compromising a small number of employee email accounts, potentially exposing sensitive personal information including Social Security numbers, bank account details, and payment card data. Attackers intermittently accessed select accounts hosted by a third-party provider, intending to redirect business transaction funds rather than harvest bulk personal data. The company engaged federal law enforcement and a security expert, finding no evidence of internal network penetration or confirmed data access. Enhanced email security measures and employee training were implemented, with affected individuals notified and offered identity protection services. Subsidiaries providing title insurance in multiple states were implicated in the incident.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

In April 2014, Fidelity National Financial experienced a targeted phishing attack compromising a small number of employee email accounts hosted by a third-party service provider. Attackers obtained usernames and passwords through these phishing attempts, gaining intermittent access to a subset of accounts between April 14 and April 16. The investigation revealed no evidence of penetration into Fidelity’s internal network or systems. According to the company’s notification letter dated September 23, 2014, the attackers’ apparent objective was to gather information about ongoing business transactions to redirect scheduled money transfers, rather than to access large volumes of personal data. Personal information potentially exposed included Social Security numbers, bank account numbers, payment card numbers, and driver’s license numbers, though no evidence confirmed actual access to this data.

Fidelity National Financial notified federal law enforcement and engaged a third-party security expert to determine the incident’s scope. The company implemented enhanced email security measures and provided additional employee training to prevent future occurrences. Impacted individuals—whose numbers remain undisclosed—received notification by mail and were offered one year of free identity protection services. The breach affected entities under Fidelity’s umbrella, including Ticor Title Company of Oregon, Ticor Title of Nevada, Inc., Lawyers Title Company, and Lawyers Title of Oregon, LLC, which provide title insurance and settlement services in Oregon, Nevada, and California. The incident was reported to California authorities on October 24, 2014, over six months after the initial compromise.

Sources

Sources available to members: 1 source.

CSIDB