First American, a leading provider of title insurance, put 885 million PDFs including bank account numbers, statements, mortgage and tax records, Social Security numbers, wire transaction receipts, and drivers license images online, with no security at all!
Earlier this week, KrebsOnSecurity was contacted by a real estate developer in Washington state who said he’d had little luck getting a response from the company about what he found, which was that a portion of its Web site (firstam.com) was leaking tens if not hundreds of millions of records. He said anyone who knew the URL for a valid document at the Web site could view other documents just by modifying a single digit in the link. And this would potentially include anyone who’s ever been sent a document link via email by First American.