Mortgage servicer LoanCare is warning 1,316,938 borrowers across America that their sensitive personal information was leaked in a data breach at its parent company, Fidelity National Financial.
See also: Samsung: Data breach affects customers

LoanCare is a partial servicing and temporary partial servicing provider and a major player in the mortgage servicing sector, managing approximately $390 billion in balances from 1.2 million loans.
Last week, its parent company, Fidelity National Financial, a well-established securities insurance company in the United States, disclosed a cyberattack in an SEC filing.
Following this information leak, LoanCare posted an announcement about the incident on its website and notified authorities of the incident, while also sharing a sample of the announcement sent to affected individuals.
“On or about November 19, 2023, LoanCare, LLC (“LoanCare”), which performs or has performed functions by assuming subordination for your mortgage lender, was notified of unauthorized access to certain systems within the provided computer network of its parent company, Fidelity National Financial, Inc. (“FNF”),” LoanCare’s data breach notification states.
The investigation, with the help of special independent committees and specialized government agencies, revealed that the attackers managed to steal data, including customer details, from Fidelity National Financial's systems
The leaked information includes:
- Full name
- Address
- Social Security Number
- Mortgage number
See also: PJ&A: Data breach affects approximately 9 million patients
The above information can be used for phishing, social engineering and fraud, therefore recipients of the notification are urged to be cautious with unexpected communication attempts.

Additionally, LoanCare provides instructions for enrolling in the two-year identity monitoring service through Kroll to further reduce the risk for exposed individuals.
Last week, insurance giant First American Financial Corporationalso revealed that it suffered a cyberattack that affected its systems.
The disruption caused by the cyberattack on First American continues as system restoration is underway and there are no estimates yet on when the company will return to normal operations.
So far the company has not provided any information on whether customer data has been leaked due to the incident.
See also: 1Password: Affected by Okta breach
The first key step in protecting against data breaches is to educate staff. Staff should be aware of the various methods attackers use to compromise data and how they can deal with such situations.
Second, the company must implement strong security policies. This may include using complex passwords, keeping software and hardware up to date, protecting networks with firewalls, and other security techniques.
Third, the company should create a data breach response plan. This should include quickly reporting the breach, communicating with customers , and taking action to restore security.
Finally, the company should invest in tools and services that provide advanced protection against data breaches. These can include intrusion detection software, network monitoring services, and encryption software.
Source: bleepingcomputer
