Fidelity National Financial (FNF) has confirmed that a cyberattack that took place in November led to a data breach affecting 1.3 million customers.

FNF is a title insurance company for the real estate and mortgage industries ,based in America. It is one of the largest companies of its kind in the United States.
In mid-December, it reported a cyberattack in which attackers gained access to its networkusing stolen credentials. As a result, some services were taken offline, disrupting the company's business operations.
See also: 23andMe: Blames customer victims for data breach
In a new statement, Fidelity National Financial confirmed that the cyberattack occurred on November 19, 2023, and was successfully contained seven days later. According to the filing with the Securities and Exchange Commission, the attackers used malware that could infiltrate data from compromised systems.
The subsequent investigation was completed on December 13, 2023, revealing that the attackers had stolen the data of 1.3 million customers.
“We determined that an unauthorized third party accessed certain systems , developed a type of malware that is not spreading, and escaped with certain data,” FNF’s SEC filing states.
See also: HealthEC LLC: Data breach affects 4.5 million patients
“The Company has notified affected customers and attorneys general and regulators. For the approximately 1.3 million customers who may be affected, credit monitoring, web monitoring and identity theft recovery services are provided.“.
The filing clarifies that the breach was limited to Fidelity National Financial systems and did not affect connected systems .
Although the company has not officially confirmed it, the BlackCat ransomware (ALPHV) claimed responsibility for this attack, listing the company on its data leak website. The threat actors did not say whether any data was stolen in the attack, stating that they were waiting for FNF to contact them first.
What are the strategies for protecting against a customer data breach?
Current strategies for protecting against data include the use of advanced security solutions, such as anti-malware and antivirus software.

Businesses must also use technologies encryption to protect customer data during transport and storage. This means that even if the data is compromised, it will not be readable without the appropriate encryption key.
See also: EasyPark: Data breach may affect millions of users
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Staff training is also an important element of protecting customer data. Staff must be aware of the risks associated with a data breach and how to react in the event of a breach.
Finally, businesses should use data protection policies and procedures to ensure that customer data is handled securely. This may include restricting access to data, using strong passwords , and regularly updating security software.
Source: www.bleepingcomputer.com
