Back to top
Join us on LinkedIn Follow us on Twitter Like us on Facebook Follow us on Instagram
 
  OCTOBER RESEARCH STORE SUBSCRIBE LOG IN
AddControlToContainer_DynamicNavigation1

Cloudstar CEO provides insight into data breach response after FNF incident

Email A Friend Printer Friendly Version
2 comments
Industry News
Monday, November 27, 2023

After Fidelity National Financial Inc. (FNF) reported in a filing with the Securities and Exchange Commission that it was the victim of a cybersecurity incident, Gregory McDonald, CEO of Cloudstar provided insight into what might be happening in these days after the attack.

The filing noted that the incident “resulted in disruptions to [FNF’s] business.”

It continued, “FNF promptly commenced an investigation, retained leading experts to assist the company, notified law enforcement authorities, and implemented certain measures to assess and contain the incident. Among other containment measures, we blocked access to certain of our systems, which resulted in disruptions to our business. For example, the services we provide related to title insurance, escrow and other title-related services, mortgage transaction services, and technology to the real estate and mortgage industries, have been affected by these measures.”

Many agents are likely asking many questions, including, “How could this happen?”

While it would be great to know exactly what happened and how it happened, McDonald said that at this stage, its hard to know.

“One article speculated that it could be a Citrix vulnerability, but there’s really no way of knowing that at this point,” he said. “There’s several different attack vectors that can be used.

“In any organization, whether it’s what happened to me or whether its Fidelity, they’re not going to know what happened right away,” McDonald continued. “They have to do their research, they need to lock things down. They need to bring in outside experts and they need to find out exactly what happened so they are going to be very tight lipped about it, just like anybody would be. The first thing that you do is you close the doors, you lock them up, you control communication and you figure out what happened.”

He said its extremely frustrating to not be able to share what is happening.

“Its extremely frustrating because we’re all on the same team, right?” McDonald said. “When that happened to me, I’m on team customer, and Fidelity is too. Fidelity is on the side of the customer. We’re all on the same team. The bad people, they’re over in Russia. The bad people are trying to harm me, the bad people are trying to harm Fidelity, the bad people are trying to harm the customer. We’re all on the same team. The reason its frustrating is that we want to help the customer… and the way that we help the customer is by fixing the problem.”

And a lot of people trained to handle these situations are going to get involved and direct you, often at the direction of your insurance carrier.

“The first thing you are going to do is call the insurance company,” he said. “There’s a good reason for that. Its because the insurance company is going to pay for the resources that you need. The first thing the insurance company is going to do is they’re going to bring in the cybersecurity experts.

McDonald said these data security and forensic experts are going to help triage and stop the bleeding and isolate where the threat is coming from.

Insurance providers will also bring in ransomware negotiation teams, people that can figure out who the threat actors are and how to talk to them.

There are also lawyers that will get involved, and they are going to advise you on what you can and cannot say in order to protect you, and by extension, your customers.

“From a customer standpoint, they’re going to think that you’re not saying something because you have something to hide,” McDonald said. “And its important to know they are not. Of course lawyers are trying to protect everyone, but you have someone that is trying to extort millions and millions and millions of dollars.”

He also noted that like other types of ransom situations, a negotiator is trying to guide you on what to say because the criminal you are negotiating with is going to be listening in on everything that you say.

“[Another] reason that communication is limited is because anything that you say can upset that criminal," McDonald said. “They can decide, ‘We’re going to publish all of that data, or we’re going to retaliate against your customers.”

As disruptions to business continue, they are also likely asking “Why can’t you just use back ups?”

McDonald said that while that is a fair question to ask, the answer is a lot more complicated when it comes to dealing with ransomware than perhaps it was when addressing the viruses of the past.

First, he noted that criminals know you have backups off site and they attack those too.

He noted that in the past, when you got a virus, it attacked your computer and the computer was toast. But you could go to your backups and get your data back. The virus was not intelligent and was unaware that you have backups somewhere across the country.

“What’s going on today, people are not getting viruses as often,” McDonald said. “What’s going on today is organizations are being strategically attacked by foreign organizations with teams of people that are rewarded by millions of dollars if they attack both your production systems and your backups. When criminal enterprises are rewarded with millions of dollars, they’re going to go after your back ups. They are going to have someone working 40 hours a week to find where those backups are located. And they are going to tear them down, otherwise they have no leverage.

He said having data replicated off site is important if you are impacted by a fire or there’s an earthquake, tornado, hurricane or other natural disaster but will not help in the event of a ransomware attack.

McDonald also noted that there are many ways these criminals can get access to credentials. One not often spoken of way is by going to individuals who work at off shore companies. They approach these hardworking people trying to provide for their families, ask them for a username and password and offer them perhaps $5,000 or $10,000.

“Everyone’s always real quick to say, ‘Oh well, it wouldn’t happen if they didn’t’ click on that link in the email,” he said. “My employees are really smart. They know not to click on links in an email. That’s how it happened 20 years ago, and it’s how it could happen today, but I don’t think that’s how this happened. I don’t know how it happened. Its usually something more sophisticated.”

He said restoring data is not like turning a switch back on.

“In my case, we had a couple of petabytes of data,” McDonald said. “Lets say you want to restore something like that. That can take weeks to restore.

“And how do you just restore?,” he continued. “When you’ve had an infiltration like that, suppose you restore it and that data is infected? You need to track it and see and that’s what’s going on right now. Fidelity just can’t make something live, even if they think that its clean, even if they think they isolated that, they need to make sure. If they restore services to quickly, maybe the threat actor can get access to capital. You don’t know how long they’ve been sitting there or when the infiltration happened. They could have been in there for three months. So if you restore last week’s data, you probably start a new [breach].”

He said it could take a long time to figure out how long the threat actor was in your system.

Today's other top stories
Old Republic’s title insurance net premiums up by 11 percent
SoHo Title partners with Florida Agency Network
Voice of the Title Agent: Fewer survey respondents expect more federal, state regulations
Rosewood Title hires escrow officer
AFX Research integrates with Mortgage Automator on title updates


COMMENT BOX DISCLAIMER:
October Research is not responsible for the comments posted on its websites by readers. We will do our best to remove comments that include profanity or personal attacks or other inappropriate comments.
Comments:

Be the first to leave a comment.

Leave your comment
Please enter a comment.
CAPTCHA Validation
CAPTCHA
Code:
Please enter the word displayed in the image above. Please enter the word displayed in the image above.
: 
Please enter your name.
: 
Please enter your email address.
This field must contain a valid email address.
Your Email is for reporting purposes only. It will NOT be displayed.
Popularity:
This article has been viewed 17043 times.


News by Topic   News by Edition   In-depth Reports   Events   Subscribe
Announcements
Conference Coverage
Cyberawareness
Industry News
Market Data
People on the Move
Technology
Trendsetters
The TRID Journey
 
March 10, 2025
March 24, 2025
April 7, 2025
April 21, 2025
May 5, 2025
Archives
 
2025 Voice of the Title Agent Report
2025 State of the Industry Report
Cybersecurity Today
2024 Title Technology
eClosing Innovations
Technology as a Compliance Tool
Trendsetters
Archives
 
 
National Settlement Services Summit (NS3)
Women's Leadership Summit (WLS)
Webinars
 
Newsletter Subscriptions
Free Email Updates
Try a Free Edition
  Resources   About   Other Publications  
 
Keys to Real Estate Podcast
Blog - Tuesdays with Mary
eClosing Solutions Showcase
Best Practices Provider Directory
Industry Partners
 
The Title Report
Contact / Editors
Social Media
Advertise
Request a Media Kit
Are You An Expert?
Subscriber Agreement
 
The Legal Description
RESPA News
Valuation Review
Dodd Frank Upate
 
                 
Copyright © 1999-2025 The Title Report
An October Research, LLC publication
3046 Brecksville Road, Suite D, Richfield, OH 44286
(330) 659-6101, All Rights Reserved
www.thetitlereport.com | Privacy Policy
VISIT OUR OTHER WEBSITES
> Valuation Review
> RESPA News
> The Legal Description
> Dodd Frank Update
> NS3 The Summit
> Women's Leadership Summit
> October Research, LLC
> The October Store


Loading... Loading...
Featuring:
  • Delivery 3X a week plus breaking news as it happens
  • Comprehensive title insurance industry news
  • Recent acquisitions, mergers, real estate stats
  • Exclusive in-depth coverage of the industry's hottest stories
Featuring:
  • Delivery 2X a week plus breaking news as it happens
  • Comprehensive Dodd-Frank coverage
  • The latest information from the CFPB
  • Full coverage of Congressional hearings
  • Updates on all agency actions
  • Analysis of controversial provisions
  • Release of newest studies and reports
Sign up today and...
  • Be one of the first to know where NS3 is being held
  • Learn about NS3 speakers and sessions
  • Save on registration with Super-Early Bird rates
  • Discover the networking opportunities NS3 offers
  • Find out if CE credits will be offered for your area
  • And much more
Featuring:
  • Delivery 2X a week plus breaking news as it happens
  • Preview the latest RESPAnews.com Top Story
  • RESPA related headline news
  • Quote of the Week
Featuring:
  • Delivery 2X a week plus breaking news as it happens
  • Legal, regulatory and legislative information impacting the settlement services industry
  • News from HUD, Congress, state legislatures and other regulatory agencies
  • Follow the lobbying efforts of all the major national real estate services organizations.
Featuring:
  • Delivery 2X a week plus breaking news as it happens
  • The industry's only full-time newsroom
  • Relevant, up-to-date appraisal industry news
  • Covering the hottest stories and industry trends
NEWS BY TOPIC
NEWS BY EDITION
IN-DEPTH REPORTS
EVENTS
RESOURCES
FREE EMAIL UPDATES
ABOUT
SUBSCRIBE
Announcements
Conference Coverage
Cyberawareness
Industry News
Market Data
People on the Move
Technology
Trendsetters
Sponsored Content
Nominate a Trendsetter
What is Trendsetters
Current Edition
April 21, 2025
April 7, 2025
March 24, 2025
Archives
2025 Voice of the Title Agent
2025 State of the Industry
Cybersecurity Today
2024 Title Technology
eClosing Innovations
Real Estate Compliance Outlook
Technology as a Compliance Tool
Trendsetters
Archives
Nominate a Trendsetter
What is Trendsetters?
National Settlement
Services Summit (NS3)
Women's Leadership
Summit (WLS)
Webinars
Evolving Realtor Relationships
2025 Economic Outlook Series
CFPB's Shake-Up & Its Impact
Artificial Intelligence for Title
Industry and Regulatory Outlook
RESPA Updates You Need to Know
Strategies post-NAR settlement
Fraud Threats Facing Title
Evolving Consumer Relationships
Excess Equity
RESPA Compliance Essentials
Securing Your Cyber Network
Webinar Archives
Cyber Solutions Showcase
Keys to Real Estate Podcast
Title Insurance at Work
Blog - Tuesdays with Mary
eClosing Solutions Showcase
Executive Interview Series
Best Practices Provider Directory
Industry Partners
The Title Report
Contact Us
Social Media
Advertise
Request a Media Kit
Are You An Expert?
Subscriber Agreement