Finastra investigates breach of internal file transfer platform
- Organization
- Finastra
- Exploit
- Credential Compromise
- Industry
- Financial Technology
Finastra, a London based financial technology company whose software is used by more than 8,000 financial institutions including many of the world's largest banks, said it was investigating a breach of an internally hosted secure file transfer platform after stolen files were advertised for sale online.
The company said its security team detected suspicious activity on the platform on 7 November 2024 and began notifying customers the following day. A later notification placed the unauthorized access between 31 October and 8 November 2024. Finastra said initial evidence pointed to compromised credentials as the route in, and that the incident was contained to the file transfer platform, with no evidence of lateral movement into its wider network and no malware deployed.
A poster on a cybercrime forum using the handle abyss0 advertised roughly 400 gigabytes of data said to have come from Finastra, described as including client files and internal documents. The claim was first reported by security journalist Brian Krebs. Finastra told TechCrunch that the affected platform is not used by all customers, and declined to say how many customers were involved or precisely what data had been accessed.
Finastra subsequently confirmed that files containing customer names and financial account details had been taken. It began notifying affected individuals in February 2025 and offered two years of identity protection and credit monitoring through Experian. The company said it had found no indication the stolen data was further copied, retained or shared, and that it had implemented security enhancements.