Close Menu
  • Home
  • Finance News
  • Personal Finance
  • Investing
  • Cards
    • Credit Cards
    • Debit
  • Insurance
  • Loans
  • Mortgage
  • More
    • Save Money
    • Banking
    • Taxes
    • Crime
What's Hot

United MileagePlus Dining guide

January 31, 2025

CMLS introduces Aveo Flex 40, Canada’s newest 40-year mortgage

January 31, 2025

Some Considerations on OPM’s Deferred Resignation Program

January 31, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
InfinBudget
Subscribe
  • Home
  • Finance News
  • Personal Finance
  • Investing
  • Cards
    • Credit Cards
    • Debit
  • Insurance
  • Loans
  • Mortgage
  • More
    • Save Money
    • Banking
    • Taxes
    • Crime
InfinBudget
Home»Banking»Finastra customer files stolen in data breach
Banking

Finastra customer files stolen in data breach

November 22, 2024No Comments3 Mins Read
Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
Finastra customer files stolen in data breach
Share
Facebook Twitter LinkedIn Pinterest Email

This week, Finastra, a financial software company that says it serves “45 of the world’s top 50 banks” and has more than 8,100 customers, publicly acknowledged a data breach that affected the files it sends to its institutional customers.

The company said the breach did not cause any operational disruptions for customers and that no malware was deployed to the Finastra network. Rather, the breach affected the secure file transfer platform the company uses to exchange data files associated with many of the company’s products. The files appeared to relate to software development rather than consumer data.

Finastra said it is analyzing the data that was stolen to determine which specific customers were affected. The company is also assessing and sharing with customers which products are and are not dependent on the file transfer platform that was compromised.

Initial evidence suggests that compromised credentials led to the breach, according to the company, though its investigation is ongoing. In a letter to customers, which cybersecurity reporter Brian Krebs published, Finastra said it engaged cybersecurity firm Sygnia to support the investigation.

Finastra detected suspicious activity on its file transfer platform on Nov. 7 and immediately isolated and contained the platform, the company said. The next day, a threat actor claimed on data breach forums to have stolen data from Finastra. Also on Nov. 8, Finsatra notified customers about the incident, according to the letter.

“Importantly, we have been sharing new information with all of our stakeholders as it becomes available,” the company told American Banker. “The Finastra team has been actively and transparently responding to our customers’ questions and keeping them informed about what we do and do not yet know about the data that was posted.”

See also  How the CFPB's 1033 rule changes data security for banks

Finastra has shared indicators of compromise, or IOCs, with customers, which can help them confirm whether their systems were directly affected by the attack, according to the company.

The secure file transfer platform that the attacker compromised is not used by all customers and “is not the default platform used by Finastra or its customers to exchange data files,” the company said, “so we are working as quickly as possible to rule out affected customers.”

Note that while the secure file transfer platform shares the SFTP initialism with the Secure File Transfer Protocol, Finastra’s statement and letter to customers did not clarify whether the platform uses the protocol.

A post on cybercrime forum BreachForums dated Nov. 8 by a user named abyss0 advertised the sale of the apparently stolen data, which the user claimed came from IBM Aspera, a file transfer product suite. The user claimed the data included files with .dmp, .bak, .war, .jar, and .iso file extensions, as well as documentation.

These types of files are largely associated with software development rather than data storage, suggesting the breach might not have involved consumer data, which tends to fetch higher sales prices on cybercrime forums when stolen in bulk.

All posts by abyss0, who had posted about many other data breaches, have been removed from the forum, though it is unclear why. Finastra did not say whether it had paid an extortion payment.

Source link

breach customer data Files Finastra stolen
Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
Previous Article10 Habits Happy Retirees Have In Common
Next Article 73% of workers worry Social Security won’t be able to pay benefits

Related Posts

Buying a car? Here’s how to check if the car was stolen

December 8, 2024

CFPB sues Comerica over abuses of federal benefits users

December 8, 2024

How long does it take for Series EE bonds to mature?

December 7, 2024
Add A Comment
Leave A Reply Cancel Reply

Top Posts

How CFPB is cracking down on banks before Trump takes office | Credit Union Journal

November 18, 2024

How to get rich: 7 steps you can take to become wealthy

October 10, 2024

Equifax launches Global Consumer Credit File to help newcomers build Canadian credit

December 2, 2024
Ads Banner

Subscribe to Updates

Subscribe to Get the Latest Financial Tips and Insights Delivered to Your Inbox!

Stay informed with our finance blog! Get expert insights, money management tips, investment strategies, and the latest financial news to help you make smart financial decisions.

We're social. Connect with us:

Facebook X (Twitter) Instagram YouTube
Top Insights

United MileagePlus Dining guide

January 31, 2025

CMLS introduces Aveo Flex 40, Canada’s newest 40-year mortgage

January 31, 2025

Some Considerations on OPM’s Deferred Resignation Program

January 31, 2025
Get Informed

Subscribe to Updates

Subscribe to Get the Latest Financial Tips and Insights Delivered to Your Inbox!

© 2025 InfinBudget.com - All rights reserved.
  • Contact
  • Privacy Policy
  • Terms & Conditions

Type above and press Enter to search. Press Esc to cancel.