Fintech giant Finastra confirms it’s investigating a data breach

Date:

Share post:


Finastra, a London-based financial software company that serves most of the world’s top banks, has confirmed it’s investigating a data breach after a hacker claimed a compromise of the company’s internal file-transfer platform. 

In a statement given to TechCrunch, Finastra spokesperson Sofia Romano confirmed the fintech giant detected what it calls “suspicious activity” related to an “internally hosted Secure File Transfer Platform (SFTP)” on November 7. 

News of the breach, first reported by cybersecurity journalist Brian Krebs, comes after someone claimed on a known cybercrime forum to be selling stolen files allegedly belonging to Finastra’s largest banking clients. In a since-deleted forum posting, the hacker said they were in possession of 400 gigabytes of data from Finastra, including client files and internal documents. 

In an incident disclosure shared with customers, obtained by Krebs, Finastra confirmed data was exfiltrated from its systems. Finastra’s spokesperson, who declined to share a copy of the disclosure with TechCrunch, said the company first communicated the incident to customers on November 8 and has been “keeping them informed about what we do and do not yet know about the data that was posted.” 

Finastra declined to name the compromised file-transfer platform, but the data seller claims the stolen data from Finastra’s network was sourced from IBM Aspera, a file-transfer software that allows organizations to move large files and data sets over the internet.

When asked by TechCrunch, Finastra would not say how many customers are affected or what types of data were accessed in the breach.

“We are analyzing affected data to determine what specific customers were affected, while simultaneously assessing and communicating which of our products are not dependent on the specific version of the SFTP platform that was compromised,” Finastra’s spokesperson Romano said in an emailed statement. “The impacted SFTP platform is not used by all customers… so we are working as quickly as possible to rule out affected customers.”

Finastra added that the company continues to investigate the root cause of the data breach, but said that “initial evidence points to credentials that were compromised.” This suggests the organization was compromised through the theft of someone’s username and password. It’s not yet known if the system was protected with multi-factor authentication, which can prevent some credential theft attacks.



Source link

Lisa Holden
Lisa Holden
Lisa Holden is a news writer for LinkDaddy News. She writes health, sport, tech, and more. Some of her favorite topics include the latest trends in fitness and wellness, the best ways to use technology to improve your life, and the latest developments in medical research.

Recent posts

Related articles

The Vision Pro is getting Apple Intelligence in April

Apple Intelligence is heading to the Vision Pro, as part of an upcoming operating system update. Apple...

How automotive exec Crystal Brown founded CircNova, an AI drug discovery biotech

Tiny Michigan biotech startup CircNova has raised a $3.3 million seed round for its technology that uses...

Apply to Speak at TechCrunch Sessions: AI before the deadline

AI Innovators, seize your moment! Have insights that could inspire 1,200 AI founders, investors, and enthusiasts eager...

Three reasons every founder and VC should be at TechCrunch All Stage 2025

From idea to IPO — where are you on your startup journey? Are you a pre-seed founder seeking...

OpenAI rolls out its AI agent, Operator, in several countries

OpenAI said on Friday that it is rolling out Operator, its so-called AI agent that can perform...

Rivian will launch hands-off highway driver assist ‘in a few weeks’

Rivian said Thursday it plans to launch a hands-off version of its driver assistance system for highway...

Solar crushed 2024, but emissions were up as industry used more natural gas

The U.S. invested a record-breaking $338 billion in the energy transition last year, according to a new...

6 new tech unicorns were minted in January 2025

Despite a still tight venture capital market, new unicorns are still being created every month. Using data from...