British fintech giant Finastralast week began sending written notifications to people whose personal data was exposed due to a security breach.
See also: Hacker pleads guilty to SEC X account breach

The incident was revealed in mid-November 2024, when a cybercriminal posted on an underground forum data he claimed to have stolen from the systems . The hacker claimed that the total amount of stolen data amounted to 400 gigabytes.
At the time, Finastra confirmed a data breach, revealing that the attacker had gained access to an internal file transfer application used by some of its customers. However, it declined to provide details on the extent of the incident, citing the ongoing investigation.
On February 12, the fintech company notified the Massachusetts Office of Consumer Affairs and Business (OCABR) that it had begun sending data breach to 65 residents of the state. The notifications informed those involved that their personal data had been exposed during the incident.
See also: Grubhub: Data breach affects customers and drivers
In the notification letter, a redacted copy of which was submitted to OCABR, Finastra discloses that, between October 31, 2024, and November 8, 2024, a threat actor repeatedly gained access to an internal, secure platform . During this period, it extracted specific files from the platform.

According to the company, the stolen files contained personal information, such as names, as well as financial account details. Finastra is offering those affected by the breach two years of free identity protection and credit monitoring services as a support and security measure.
The company did not disclose how many people may have been affected by the cyberattack, nor did it provide additional details. However, in November it clarified that it was not a ransomware attack and that no malware on its systems.
The wording of the notification letter, combined with the fact that the attacker's post on the underground forum was deleted relatively quickly, potentially suggests that the company negotiated with the perpetrator and paid a monetary fee to delete the stolen data.
See also: Community Health Center: Data breach affects 1 million patients
Data breaches are a serious threat in our digital age, as they can lead to loss of sensitive information and financial losses. They usually result from malicious attacks such as hacking, phishing scams, or even human errors such as carelessness in data management. It is essential to implement strong security measures, such as encryption, regular system updates, and staff training, to reduce the risk and protect data.
Source: securityweek
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
