Finastra Technology, Inc. experienced a data breach where unauthorized access occurred between October 31 and November 8, 2024, affecting an internal Secure File Transfer Platform (SFTP). The company discovered the breach on November 7, 2024, and subsequently notified law enforcement, including the FBI. An unknown third party using compromised credentials was responsible for the access, and a hacker alias "abyss0" claimed to be selling 400GB of stolen data.
The breach exposed sensitive data for more than 800,000 individuals across the United States. Confirmed data types include Social Security numbers (SSNs), financial account information, dates of birth, full names, mailing addresses, and email/phone details. No protected health information (PHI) was reportedly involved. Written notification letters to affected individuals began on July 3, 2025. Finastra offered 24 months of complimentary identity monitoring via Experian IdentityWorks, credit monitoring, and access to a dedicated call center.
More details about this incident may become public over time, and notification processes can sometimes be delayed.