DisclosureLens
HackingTechnologyInformationVulnerability ExploitData ExfiltratedCustomer Data InvolvedPIIIdentity (basic)Government IDHighContained

FINASTRA TECHNOLOGY, INC.

bd_0f147676c144ac5a · schema v1 · pii pii-v1

Severity

High

Discovered

Nov 7, 2024

Filed

Jul 3, 2025

To disclose

34 weeks

Affected

25,518state residents only

Linked

8 filings

Confidence

66%
Full breach record for FINASTRA TECHNOLOGY, INC.3 incidents on file

Finastra Technology, Inc. reported a cybersecurity incident involving its Secure File Transfer Platform (Aspera) to the Iowa Attorney General. An unauthorized third party accessed the platform between October 31 and November 8, 2024, obtaining files containing names and Social Security numbers of 25,518 Iowa residents. Finastra discovered the incident on November 7, 2024, engaged law enforcement and forensic investigators, and is offering 24 months of credit monitoring. The risk to individuals is assessed as low.

Iowa clock IA AG ≤5 bday34 weeks discovery → filing
unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.

Incident timeline

undetected · 7 days
discovery → filing · 34 weeks / 238 days

Oct 31, 2024

Begins

Nov 7, 2024

Discovered

Jul 3, 2025

Filed

vs. sector median

+15 wks slower

This filing is one of 8 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (7) · sorted by filing gap

Show 3 more filingsup to 5d gap

Filing propagation · 8 filings · 8 states

View merged incident ↗

Pattern: first filing Jul 1 (IL), last Jul 8 (TX) — a 7-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.