HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICLowContained
FINASTRA TECHNOLOGY, INC.
bd_27ecf1fa9b7657fe · schema v1 · pii pii-v1
Full breach record for FINASTRA TECHNOLOGY, INC. →Finastra Technology, Inc. disclosed a cybersecurity incident where an unauthorized third party accessed a Secure File Transfer Platform (SFTP) between October 31 and November 8, 2024. The company identified the incident on November 7, 2024. The breach involved personal information, including names, of individuals associated with Finastra's customer support files. Finastra engaged forensic investigators, notified the FBI, and confirmed the attacker no longer has access. The company is offering 24 months of identity protection services to affected individuals.
California clockDiscovered Nov 7, 2024 → Notified Jun 30, 2025235d ✗ CA 60-day late34 weeks discovery → filing
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_0f147676c144ac5aIowa State AGfiled 2025-07-03Candidate
- bd_430784254ce353aeWashington State AGfiled 2025-07-03Verified
- bd_599c031205796f94Oregon State AGfiled 2025-07-03Verified
- bd_7dbdccbdc6fa01b8Maine State AGfiled 2025-07-03Verified
Show 1 more filing ↓Show fewer ↑up to 5d gap
- bd_5e257872f264f7fdTexas State AGfiled 2025-07-08(5d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-604911
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 3, 2025
- Raw hash
- 848dfe8cba34a94881cd66dbb9024bef4c6341aa7ce47d6780d1ec5311df953e
Reporting entity
- Name
- FINASTRA TECHNOLOGY, INC.norm: finastra technology
- Domain
- finastra.com
Victim entity
- Name
- FINASTRA TECHNOLOGY, INC.norm: finastra technology
- Domain
- finastra.com
Incident
- Discovered
- Nov 7, 2024
- Materiality determined
- —
- Notification sent
- Jun 30, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified law enforcement
Compliance
- Time to disclose
- 34 weeks(238 days from discovery to filing)
- Compliance flags
- CA 60-day late · 235dLeak >180d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Nov 7, 2024→ Notified: Jun 30, 2025235d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.