HackingStolen CredentialsTargetedIDENTITY_BASICLowContained
FINASTRA USA CORPORATION
bd_afaf827ed8c3c946 · schema v1 · pii pii-v1
Full breach record for FINASTRA USA CORPORATION →Finastra reported a cybersecurity incident where an unauthorized third party accessed a Secure File Transfer Platform (SFTP) between Oct 31 and Nov 8, 2024. The incident impacted customer personal information (names). Finastra engaged cybersecurity firms and law enforcement (FBI). 169 Rhode Island residents were explicitly identified as affected; the notice is filed in South Carolina. Remediation included enhanced security measures and offering 24 months of Experian IdentityWorks.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_4ed6dc4c5a846602Vermont State AGfiled 2025-07-03Verified
- bd_55c58c38375cc5dbMontana State AGfiled 2025-07-03Candidate
- bd_d132e026415d4128New Hampshire State AGfiled 2025-07-03Verified
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Security%20Breach%20Notices/2025/Consumer%20Notice%207.3.2025.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 3, 2025
- Raw hash
- 7c5868f6eb6d7c9ba15feaf73803f0342617578c78f01a2ef1c8a02a64419138
Reporting entity
- Name
- FINASTRA USA CORPORATIONnorm: finastra usa
Victim entity
- Name
- FINASTRA USA CORPORATIONnorm: finastra usa
Incident
- Discovered
- Nov 7, 2024
- Materiality determined
- —
- Notification sent
- Jun 30, 2025
- Affected individuals
- 169
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- reported the incident to, and is working closely with, law enforcement authorities, including the FBI
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 34 weeks(238 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.