HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
FINASTRA USA CORPORATION
bd_d132e026415d4128 · schema v1 · pii pii-v1
Full breach record for FINASTRA USA CORPORATION →Finastra notified the New Hampshire Attorney General of a cybersecurity incident involving its Secure File Transfer Platform (Aspera). An unauthorized third party accessed the platform between October 31 and November 8, 2024, obtaining files containing names and Social Security numbers affecting 281 NH residents. Finastra discovered the incident on November 7, 2024, engaged law enforcement (FBI) and forensic investigators, and is offering 24 months of credit monitoring. The risk to individuals is assessed as low.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_4ed6dc4c5a846602Vermont State AGfiled 2025-07-03Verified
- bd_55c58c38375cc5dbMontana State AGfiled 2025-07-03Candidate
- bd_afaf827ed8c3c946South Carolina State AGfiled 2025-07-03Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/finastra-20250703.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 3, 2025
- Raw hash
- 31ed8e01686a72cc81c1aa0de008a8fd264444f6a5eff7c3e44f76988345ff44
Reporting entity
- Name
- Norton Rose Fulbright US LLPnorm: norton rose fulbright us
Victim entity
- Name
- FINASTRA USA CORPORATIONnorm: finastra usa
Incident
- Discovered
- Nov 7, 2024
- Materiality determined
- —
- Notification sent
- Jul 3, 2025
- Affected individuals
- 281
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General's Office
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 34 weeks(238 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.