TechCrunch News 2024年11月20日
Fintech giant Finastra confirms it’s investigating a data breach
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

Finastra公司内部文件传输平台疑遭数据泄露,黑客称在论坛售卖相关文件。公司确认检测到可疑活动,正调查此事,已向客户通报,在分析受影响数据以确定具体客户,同时评估产品情况,初步证据表明是凭证遭泄露。

🎯Finastra公司内部文件传输平台出现可疑活动

💻黑客在论坛售卖据称属于Finastra客户的文件

📋Finastra正调查并分析受影响数据及产品情况

🔑初步证据显示凭证遭泄露,原因待查

Finastra, a London-based financial software company that serves most of the world’s top banks, has confirmed it’s investigating a data breach after a hacker claimed a compromise of the company’s internal file-transfer platform. 

In a statement given to TechCrunch, Finastra spokesperson Sofia Romano confirmed the fintech giant detected what it calls “suspicious activity” related to an “internally hosted Secure File Transfer Platform (SFTP)” on November 7. 

News of the breach, first reported by cybersecurity journalist Brian Krebs, comes after someone claimed on a known cybercrime forum to be selling stolen files allegedly belonging to Finastra’s largest banking clients. In a since-deleted forum posting, the hacker said they were in possession of 400 gigabytes of data from Finastra, including client files and internal documents. 

In an incident disclosure shared with customers, obtained by Krebs, Finastra confirmed data was exfiltrated from its systems. Finastra’s spokesperson, who declined to share a copy of the disclosure with TechCrunch, said the company first communicated the incident to customers on November 8 and has been “keeping them informed about what we do and do not yet know about the data that was posted.” 

Finastra declined to name the compromised file-transfer platform, but the data seller claims the stolen data from Finastra’s network was sourced from IBM Aspera, a file-transfer software that allows organizations to move large files and data sets over the internet.

When asked by TechCrunch, Finastra would not say how many customers are affected or what types of data were accessed in the breach.

“We are analyzing affected data to determine what specific customers were affected, while simultaneously assessing and communicating which of our products are not dependent on the specific version of the SFTP platform that was compromised,” Finastra’s spokesperson Romano said in an emailed statement. “The impacted SFTP platform is not used by all customers… so we are working as quickly as possible to rule out affected customers.”

Finastra added that the company continues to investigate the root cause of the data breach, but said that “initial evidence points to credentials that were compromised.” This suggests the organization was compromised through the theft of someone’s username and password. It’s not yet known if the system was protected with multi-factor authentication, which can prevent some credential theft attacks.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

Finastra 数据泄露 文件传输 调查
相关文章