Desk live·
ForensicPost
Breaches/Finance/File 24-1120

Finastra Breach of a Support File Platform Reached 888,627 People

Unauthorised access between 31 October and 8 November 2024 took files from a platform Finastra used for customer and technical support. The fintech supplier serves banks, so the affected people were its customers’ customers.

Constructed geometry · not a chart of case data
JurisdictionUnited KingdomLondonthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetFinastra
ActorUnattributed
S. Rosler8 min readConfidence: high2 sources reviewed

Finastra, which supplies financial technology to banks, reported unauthorised access between 31 October and 8 November 2024 to a platform it used for customer and technical support. Files containing personal data were obtained. The company subsequently reported that 888,627 people were affected, with social security numbers among the exposed fields.

A Support Platform Is A Data Store

Support systems accumulate whatever customers attach to tickets. Nobody plans for that; it is what happens when a bank sends a file to explain a problem.

The platform is then classified as a support tool rather than as a repository of customer records, and secured accordingly. The Metabase compromise in 2026 is the same misclassification applied to an analytics product.

Two Steps From The Person Affected

Finastra’s customers are banks. The 888,627 people are those banks’ customers, who have no relationship with Finastra and mostly will not have heard the name.

A nine-day window produced nearly 900,000 affected individuals, which is what happens when the breached party sits behind institutions rather than in front of people.

How we reported this

Compiled from the company’s notifications and public reporting, listed below. The affected banks are not enumerated in the disclosure. Corrections: corrections@forensicpost.com.

Sources
  1. Fintech Giant Finastra Investigating Data BreachKrebs on Security
  2. Finastra Announces Data Breach Following Discovery of November 2024 CyberattackJD Supra
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary