Finastra, which supplies financial technology to banks, reported unauthorised access between 31 October and 8 November 2024 to a platform it used for customer and technical support. Files containing personal data were obtained. The company subsequently reported that 888,627 people were affected, with social security numbers among the exposed fields.
A Support Platform Is A Data Store
Support systems accumulate whatever customers attach to tickets. Nobody plans for that; it is what happens when a bank sends a file to explain a problem.
The platform is then classified as a support tool rather than as a repository of customer records, and secured accordingly. The Metabase compromise in 2026 is the same misclassification applied to an analytics product.
Two Steps From The Person Affected
Finastra’s customers are banks. The 888,627 people are those banks’ customers, who have no relationship with Finastra and mostly will not have heard the name.
A nine-day window produced nearly 900,000 affected individuals, which is what happens when the breached party sits behind institutions rather than in front of people.
Compiled from the company’s notifications and public reporting, listed below. The affected banks are not enumerated in the disclosure. Corrections: corrections@forensicpost.com.