Desk live·
ForensicPost
Breaches/Finance/File 25-0214

The File-Transfer Product Is the Bank’s Weakest Wall

Western Alliance Bank disclosed a breach affecting around 22,000 people, linked to a zero-day in third-party file-transfer software. It is the third such product to appear in this database.

Constructed geometry · not a chart of case data
TargetWestern Alliance Bank
ActorUnattributed
D. Kennedy10 min readConfidence: high2 sources reviewed

Western Alliance Bank disclosed a breach in early 2025 affecting approximately 22,000 people, arising from a zero-day vulnerability in third-party managed file-transfer software.

This Product Category Keeps Failing

Managed file transfer is the least glamorous software an enterprise runs and among the most consequential. Its purpose is to move bulk data between organisations, which means it must be reachable from outside, must authenticate external parties, and by design holds exactly the files an organisation considers too large or too sensitive for email.

Internet-facing, authentication-heavy, and sitting on the highest-value data in the estate. A mass-exploitation campaign against one of these products yields a portfolio of victims from a single vulnerability — the pattern filed at 26-0730 and 25-0930.

Twenty-Two Thousand Is A Small Number And That Is The Point

Against the eight-figure files elsewhere in this corpus, 22,000 barely registers. It registers here because of what a bank’s 22,000 records contain: identity documents, account details, income evidence, and in many cases the supporting material submitted for a lending decision.

This desk’s consistent position, from 26-0227 to 25-0603, is that record counts are a poor proxy for harm. A file-transfer server at a bank is where the densest records in the institution briefly sit.

Zero-Day Does Not Mean Blameless

A previously unknown vulnerability genuinely limits what a customer organisation could have done to prevent exploitation. It does not settle every question.

Why was the product internet-facing rather than behind a broker? Why did files remain on it after transfer rather than being removed on completion? Would the bank have detected the exfiltration if it had not been told? Those are architecture and retention decisions the bank owned, and they determine how much a zero-day is worth to whoever finds it.

How we reported this

Compiled from public reporting, listed below. The specific product and vulnerability are as reported; we have not independently verified the exploitation route. Corrections: corrections@forensicpost.com.

Sources
  1. Top 5 banking data breaches of 2025Cybersecurity Insiders
  2. Data breach in financial institutions 2025: a CISO’s guideDeepStrike
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary