Finastra, a company that provides financial software solutions to large financial institutions, has notified individuals about a cybersecurity incident that affected some of their personal information. According to the notice, an unauthorized third party accessed Finastra’s Secure File Transfer Platform (SFTP) — a system the company uses to provide technical and customer support related to certain Finastra products — at various times between October 31, 2024 and November 8, 2024. Finastra identified the incident on November 7, 2024, launched an investigation with outside cybersecurity firms, and notified law enforcement, including the FBI. The company states it has confirmed the unauthorized party no longer has access to the data and has no indication the files were further copied, retained, or shared.
The notice was sent to people whose personal information was found in the files taken from the SFTP during a review Finastra conducted after the incident. The letter confirms that 169 Rhode Island residents were affected, but it does not give a total nationwide figure, so the full scope of individuals impacted isn’t clear from the notice text alone.
What information was exposed?
- Name
- Additional personal information — the letter references further data elements but does not spell out what type in the text provided to us, so we can’t say more specifically what else was included in your file
As a precaution, Finastra is offering a complimentary 24-month membership to Experian IdentityWorks, which provides identity monitoring and identity restoration support at no cost to you. To activate it, enroll by October 31, 2025 at https://www.experianidworks.com/credit using the activation code included in your mailed letter.
What should you do now?
- Enroll in the free Experian IdentityWorks membership before the October 31, 2025 deadline using the activation code from your letter.
- Review your credit card and bank statements regularly for any charges or activity you don’t recognize.
- Request your free annual credit report from annualcreditreport.com or by calling 877-322-8228 to check for accounts you didn’t open.
- Consider placing a free fraud alert or security freeze with Equifax, Experian, and TransUnion if you want an extra layer of protection against new accounts being opened in your name.
- Since it’s unclear exactly what personal details were in the exposed files, consider signing up for a service like Aura or LifeLock, which can alert you if your information appears elsewhere.
- Keep the letter and any correspondence about this incident in case you need it later to prove eligibility for identity restoration services.
If you have questions, Finastra can be reached at 833-918-5929, Monday through Friday, between 8am and 8pm CST.