Back to Insights Data Breaches

Lessons Learned from the Security Incident at Major Banking Software Provider Finastra

Security Breach and Its Impact: Vulnerabilities in Sensitive Financial Systems

On November 7, 2024, Finastra, a financial software provider serving thousands of financial institutions, experienced a severe cyberattack. The attackers utilized stolen credentials to access the company’s Secure File Transfer Protocol (SFTP) system and exfiltrated sensitive information. They claimed to be in possession of 400GB of stolen data, and the impact of the attack on the banking industry was extensive.

The breach exposed critical vulnerabilities in the security posture of Finastra, which provides services to approximately 45 of the world’s 50 largest banks. Such vulnerabilities can lead to sensitive data leaks and difficulties in mitigating subsequent attacks on other institutions.

Primary Factors Behind the Breach: Defense Based on Information Security Principles

Experts argue that password-based access alone is insufficient. Multi-Factor Authentication (MFA) must be implemented alongside continuous monitoring of suspicious activities within information systems. This is essential for identifying threats in real-time and preventing significant data leaks.

Data protection should begin with system design based on structural security. Organizations must utilize modern technologies, such as distributed platforms and data segmentation, ensuring each client remains isolated and their information is better protected. It is particularly vital to implement the principle of Least Privilege—a critical component in securing sensitive file transfer systems. This principle requires the organization to grant users access only to the resources necessary for their role, and only for the duration required.

Hardened and Intelligent Systems: The Importance of Advanced Defenses

This incident underscores the need for distributed systems with diverse defensive layers to prevent damage during an attack. Experts recommend integrating automated monitoring systems that respond rapidly to suspicious activities, such as SIEM (Security Information and Event Management) and Data Loss Prevention (DLP) systems. These systems enable real-time threat detection and neutralize actions before they cause severe damage.

In parallel with system upgrades, investment in employee training is essential. Cyberattacks often originate from human error; therefore, it is crucial to instill knowledge and maintain ongoing management of security measures within the organization.

Recommendations from IPV Security Information Security Experts:

  • Mandatory Multi-Factor Authentication (MFA): Use advanced authentication for all system access.
  • Advanced Control and Monitoring: Implement real-time monitoring systems and alerts for suspicious activity.
  • Encryption and Data Security: Secure data using high-level encryption and manage strict access permissions.
  • Distributed Systems: Ensure data separation between clients to prevent data leakage in future attacks.
  • Information Security Process Management: Ensure the organization implements organized security management processes and regularly audits their execution. This can be achieved through dedicated platforms, such as CISOteria, which enable efficient documentation, control, and enforcement.

For more lessons and insights, see the post by the CEO of IPV Security / CISOteria here.

In conclusion, the Finastra breach serves as a painful reminder of the importance of investing in advanced information security. Financial institutions must adopt innovative solutions to ensure protection against similar threats. Defense begins with infrastructure improvement and the implementation of an organizational security culture.

For further information: [Link to Kiteworks article]

Continue the Conversation

Facing a cybersecurity challenge? Let's talk about how a managed program can strengthen your resilience.

Start a conversation