Finastra, World’s Third Largest Fintech, Hit by Ransomware
.jpg)
London-based Finastra, the world’s third-largest financial services software provider, has been hacked. The fintech giant told customers that affected servers “both in the USA and elsewhere” had been disconnected from the internet while it contains the breach.
In a short statement, the company initially described noticing “potentially anomalous activity”, updating this late Friday to confirm a ransomware attack.
Finastra, formed through the merger of Misys and DH Corp. in June 2017, provides a wide range of software and services across the financial services ecosystem, ranging from retail and investment banking systems through to treasury, payments, cash management, trade, and supply chain finance, among other offerings.
It is owned by a private equity fund. Finastra’s 9,000 customers include 90 of the top 100 banks globally. It employs over 10,000 and has annual revenues of close to $2 billion.
Finastra Hacked: We Do Not Believe Clients’ Networks Were Impacted
Chief Operating Officer Tom Kilroy said: “Earlier today, our teams learned of potentially anomalous activity on our systems. Upon learning of the situation, we engaged an independent, leading forensic firm to investigate the scope of the incident. Out of an abundance of caution and to safeguard our systems, we immediately acted to voluntarily take a number of our servers offline while we continue to investigate.
He added: “At this time, we strongly believe that the incident was the result of a ransomware attack and do not have any evidence that customer or employee data was accessed or exfiltrated, nor do we believe our clients’ networks were impacted. ”
“We are working to resolve the issue as quickly and diligently as possible and to bring our systems back online, as appropriate. While we have an industry-standard security program in place, we are conducting a rigorous review of our systems to ensure that our customer and employee data continues to be safe and secure. We have also informed and are cooperating with the relevant authorities and we are in touch directly with any customers who may be impacted as a result of disrupted service.”
Finastra appears to have earlier been running an unpatched Pulse Secure VPN, which is vulnerable to CVE-2019-11510: a vulnerability in the VPN (previously known as Juniper SSL VPN) which in 2019 was found to have a number of severe security issues that could, when chained together, allow a hacker to write arbitrary files to the host.
(Needless to say, it is unclear at this juncture if that had remained unpatched and was the initial vector for this particular breach. Finastra hasn’t disclosed such details).
An email by Finastra to customers, as reported by Security Boulevard, reads: “Our approach has been to temporarily disconnect from the internet the affected servers, both in the USA and elsewhere, while we work closely with our cybersecurity experts to inspect and ensure the integrity of each server in turn.
In a late Sunday update, Finastra said it was “now able to bring back online the servers which we voluntarily took offline whilst we neutralized the threat.
COO Tom Kilroy added: “We are working with our impacted customers systematically and securely to return to normal operations. Because our solutions each have their own nuanced processes to move from being available to operationally live, each of our products will be back once readiness steps are completed… Thank you for your patience and understanding as we restore our systems. We will provide further information as soon as it is available.”
source cbronline
Industry: Cyber Security

Latest Jobs
-
- Contract (outside) Cyber Incident manager – current SC clearance ESSENTIAL
- United Kingdom
- N/A
-
Contract (outside) Cyber Incident manager – current SC clearance ESSENTIAL Outside IR35 Client facing (Remote UK) with occasional site visit. Must have current Cyber incident response / management experience. Both proactive planning, escalation, coordination and coordinating response. Stakeholder engagement both technical and non technical teams. Prior experience with Technical incident / digital forensics / crisis management. Immediate role.
-
- Tenable Vulnerability Analyst - CONTRACT outside IR35. SC cleared.
- United Kingdom
- N/A
-
6 month rolling contract Outside IR35- immediate start. Threat and Vulnerability Analyst. Tenable.sc experience needed. The ability to deploy agent, configure environments, run active and passive scans, produce reports and prioritise remediation activities based on output Current and ACTIVE SC clearance is required
-
- ForgeRock Consultant
- N/A
- £600 per day
-
ForgeRock Consultant required for 6 Month Contract (with potential to extend) Outside IR35, Must be willing to work Europe hours (GMT+1) This is a remote position, Looking for a lead ForgeRock Technical Consultant with strong experience of ForgeRock to lead the next phase of deployment. Good understanding of ForgeRock Directory Services. · Responsible for the design and implementation of ForgeRock stack · Install and configure ForgeRock stack to meet customer authentication and authorization requirements, · Design and implement OAuth2 protocol using ForgeRock OpenAM, · Design and develop OpenAM custom authentication modules, · Configure ForgeRock stack to protect RESTful API, · Troubleshoot and support ForgeRock IAM stack. · Designed and developed Restful APIs, This is a great project with an expanding ForgeRock Partner, where you will get to work on some high level deployment projects We are looking for someone with the above experience, who is comfortable hitting the ground running and taking on the reins mid project
-
- Network Security Engineer
- Germany
- €550 a day
-
German- based contract opportunity This is an onsite based position, we would need the Network Security engineer to be able to work on the client site 5 days a week Seeking an experienced Network Security Engineer for a leading technology company. Strong expertise in firewall/IPS solutions, proxy solutions, and certificate management is required. Good hands-on experience in networking and web-related technologies necessary. Strong problem-solving skills and the ability to work under pressure are essential. we are looking for a Network Security Engineer with the following experience: · Expertise in Administration, Management & Troubleshooting of Firewall / IPS solutions / Proxy solutions/Certificate Management Solutions · Good Hands-on Experience on security devices (PaloAlto/ /McAfee Proxy/CISCO ISE/Certificate Management) · Good Hands-on Experience in Networking with skills of switching, routing & wireless Technologies · Familiarity with web related technologies (Web applications, Web Services, Service Oriented Architectures) and of network/web related protocol · Configuration of NAT / PAT, firewall policies, profiling, objects, AD-Integration, backup – restore · Knowledge of Subnetting TCP/IP Communication, VLSM Configuration of VLAN VTP · Configuration of Routing Protocols e.g. RIPv1 & v2, OSPF, EIGRP, BGP Knowledge of standard and extended ACL 12 month contract