Validated Containment Architectures are here. →Explore

Industry Category

Banking/Mortgage

Breach intelligence, attack campaigns, and threat reports targeting the Banking/Mortgage sector.

470 threat reports
Page 1 of 40

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Banking/Mortgage Threat Reports

Showing 112 / 470 reports
Kaspersky's Q2 2026 Mobile Threat Analysis
Impact· MEDIUM

Kaspersky's Q2 2026 Mobile Threat Analysis

In Q2 2026, Kaspersky's Security Network reported a significant decline in mobile device attacks, blocking over 1.99 million incidents involving malware, adware, or unwanted software. Notably, the Trojan-Banker category emerged as the predominant mobile malware threat, accounting for 30.77% of detected applications. Additionally, more than 304,000 malicious installation packages were identified, including 93,574 related to mobile banking Trojans and 570 associated with mobile ransomware Trojans. This period also saw the discovery of multiple malicious loaders on Google Play, such as a trojanized PDF reader app deploying the Anatsa banking malware, highlighting the evolving tactics of threat actors in targeting mobile platforms. The continued prevalence of mobile banking Trojans underscores the critical need for enhanced security measures and user vigilance, especially as attackers refine their methods to infiltrate trusted app stores and exploit user trust.

4 hours ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Passkey Vulnerabilities Uncovered: Bypassing Phishing-Resistant MFA
Impact· MEDIUM

Critical Passkey Vulnerabilities Uncovered: Bypassing Phishing-Resistant MFA

In August 2026, researchers identified multiple vulnerabilities in passkey authentication systems, revealing methods to bypass phishing-resistant multi-factor authentication (MFA) without compromising underlying cryptographic protocols. These attacks exploited weaknesses in Windows Event Logging Service (CVE-2026-34348), Google Password Manager's synced passkeys, and Windows Hello for Business, allowing unauthorized access through replayed authentication materials and malware manipulation. The incidents underscore the necessity for organizations to reassess the security of passkey implementations and enhance endpoint protections to mitigate such sophisticated threats. As passkeys gain popularity as a passwordless authentication method, these findings highlight the importance of continuous vigilance and adaptation to emerging attack vectors targeting authentication mechanisms.

12 hours ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Real Emails, Hijacked Payments: Analyzing Two H1 2026 Attack Chains
Impact· HIGH

Real Emails, Hijacked Payments: Analyzing Two H1 2026 Attack Chains

In the first half of 2026, cybercriminals executed sophisticated campaigns exploiting trusted systems to deliver malware. One campaign involved compromised corporate email accounts sending legitimate-looking business emails with malicious attachments, leading to banking malware that manipulated proxy settings and browser extensions to intercept financial transactions. Another campaign utilized a Rust-based clipboard hijacker that monitored and replaced cryptocurrency wallet addresses copied to the clipboard, redirecting funds to attacker-controlled wallets. These incidents highlight a shift towards attacks that exploit existing trust mechanisms, making detection and prevention more challenging. Organizations must enhance their security measures to monitor for unusual activities within trusted workflows and educate users on verifying transaction details to mitigate such threats.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
TeamPCP's Cyber Evolution: From Redis Exploits to Supply Chain Attacks
Impact· CRITICAL

TeamPCP's Cyber Evolution: From Redis Exploits to Supply Chain Attacks

TeamPCP, a threat actor active since at least 2020, has been implicated in a series of cyberattacks targeting internet-facing infrastructure and software supply chains. Initial activities involved compromising exposed Redis servers to deploy cryptocurrency miners, evolving into more sophisticated campaigns like ShadowRay 2.0, which hijacked AI infrastructure into self-propagating botnets. By 2026, TeamPCP expanded into high-profile supply chain attacks, injecting malicious code into popular open-source libraries through GitHub Actions and token theft, leading to widespread developer system infections. This escalation underscores the increasing threat posed by supply chain attacks, highlighting the need for enhanced security measures in software development and deployment processes. Organizations must remain vigilant against such evolving tactics to protect their infrastructure and data.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
AI Unveils New HTTP Desynchronization Techniques and Apache Zero-Day Vulnerability
Impact· MEDIUM

AI Unveils New HTTP Desynchronization Techniques and Apache Zero-Day Vulnerability

In August 2026, PortSwigger's AI-assisted research system, HTTP Terminator, identified novel HTTP desynchronization techniques and uncovered a zero-day vulnerability in Apache Traffic Server, designated as CVE-2026-63078. The system analyzed 30,000 websites, revealing approximately 700 vulnerable targets, including financial institutions, government infrastructure, and security products. Key findings include new desynchronization triggers, a dual-matching Content-Length pattern, and a 'dangling-byte' technique enhancing the reliability of response queue poisoning (RQP) attacks. These vulnerabilities could allow attackers to intercept sensitive user data, such as session cookies and API keys. The discovery underscores the evolving threat landscape, highlighting the increasing sophistication of AI-driven security research and the critical need for organizations to proactively address emerging vulnerabilities to safeguard sensitive information and maintain trust.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
AI-Driven Fraud: A New Era of Global Crime Syndicates in 2026
Impact· HIGH

AI-Driven Fraud: A New Era of Global Crime Syndicates in 2026

In 2026, global crime syndicates have significantly escalated their fraudulent activities by leveraging advanced artificial intelligence technologies. These groups employ AI-driven tools such as voice cloning, deepfake real-time video overlays, large language model (LLM)-driven persona management, and automated translation to create highly convincing synthetic identities. This sophisticated approach enables them to bypass traditional 'know your customer' (KYC) protocols and other identity verification methods, leading to substantial financial losses across various sectors, including financial institutions, online retailers, and cryptocurrency exchanges. The urgency to address this issue is underscored by a 2026 INTERPOL report, which highlights a 54% increase in fraud-related campaigns since 2024, attributing this surge to AI enhancements. The report also notes that AI-enhanced fraud is 4.5 times more profitable than traditional methods, emphasizing the need for immediate and coordinated global action to combat this evolving threat. ([interpol.int](https://www.interpol.int/en/News-and-Events/News/2026/INTERPOL-report-warns-of-increasingly-sophisticated-global-financial-fraud-threat?utm_source=openai))

4 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Attackers Leverage SQL Injection to Deploy 'khunt' Toolkit in Oracle Database
Impact· HIGH

Attackers Leverage SQL Injection to Deploy 'khunt' Toolkit in Oracle Database

In July 2026, attackers exploited a SQL injection vulnerability in a public-facing web application's autocomplete search field to gain unauthorized access to an organization's Oracle database. Utilizing the database's embedded Java Virtual Machine, they compiled and executed Java code within the database, achieving SYSTEM-level access on the underlying Windows server. This method allowed the deployment of a post-exploitation toolkit, 'khunt,' without writing executables to disk, effectively transforming the database into an attack platform. The incident underscores the critical need for robust input validation, parameterized queries, and strict privilege management to prevent such sophisticated attacks. The 'khunt' toolkit's deployment highlights a resurgence in advanced SQL injection techniques, emphasizing the importance of comprehensive security measures in database management systems. Organizations must remain vigilant against evolving threats that exploit inherent database functionalities for malicious purposes.

4 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Apple iCloud Private Relay Vulnerability Exposes Real IP Addresses
Impact· MEDIUM

Apple iCloud Private Relay Vulnerability Exposes Real IP Addresses

In August 2026, cybersecurity researchers Talal Haj Bakry and Tommy Mysk disclosed a vulnerability in Apple's iCloud Private Relay, a feature designed to enhance user privacy by routing Safari web traffic through dual relays. The flaw resides in WebKit's handling of DNS prefetching, WebAuthn Related Origin Requests, and WebTransport, which can bypass configured proxies and expose users' real IP addresses. This issue affects Safari and all third-party browsers on iOS, iPadOS, and macOS that rely on WebKit's proxy configuration APIs. As a result, users' actual IP addresses can be leaked, undermining the privacy protections offered by iCloud Private Relay. This vulnerability is particularly concerning given the widespread use of WebKit across Apple's ecosystem and its integration into various browsers. The exposure of real IP addresses can lead to targeted attacks, tracking, and a compromise of user anonymity. Organizations and individuals relying on iCloud Private Relay for privacy should be aware of this flaw and consider additional protective measures until a patch is released.

4 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Snowflake 2024 Data Breach: A Wake-Up Call for Cloud Security
Impact· MEDIUM

Snowflake 2024 Data Breach: A Wake-Up Call for Cloud Security

In mid-2024, a significant cybersecurity incident unfolded involving unauthorized access to over 165 customer environments hosted on Snowflake Inc.'s cloud platform. Threat actors, notably including Connor Moucka, exploited stolen credentials—often lacking multi-factor authentication—to infiltrate these environments. High-profile victims such as AT&T, Ticketmaster, and Santander Bank suffered extensive data theft, leading to substantial financial losses and reputational damage. The attackers utilized the stolen data for extortion, demanding ransoms to prevent public disclosure. ([en.wikipedia.org](https://en.wikipedia.org/wiki/Snowflake_data_breach?utm_source=openai)) This breach underscores the critical importance of robust access controls and the implementation of multi-factor authentication (MFA) in cloud environments. The incident serves as a stark reminder of the vulnerabilities associated with single-factor authentication and the necessity for organizations to enforce stringent security measures to protect sensitive data. ([techtarget.com](https://www.techtarget.com/searchsecurity/news/366587555/Snowflake-No-evidence-of-platform-breach?utm_source=openai))

4 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
COLDCARD Phishing Attack Leads to Remote Access Installation
Impact· CRITICAL

COLDCARD Phishing Attack Leads to Remote Access Installation

In August 2026, a sophisticated phishing campaign targeted COLDCARD hardware wallet users by impersonating official communications. Attackers sent emails claiming a security audit was necessary due to recent vulnerabilities, directing recipients to a fraudulent website to download a diagnostic tool. This tool installed ScreenConnect remote access software, granting attackers control over victims' computers, potentially leading to data theft or further malware deployment. This incident underscores the evolving nature of phishing attacks, which are becoming more targeted and convincing. The exploitation of recent security concerns to deceive users highlights the critical need for continuous vigilance and education on recognizing and avoiding such threats.

5 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Hackers Deploy 'khunt' Toolkit via SQL Injection in Oracle Database
Impact· HIGH

Hackers Deploy 'khunt' Toolkit via SQL Injection in Oracle Database

In July 2026, attackers exploited a SQL injection vulnerability in a public-facing Java application running Apache Tomcat to gain unauthorized access to an Oracle database. They installed the 'khunt' post-exploitation toolkit directly within the database as a Java object, enabling them to execute system commands, steal credentials, and manage files. This method allowed the attackers to operate with SYSTEM-level permissions on the Windows server hosting the database, facilitating potential data exfiltration and further network compromise. This incident underscores the critical need for organizations to sanitize all user-supplied input and restrict database account privileges, especially in public-facing applications. The use of embedded Java Virtual Machines within databases as a vector for post-exploitation activities highlights an emerging threat landscape that security teams must address proactively.

5 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Snowflake Data Breach 2024: A Wake-Up Call for Cloud Security
Impact· CRITICAL

Snowflake Data Breach 2024: A Wake-Up Call for Cloud Security

Between February and October 2024, cybercriminals exploited stolen credentials to access Snowflake customer accounts lacking multi-factor authentication (MFA). This led to unauthorized access to sensitive data from at least 165 organizations, including AT&T, Ticketmaster, and Santander. The attackers, notably Connor Riley Moucka and John Erin Binns, utilized infostealer malware to harvest login information, resulting in the theft of terabytes of data and extortion of millions of dollars from affected companies. The incident underscores the critical importance of implementing robust security measures, such as MFA, to protect cloud-based data. As cloud services become increasingly integral to business operations, organizations must prioritize stringent access controls and continuous monitoring to mitigate the risk of similar breaches.

5 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports