The Containment Era is here. →Explore

Industry Category

Banking/Mortgage

Breach intelligence, attack campaigns, and threat reports targeting the Banking/Mortgage sector.

446 threat reports
Page 21 of 38

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Banking/Mortgage Threat Reports

Showing 241252 / 446 reports
ClickFix Campaign 2026: Unveiling the MIMICRAT Malware Threat
Impact· HIGH

ClickFix Campaign 2026: Unveiling the MIMICRAT Malware Threat

In February 2026, a sophisticated cyber campaign known as ClickFix was identified, leveraging compromised legitimate websites to distribute a custom remote access trojan (RAT) named MIMICRAT. The attack initiated through a legitimate Bank Identification Number (BIN) validation service, bincheck.io, which was breached to inject malicious JavaScript. This script redirected users to a fake Cloudflare verification page, prompting them to execute a PowerShell command that ultimately deployed MIMICRAT. The RAT featured capabilities such as Windows token impersonation, SOCKS5 tunneling, and a suite of 22 commands for extensive post-exploitation activities. Victims spanned multiple geographies, including a U.S.-based university and various Chinese-speaking users, indicating broad opportunistic targeting. This incident underscores the evolving nature of cyber threats, where attackers exploit trusted websites to deliver sophisticated malware. The use of multi-stage PowerShell scripts and the deployment of custom RATs like MIMICRAT highlight the increasing complexity of attack vectors. Organizations must remain vigilant, ensuring robust security measures are in place to detect and mitigate such advanced threats.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Abu Dhabi Finance Week 2026 Data Breach: A Cloud Misconfiguration Exposes VIP Passport Details
Impact· HIGH

Abu Dhabi Finance Week 2026 Data Breach: A Cloud Misconfiguration Exposes VIP Passport Details

In early February 2026, Abu Dhabi Finance Week (ADFW) experienced a significant data breach due to a misconfigured cloud storage environment managed by a third-party vendor. This misconfiguration exposed scans of over 700 passports and identity cards belonging to high-profile attendees, including former British Prime Minister David Cameron and U.S. investor Anthony Scaramucci. The breach was discovered by cybersecurity researcher Roni Suchowski, who found that the sensitive documents were publicly accessible without password protection. Upon notification, ADFW promptly secured the environment and stated that access activity was limited to the researcher who identified the issue. The incident underscores the critical importance of securing cloud storage configurations to prevent unauthorized access to sensitive information. ([techradar.com](https://www.techradar.com/pro/security/abu-dhabi-finance-summit-exposes-personal-data-passport-info-of-hundreds-of-major-global-figures?utm_source=openai)) This breach highlights the ongoing risks associated with cloud misconfigurations, which continue to be a leading cause of data exposure. As organizations increasingly rely on cloud services, ensuring proper configuration and regular security audits is essential to protect sensitive data and maintain trust with stakeholders.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Starkiller Phishing Kit: A New Era of MFA Bypass Attacks
Impact· HIGH

Starkiller Phishing Kit: A New Era of MFA Bypass Attacks

In February 2026, cybersecurity researchers uncovered 'Starkiller,' a sophisticated phishing-as-a-service (PhaaS) platform that enables cybercriminals to bypass multi-factor authentication (MFA) by proxying live login pages. Unlike traditional phishing kits that use static HTML clones, Starkiller employs a headless Chrome browser within a Docker container to relay real-time authentication sessions, capturing credentials, MFA codes, and session tokens as users interact with legitimate sites. This approach allows attackers to harvest sensitive information without raising user suspicion. The platform is distributed on the dark web with a subscription model, offering updates and customer support, thereby lowering the technical barrier for launching credential-stealing campaigns at scale. ([darkreading.com](https://www.darkreading.com/threat-intelligence/starkiller-phishing-kit-mfa/?utm_source=openai)) The emergence of Starkiller highlights a significant escalation in phishing infrastructure, demonstrating a shift towards real-time, session-aware compromises that render traditional detection methods, such as static page analysis and URL blocklisting, less effective. Organizations are urged to adopt behavioral and identity-aware detection strategies, including monitoring for anomalous sign-ins and session token reuse, to mitigate the risks posed by such advanced phishing platforms. ([darkreading.com](https://www.darkreading.com/threat-intelligence/starkiller-phishing-kit-mfa/?utm_source=openai))

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Massiv Android Banking Malware: A New Threat in 2026
Impact· HIGH

Massiv Android Banking Malware: A New Threat in 2026

In early 2026, cybersecurity researchers identified a new Android banking malware named Massiv, which masquerades as IPTV applications to infiltrate devices. Once installed, Massiv employs screen overlays and keylogging to steal sensitive information, including banking credentials, and can remotely control compromised devices. Notably, it targeted the Portuguese government's Chave Móvel Digital app, potentially allowing attackers to bypass KYC verifications and access banking accounts. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/new-massiv-android-banking-malware-poses-as-an-iptv-app/?utm_source=openai)) This incident underscores a growing trend where cybercriminals exploit popular app themes, like IPTV, to distribute malware. The increasing sophistication of such attacks highlights the urgent need for enhanced mobile security measures and user vigilance against downloading apps from unverified sources.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Operation Red Card 2.0: Unveiling Africa's Cybercrime Crackdown
Impact· HIGH

Operation Red Card 2.0: Unveiling Africa's Cybercrime Crackdown

Between December 8, 2025, and January 30, 2026, INTERPOL coordinated Operation Red Card 2.0, leading to the arrest of 651 individuals across 16 African countries. This operation targeted cybercriminal networks involved in investment fraud, mobile money scams, and fraudulent loan applications, resulting in the identification of 1,247 victims and the recovery of over $4.3 million. Authorities also seized 2,341 devices and dismantled 1,442 malicious websites, domains, and servers. Notably, in Nigeria, police dismantled an investment fraud ring and arrested six individuals who had breached a major telecom provider using stolen employee credentials. ([interpol.int](https://www.interpol.int/News-and-Events/News/2026/Major-operation-in-Africa-targeting-online-scams-nets-651-arrests-recovers-USD-4.3-million?utm_source=openai)) This operation underscores the escalating threat of cybercrime in Africa, with online scams and financial frauds becoming increasingly prevalent. The success of Operation Red Card 2.0 highlights the critical need for international collaboration and proactive measures to combat transnational cybercriminal activities effectively.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
ShinyHunters' 2026 Attack: Exploiting OAuth Device Code Flow in Microsoft Entra
Impact· HIGH

ShinyHunters' 2026 Attack: Exploiting OAuth Device Code Flow in Microsoft Entra

In early 2026, the cybercriminal group ShinyHunters orchestrated a sophisticated attack targeting Microsoft Entra accounts. By combining device code phishing with voice phishing (vishing), they exploited the OAuth 2.0 Device Authorization flow. Attackers generated legitimate device codes and, through impersonation of IT staff, convinced employees to enter these codes on authentic Microsoft login pages. This manipulation granted the attackers valid authentication tokens, enabling unauthorized access to victims' accounts and associated Single Sign-On (SSO) applications, including Microsoft 365, Salesforce, and Google Workspace. The breach led to significant data exfiltration and subsequent extortion attempts. This incident underscores a concerning evolution in phishing tactics, moving beyond traditional credential theft to the exploitation of trusted authentication processes. The success of such attacks highlights the pressing need for organizations to adopt phishing-resistant multi-factor authentication (MFA) methods and to enhance employee awareness regarding emerging social engineering techniques.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Massiv Android Trojan Exploits IPTV Apps for Device Takeover Attacks in 2026
Impact· HIGH

Massiv Android Trojan Exploits IPTV Apps for Device Takeover Attacks in 2026

In early 2026, cybersecurity researchers identified a new Android trojan named Massiv, which masquerades as IPTV applications to infiltrate devices. Once installed, Massiv enables attackers to remotely control infected devices, facilitating device takeover attacks that lead to unauthorized financial transactions from victims' banking accounts. The malware employs techniques such as screen streaming, keylogging, SMS interception, and fake overlays to steal sensitive information. Notably, it has targeted applications like Portugal's gov.pt, exploiting digital identity systems to bypass Know Your Customer (KYC) verifications and open fraudulent accounts in victims' names. This incident underscores the evolving tactics of cybercriminals who exploit popular app themes to distribute malware, highlighting the need for heightened vigilance among mobile banking users. The use of IPTV app disguises reflects a broader trend of leveraging entertainment-related applications to deceive users, emphasizing the importance of downloading apps only from trusted sources and maintaining robust security practices.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
INTERPOL's Operation Red Card 2.0: A Major Blow to African Cybercrime Networks
Impact· HIGH

INTERPOL's Operation Red Card 2.0: A Major Blow to African Cybercrime Networks

Between December 8, 2025, and January 30, 2026, INTERPOL coordinated Operation Red Card 2.0, a collaborative effort involving law enforcement agencies from 16 African countries. This operation targeted transnational cybercriminal networks engaged in high-yield investment scams, mobile money fraud, and fraudulent mobile loan applications. The concerted efforts led to the arrest of 651 individuals, the recovery of over $4.3 million, and the dismantling of 1,442 malicious infrastructures, including IPs, domains, and servers. Investigations revealed that these scams were responsible for financial losses exceeding $45 million, affecting 1,247 victims across Africa and beyond. ([interpol.int](https://www.interpol.int/News-and-Events/News/2026/Major-operation-in-Africa-targeting-online-scams-nets-651-arrests-recovers-USD-4.3-million?utm_source=openai)) The success of Operation Red Card 2.0 underscores the escalating threat posed by organized cybercrime syndicates and highlights the critical importance of international collaboration in combating these pervasive threats. The operation also emphasizes the need for continuous vigilance and proactive measures to protect individuals and businesses from evolving cyber fraud schemes.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
PromptSpy: AI-Enhanced Android Malware Redefines Mobile Threats
Impact· MEDIUM

PromptSpy: AI-Enhanced Android Malware Redefines Mobile Threats

In February 2026, cybersecurity researchers identified PromptSpy, the first known Android malware to exploit Google's Gemini AI for persistence. Disguised as a banking app targeting users in Argentina, PromptSpy uses Gemini to analyze on-screen elements and execute gestures that keep it active in the device's recent apps list, preventing easy termination. Beyond persistence, it deploys a VNC module granting attackers remote access to the device, enabling actions like capturing lockscreen data, taking screenshots, and recording screen activity. The malware also employs Android's accessibility services to block uninstallation attempts by overlaying invisible elements on critical buttons. Distribution occurred through dedicated phishing websites impersonating JPMorgan Chase Bank, with evidence suggesting development in a Chinese-speaking environment. ([eset.com](https://www.eset.com/us/about/newsroom/research/eset-research-discovers-promptspy-first-android-threat-using-genai/?utm_source=openai)) This incident underscores the evolving threat landscape where adversaries integrate generative AI into malware, enhancing adaptability across various devices and operating system versions. The use of AI in malware execution flows signifies a shift towards more dynamic and resilient attack methods, posing challenges for traditional detection and mitigation strategies. ([computerweekly.com](https://www.computerweekly.com/news/366639201/PromptSpy-Android-malware-may-exploit-Gemini-AI?utm_source=openai))

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Figure Technology Solutions Data Breach: A 2026 Case Study
Impact· HIGH

Figure Technology Solutions Data Breach: A 2026 Case Study

In January 2026, Figure Technology Solutions, a blockchain-based fintech lender, suffered a data breach exposing the personal information of approximately 967,200 customers. The breach was executed by the cybercriminal group ShinyHunters through a social engineering attack that deceived an employee into granting unauthorized access. The compromised data includes full names, email addresses, phone numbers, physical addresses, and dates of birth. ShinyHunters subsequently published 2.5GB of this data online after Figure declined to meet their ransom demands. This incident underscores the increasing prevalence of social engineering tactics targeting financial institutions, highlighting the critical need for robust employee training and advanced security measures to prevent unauthorized access. Organizations must remain vigilant against such sophisticated attacks to protect sensitive customer information and maintain trust.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Vulnerability in Honeywell CCTV Products Exposes Unauthorized Access Risks
Impact· CRITICAL

Critical Vulnerability in Honeywell CCTV Products Exposes Unauthorized Access Risks

In February 2026, a critical vulnerability (CVE-2026-1670) was discovered in multiple Honeywell CCTV products, allowing unauthenticated attackers to remotely change the 'forgot password' recovery email address. This flaw enables unauthorized access to camera feeds and potential account hijacking. The affected models include I-HIB2PI-UL 2MP IP (version 6.1.22.1216), SMB NDAA MVO-3, PTZ WDR 2MP 32M, and 25M IPC, all running firmware version WDR_2MP_32M_PTZ_v2.0. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/critical-infra-honeywell-cctvs-vulnerable-to-auth-bypass-flaw/?utm_source=openai)) The vulnerability underscores the importance of securing IoT devices, especially those deployed in critical infrastructure. Organizations are advised to minimize network exposure of such devices, isolate them behind firewalls, and use secure remote access methods like updated VPN solutions. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/critical-infra-honeywell-cctvs-vulnerable-to-auth-bypass-flaw/?utm_source=openai))

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Unauthenticated API Vulnerability in Honeywell CCTV Products (CVE-2026-1670)
Impact· CRITICAL

Critical Unauthenticated API Vulnerability in Honeywell CCTV Products (CVE-2026-1670)

In February 2026, a critical vulnerability (CVE-2026-1670) was identified in Honeywell CCTV products, allowing unauthenticated attackers to remotely modify the 'forgot password' recovery email address via an exposed API endpoint. This flaw could lead to unauthorized access to camera feeds and potential network compromise. Affected models include I-HIB2PI-UL 2MP IP (version 6.1.22.1216), SMB NDAA MVO-3 WDR_2MP_32M_PTZ_v2.0, PTZ WDR 2MP 32M WDR_2MP_32M_PTZ_v2.0, and 25M IPC WDR_2MP_32M_PTZ_v2.0. ([cvedetails.com](https://www.cvedetails.com/cve/CVE-2026-1670/?utm_source=openai)) The vulnerability underscores the importance of securing IoT devices, especially in critical infrastructure sectors. Organizations are urged to apply patches promptly and implement robust access controls to mitigate such risks.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports