The Containment Era is here. →Explore

Industry Category

Banking/Mortgage

Breach intelligence, attack campaigns, and threat reports targeting the Banking/Mortgage sector.

447 threat reports
Page 23 of 38

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Banking/Mortgage Threat Reports

Showing 265276 / 447 reports
Kingdom Market Darknet Takedown: How Law Enforcement Disrupted a Global Cybercrime Hub (2021–2023)
Impact· high

Kingdom Market Darknet Takedown: How Law Enforcement Disrupted a Global Cybercrime Hub (2021–2023)

Between March 2021 and December 2023, the Kingdom Market darknet platform operated as a large-scale cybercrime marketplace facilitating the sale of narcotics, cybercrime tools, stolen personal information, and fraudulent documents. Slovakian national Alan Bill, also known as "Vend0r" or "KingdomOfficial," admitted in January 2026 to administering the illicit platform, handling site infrastructure, and orchestrating anonymous cryptocurrency payments. The marketplace boasted over 42,000 illegal listings and tens of thousands of customer accounts. Its takedown culminated in coordinated law enforcement actions, domain seizures, and Bill's arrest in the U.S., where evidence linked him directly to site operations. This case highlights the persistent challenge of global, darknet-enabled cybercrime, the evolution of anonymous payment technologies, and the international scope of enforcement efforts. Cybercrime marketplaces remain a top concern for regulators and enterprises alike, with attackers rapidly adapting business models and operational security to evade detection.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
FBI Takedown of RAMP: Ransomware's Last Open Forum Seized in 2026
Impact· medium

FBI Takedown of RAMP: Ransomware's Last Open Forum Seized in 2026

In January 2026, the FBI seized control of the notorious Russian-speaking RAMP cybercrime forum, widely used by ransomware gangs to promote operations, recruit affiliates, and trade access to compromised networks. Both its Tor and clearnet domains were confiscated, and a seizure notice was displayed in coordination with U.S. law enforcement agencies. As one of the last prominent ransomware-friendly forums, RAMP had become a hub for multiple groups, facilitated by threat actor Mikhail Matveev (aka Orange/Wazawaka). The FBI now possesses potentially incriminating data on user identities, logins, and private communications, increasing the risk of arrests for those with poor operational security. This takedown reflects a broader law enforcement crackdown on cybercrime infrastructure supporting ransomware attacks. The RAMP seizure is significant amid heightened regulatory and industry focus on disrupting the ransomware ecosystem and demonstrates the ongoing risk of exposure for those operating in or near dark web forums.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
SafePay 2025: Ransomware Double-Extortion Escalates Against SMBs
Impact· high

SafePay 2025: Ransomware Double-Extortion Escalates Against SMBs

In late 2024 and throughout 2025, the SafePay ransomware group rapidly escalated its operations, launching a string of highly targeted double-extortion attacks against small and mid-sized businesses (SMBs), particularly in highly regulated markets such as the US and Germany. SafePay affiliates compromised victim networks via common attack vectors, exfiltrated sensitive data, and deployed ransomware to encrypt crucial assets. Victims predominantly included service-based companies lacking the resilience to handle operational downtime or public exposure. Attackers leveraged leak sites and aggressive negotiation tactics, threatening regulatory action, legal liability, and reputational damage to compel payment, creating severe business, legal, and financial impacts. This incident exemplifies a broader trend in ransomware: extortion is no longer just about encrypting files, but about exploiting regulatory frameworks and psychological leverage. The rise of fragmented ransomware ecosystems and pressure-centric extortion highlights the need for organizations to move beyond classic recovery strategies and address emerging risks such as data exposure, legal repercussions, and reputational harm.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Stanley Malware: Chrome Web Store Defense Bypassed for Phishing – 2026 Breach Analysis
Impact· medium

Stanley Malware: Chrome Web Store Defense Bypassed for Phishing – 2026 Breach Analysis

In January 2026, security researchers uncovered 'Stanley', a Malware-as-a-Service (MaaS) operation specializing in the distribution of phishing Chrome extensions designed to bypass Google’s official Chrome Web Store review process. Marketed on underground forums, Stanley provides subscribers with malicious browser extensions capable of injecting full-page phishing iframes, silently installing on Chrome, Edge, and Brave, and maintaining persistent command-and-control communication. The malware enables attackers to manipulate users’ browsing sessions while masking the true origin, collect sensitive credentials, and target victims based on IP and geography. This poses a significant risk of data theft and compromise within organizations that rely on browser-based workflows. This incident underscores the growing trend of abusing trusted extension platforms to deliver targeted phishing and credential theft at scale. The ability for criminal actors to bypass established security vetting processes presents urgent challenges for enterprise security teams and highlights the broader concern over supply chain weakness in browser ecosystems.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
US ATM Jackpotting: Tren de Aragua's Ploutus Malware Heist Exposed
Impact· high

US ATM Jackpotting: Tren de Aragua's Ploutus Malware Heist Exposed

In late 2025 and early 2026, US law enforcement charged 31 additional suspects in a major campaign of ATM jackpotting attacks attributed to the Venezuelan criminal gang Tren de Aragua. The attackers breached numerous ATMs across the United States, installing Ploutus malware by physically accessing internal components and deploying malware to force the machines to dispense large quantities of cash. The sophisticated attacks leveraged swapped hard drives or infected USB devices and allowed the perpetrators to launder stolen funds internationally, inflicting millions of dollars in losses on banks and credit unions. To date, over 87 individuals have been charged in this transnational criminal scheme. This incident highlights the evolving tactics of financially motivated threat groups combining physical access and technical expertise. The designation of Tren de Aragua as a Foreign Terrorist Organization underscores law enforcement’s recognition of cyber-enabled financial crime as a national security threat and signals intensified global scrutiny on such operations.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
How 2024 Romance Scams Use WhatsApp Social Engineering: An Inside Look
Impact· medium

How 2024 Romance Scams Use WhatsApp Social Engineering: An Inside Look

In early 2024, security researchers investigated the initial phases of romance scams conducted over WhatsApp, where attackers use social engineering tactics to engage targets. Scammers made initial contact using 'wrong number' messages, then rapidly built rapport through flattering responses and fabricated personal stories. Over the span of several weeks, operators established credibility by sharing career details, transitioning conversations to new phone numbers, and sharing lifestyle photos to lay groundwork for future financial scams. The observed campaigns were early-stage but designed to emotionally manipulate victims for eventual financial exploitation. This incident spotlights the refined playbooks, multi-operator approaches, and psychological grooming now typical in romance scams. With surges in digital-first communication and persistent threat actor innovation, such social engineering exploits pose a significant and evolving risk to individuals and businesses alike.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(medium)
Read Report
US ATM Jackpotting 2024: Venezuelan Hackers Steal Hundreds of Thousands Using Malware
Impact· high

US ATM Jackpotting 2024: Venezuelan Hackers Steal Hundreds of Thousands Using Malware

In early 2024, federal prosecutors in South Carolina uncovered a sophisticated ATM jackpotting scheme perpetrated by two Venezuelan nationals. Employing financial malware, the attackers compromised U.S. bank ATM networks and extracted hundreds of thousands of dollars in cash. The scheme involved the unauthorized installation of malware on ATM machines, which enabled the criminals to override withdrawal limits and rapidly dispense large sums of money. Following their arrest, both individuals were convicted and will be deported after serving their sentences, highlighting significant vulnerabilities in ATM security and network segmentation. This incident reflects a growing trend in financial crime, where cybercriminals target banking infrastructure using advanced malware and physical access techniques. Regulators and banks are increasingly focused on hardening ATM systems and tightening controls to prevent similar attacks as cyber-enabled fraud remains a persistent and evolving threat.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Kimwolf Botnet: How Residential Proxy Infections Fueled a 2025 IoT Crisis
Impact· high

Kimwolf Botnet: How Residential Proxy Infections Fueled a 2025 IoT Crisis

In late 2025, the Kimwolf botnet rapidly infected over 2 million IoT devices—primarily unofficial Android TV streaming boxes—by exploiting insecure residential proxy networks, notably those operated by IPIDEA. Kimwolf used these proxies to scan and compromise additional devices on local networks, enabling attackers to conscript them for distributed denial-of-service (DDoS) attacks and other forms of malicious activity, such as ad fraud and data scraping. Investigations by Infoblox and other security firms found Kimwolf infections active across diverse industry sectors worldwide, including healthcare, finance, utilities, and notably, dozens of sensitive government networks. The Kimwolf incident highlights persistent weaknesses in IoT device security, the risks of unmanaged devices on enterprise networks, and the danger posed by residential proxy services abused for malicious purposes. As threat actors increasingly exploit lateral movement via proxy endpoints, organizations in all industries must strengthen segmentation, east-west traffic monitoring, and endpoint visibility to mitigate future outbreaks.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Russian Ransomware Leader Brought to Justice: Lessons from the Antropenko Case
Impact· high

Russian Ransomware Leader Brought to Justice: Lessons from the Antropenko Case

Between 2018 and August 2022, Ianis Aleksandrovich Antropenko led a prolific ransomware operation targeting at least 50 victims across various sectors, causing losses exceeding $1.5 million. Operating from both Russia and later the United States, Antropenko leveraged variants like Zeppelin and GlobeImposter, coordinating with co-conspirators—including his ex-wife—to deploy ransomware, extort victims, and launder proceeds through a network of global accounts and crypto wallets. His arrest and subsequent guilty plea follow a multi-year investigation by U.S. federal authorities, resulting in the seizure of more than $3 million in assets. This case highlights the growing trend of ransomware group leaders operating internationally and even within U.S. borders, challenging traditional law enforcement approaches. It underscores persistent ransomware risk, ongoing challenges in detecting coordinated laundering activity, and the critical need for comprehensive security controls and compliance vigilance.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Why Even Security Pros Get Phished: The Human & AI-Powered Phishing Crisis of 2026
Impact· medium

Why Even Security Pros Get Phished: The Human & AI-Powered Phishing Crisis of 2026

In January 2026, multiple incidents highlighted how even vigilant individuals and cybersecurity professionals are susceptible to highly convincing phishing attacks. Attackers leveraged advanced social engineering techniques and sophisticated phishing-as-a-service (PhaaS) platforms, often enhanced by AI-driven content generators such as PhishGPT, to deliver targeted messages via email, SMS, and collaboration tools. These lures bypassed traditional defenses, exploiting moments of distraction or emotional vulnerability to harvest sensitive information including credentials and payment data. The operational impact ranged from financial loss and credential compromise to downstream business risk due to unauthorized access or fraud. The incident typifies the evolution of phishing as an industrialized, scalable ecosystem that increasingly relies on automation, AI-tailored content, and a broadening array of tactics. As these methods proliferate and become accessible to attackers with limited technical skills, organizations face heightened regulatory, operational, and reputational risks, making effective prevention and user awareness more vital than ever.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
CrashFix Browser Scam: How Malicious Extensions Opened the Door to RATs in 2024
Impact· medium

CrashFix Browser Scam: How Malicious Extensions Opened the Door to RATs in 2024

In early 2024, security researchers identified a sophisticated malware campaign dubbed the 'CrashFix' scam, which leveraged malicious browser extensions—specifically the NexShield extension—to crash users' browsers via social engineering popups and prompt them to install phony fixes. Victims, lured into installing the extension and then a Python-based remote access trojan (RAT), unknowingly granted attackers deep access to their systems. Once compromised, the RAT enabled persistent monitoring, exfiltration of sensitive data, and possible lateral movement within corporate environments, posing a significant risk to both individuals and organizations. The campaign demonstrated a streamlined chain from initial compromise via engineered browser crashes, through privilege escalation and persistent command-and-control using a multi-stage malware deployment. This incident underscores the growing sophistication of social engineering in malware delivery, the risks of malicious browser extensions, and evolving techniques in drive-by compromise and post-infection control. Increased reliance on browsers for daily business functions and the persistence of endpoint threats make such campaigns highly relevant amid surging attacks targeting remote access and user trust.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Tudou Guarantee Shuts Down Telegram Transactions After $12B Crypto Fraud Wave
Impact· medium

Tudou Guarantee Shuts Down Telegram Transactions After $12B Crypto Fraud Wave

In January 2026, Tudou Guarantee Marketplace, a major Telegram-based platform known for facilitating illicit services and cryptocurrency fraud, halted its public Telegram transactions after processing over $12 billion in suspicious activity. This dramatic step followed the arrest of Chen Zhi, CEO of Prince Group, whose organization was linked to large-scale scam operations including forced labor, romance scams, and investment fraud. The sudden drop in wallet activity suggests a direct link to recent law enforcement action targeting Southeast Asian scam networks. This incident highlights the persistent risks of unregulated messaging platforms in enabling transnational cybercrime and the growing technological sophistication behind crypto-related fraud. With law enforcement crackdowns intensifying and marketplaces shifting tactics, organizations must update controls against social engineering, identity abuse, and crypto laundering.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports