✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Banking/Mortgage
Breach intelligence, attack campaigns, and threat reports targeting the Banking/Mortgage sector.
Explore Other Sectors
Banking/Mortgage Threat Reports
Authorities Dismantle Cryptomixer: $28 Million in Bitcoin Seized Amid Europol-Led Takedown
In June 2024, European authorities executed a coordinated operation to dismantle Cryptomixer, a cryptocurrency mixing service reportedly used to launder over $1.5 billion for global cybercriminals. Operation Olympia involved Europol, Eurojust, and law enforcement agencies from Germany and Switzerland, resulting in the seizure of nearly $28 million in Bitcoin, three physical servers, the cryptomixer.io domain, and over 12 terabytes of data. Cryptomixer functioned as an anonymizing layer for a multitude of cybercrimes, including ransomware, payment card fraud, and trafficking in illicit goods, allowing threat actors to evade detection and launder stolen assets. This takedown demonstrates mounting regulatory and law enforcement pressure on cryptocurrency-based money laundering infrastructure. The case highlights a shift among advanced threat groups—such as the North Korean Lazarus Group—from prioritizing anonymity to speed and automation in financial cybercrime operations, reflecting evolving cybercriminal tactics and the urgent need for robust digital asset tracking controls.
6 months ago
Kill Chain
Law Enforcement Dismantles Cryptomixer: Major Blow to Crypto Laundering Networks
In June 2024, a coordinated operation between Swiss and German law enforcement agencies led to the shutdown of the Cryptomixer cryptocurrency-mixing service. Since its inception in 2016, Cryptomixer is believed to have laundered over €1.3 billion in Bitcoin, providing cybercriminals with tools to obfuscate illicit financial flows from ransomware, scams, and darknet market activities. The takedown included seizure of digital infrastructure and assets, disrupting one of the major cryptocurrency laundering platforms that aided threat actors operating globally. This collaborative international action highlights increased efforts by authorities to clamp down on crypto-enabled cybercrime. The incident reflects the growing focus on digital financial transparency and signals greater scrutiny of services aiding threat actors in anonymizing transactions.
6 months ago
Kill Chain
Albiriox MaaS Android Malware: On-Device Fraud Spreads Across 400+ Financial Apps
In late 2025, a new Android malware strain dubbed Albiriox emerged on underground forums as a malware-as-a-service (MaaS) solution. Distributed primarily through phishing and malicious downloads, Albiriox targets over 400 financial, fintech, and cryptocurrency applications to enable on-device fraud and real-time manipulation of compromised devices. The malware supports screen control, credential theft, interception of two-factor authentication, and covert interaction, enabling attackers to bypass traditional defenses and commit large-scale financial fraud via victim phones. The impact has been significant, with financial institutions and consumers reporting substantial losses and operational disruptions, as attackers exploit compromised user devices for unauthorized transactions. This incident underscores the growing sophistication and accessibility of mobile malware platforms offered as a service by cybercriminals. The rise of on-device fraud capabilities—especially those circumventing multi-factor authentication and real-time security controls—demands renewed vigilance, continuous threat monitoring, and integrated security measures from organizations in the financial sector.
6 months ago
Kill Chain
Old Tech, New Headaches: How 2025’s NTLM Vulnerabilities Fueled Global APT Attacks
In 2025, a wave of advanced persistent threat campaigns exploited persistent vulnerabilities in Microsoft NTLM authentication, impacting organizations across Latin America, Russia, and Central Asia. Attackers such as BlindEagle and Head Mare leveraged newly disclosed Windows flaws (including CVE-2024-43451, CVE-2025-24054, and CVE-2025-33073) to harvest NTLM password hashes via crafted files and phishing emails, enabling credential theft, privilege escalation, and remote malware deployment. High-profile incidents included Remcos RAT and AveMaria Trojan infections following targeted spear-phishing, widespread lateral movement using pass-the-hash techniques, and the abuse of man-in-the-middle and reflection vulnerabilities to gain SYSTEM-level access. These incidents underscore the urgent risks posed by legacy protocols—despite announced NTLM deprecation, its widespread legacy use enables cybercriminals to refine credential relay and privilege escalation tactics. The ongoing threat highlights the necessity for rapid protocol retirement, proactive device auditing, regular patching, and adopting stronger authentication frameworks to defend against evolving identity-driven attacks.
6 months ago
Kill Chain
FBI: $262M Lost to ATO Fraud as AI Phishing and Holiday Scams Surge in 2025
In late 2025, the FBI reported an alarming uptick in Account Takeover (ATO) fraud totaling over $262 million in losses. Cybercriminals, leveraging advanced AI-driven phishing tactics and holiday-themed scams, targeted individuals, businesses, and financial institutions with convincing impersonations to steal credentials and gain access to banking and sensitive accounts. Upon entry, attackers executed lateral movement, funds transfers, and data exfiltration, impacting organizations of all sizes and sectors by causing substantial financial loss, reputational harm, and regulatory scrutiny. This incident underscores an acceleration in AI-powered social engineering and the increasing sophistication of phishing campaigns, especially during high-activity periods like the holidays. Security teams now face heightened urgency to adapt with advanced detection, identity controls, and zero trust segmentation to address evolving threats using AI and automation.
6 months ago
Kill Chain
Inside the 2025 Digital Fraud Surge: How AI Supercharged Cybercrime
In early 2025, a wave of advanced persistent fraud targeted multiple global organizations as cybercriminals leveraged generative AI and automated bots to launch large-scale digital fraud schemes. Attackers used sophisticated deepfake technology and high-quality counterfeit IDs to penetrate identity verification systems, bypass account controls, and hijack customer accounts across banking, healthcare, and e-commerce sectors. The attacks exploited gaps in east-west traffic security and leveraged encrypted channels to evade detection for months. Businesses suffered significant financial losses, reputational damage, and were forced to bolster their compliance efforts in the wake of the breach. This incident marked a turning point in the evolution of digital fraud, as attackers embraced highly scalable automation and AI for identity-driven campaigns. The surge in industrial-scale fraud highlighted gaps in visibility, zero-trust segmentation, and anomaly detection while placing new urgency on regulatory compliance and modern defense architectures.
6 months ago
Kill Chain
FBI Alert: $262M Stolen in 2024 Account Takeover Fraud by Bank Impersonators
In early 2024, the FBI reported a dramatic surge in account takeover (ATO) fraud targeting U.S. banking customers through sophisticated social engineering. Cybercriminals, primarily via phone and digital messages, impersonated legitimate bank support teams to exploit unsuspecting individuals. Attackers tricked victims into revealing credentials and one-time passcodes, enabling unauthorized access to bank accounts. Since January, over $262 million has been stolen in these highly coordinated campaigns, impacting both major financial institutions and their customers, with funds rapidly funneled out—often through cryptocurrency exchanges or money-mule accounts. This incident highlights an escalating trend of identity-driven attacks leveraging increasingly convincing social engineering tactics. As financial fraud rises sharply, financial institutions face mounting regulatory pressures to improve anomaly detection and secure authentication, while consumers must remain vigilant against evolving ATO schemes.
6 months ago
Kill Chain
Banks and Governments Exposed: Code Beautifiers Leak Credentials in 2024
In early 2024, researchers discovered that thousands of sensitive credentials, API keys, and authentication tokens belonging to global banks, government agencies, and technology companies were inadvertently exposed through public submissions to online code formatting tools such as JSONFormatter and CodeBeautify. These web-based beautifier platforms, commonly used by developers to format or debug code, were found to be storing users’ uploads—including confidential configuration files—in publicly accessible repositories without adequate warning or access control. As a result, threat actors could easily discover and exploit these exposed secrets to compromise critical infrastructure or initiate supply chain attacks. This incident underscores the ongoing risks of third-party tool usage in secure development lifecycles. With data exposures driven by everyday tooling, organizations face mounting regulatory and operational scrutiny to audit developer practices, harden supply chain security, and implement broader controls for inadvertent credential leakage.
6 months ago
Kill Chain
SitusAMC Breach Exposes Sensitive Data in Real-Estate Finance Supply Chain
In June 2024, SitusAMC, a leading provider of real-estate finance back-end services, identified unauthorized access to systems containing client data. Attackers exploited a vulnerability in the company’s network infrastructure, resulting in the exposure of sensitive information related to financial institutions and their customers. SitusAMC promptly launched an investigation and notified impacted clients after confirming that personal and business data—including names, contact details, financial records, and transaction information—had been compromised. The breach triggered operational reviews and regulatory notification obligations, highlighting the company’s broad reach in the U.S. finance sector. This incident spotlights a worrisome trend of threat actors targeting managed services and supply chains in critical industries. With rising attacks focusing on lateral movement and data exfiltration, organizations face growing pressure from regulators and industry groups to prioritize segmentation, monitoring, and encryption across their digital estates.
6 months ago
Kill Chain
2025 Black Friday Cybercrime Surge: How E-Commerce, Banking & Gaming Users Were Targeted
During the 2025 Black Friday sales period, a massive wave of phishing, financial malware, and scam campaigns targeted global consumers across e-commerce, online banking, payment systems, and gaming platforms. Threat actors leveraged sophisticated phishing pages mimicking major retailers like Amazon, Alibaba, and Walmart, and deployed banking Trojans such as Maverick and Efimer via email and messaging apps. Over 6.4 million e-commerce phishing attempts and 1.09 million banking Trojan attacks were detected, with cybercriminals intensively exploiting shopping and gaming hype to harvest credentials, payment data, and digital assets. This incident highlights an ongoing shift as cyber attackers increasingly time their campaigns around large global retail events, exploiting predictable user behavior and surges in online activity. Threats have diversified across platforms, with a notable rise in attacks on gaming services and dramatic increases in malicious activity leveraging Discord and Steam, signaling a pressing need for adaptive, multi-layered cyber defenses.
6 months ago
Kill Chain
Sturnus Android Trojan Exposes Secure Messaging Apps in Major 2024 Threat
In May 2024, security researchers uncovered a new Android banking trojan named Sturnus targeting mobile devices in the wild. Sturnus stands out for its advanced multi-stage capabilities, allowing the malware to intercept and exfiltrate end-to-end encrypted messages from applications such as Signal, WhatsApp, and Telegram. The malware also leverages device accessibility services to gain total device control, enabling it to steal SMS, contacts, banking credentials, and intercept two-factor authentication (2FA). Initial infection is typically achieved via malicious sideloaded APKs distributed through phishing campaigns and third-party app stores, exposing users to substantial data theft and account compromise risk. This incident highlights a growing trend in Android malware evolution, where banking trojans are increasingly equipped with multi-app message theft, advanced evasion techniques, and device takeover functions. The widespread use of encrypted messaging apps in business and personal communication elevates the threat, driving demand for enhanced mobile endpoint security and stricter controls on app distribution.
6 months ago
Kill Chain
Crypto Mixer Crackdown: Samourai Wallet Founders Convicted for $237M Laundering Scheme
In 2024, the founders of Samourai Wallet, a cryptocurrency mixing service, were sentenced to prison by US authorities for their role in facilitating the laundering of over $237 million in illicit funds. Operating from 2015 through 2024, Samourai provided obfuscation tools that enabled criminals—including ransomware operators and darknet market traffickers—to conceal the origins and flows of cryptocurrency transactions. Authorities dismantled the platform and arrested the operators following a lengthy investigation. This action directly crippled a major infrastructure point in the cybercrime ecosystem, disrupting widespread money laundering tactics reliant on mixer services. The case underscores growing regulatory and law enforcement scrutiny of crypto-mixing services due to their integral role in financial crime, ransomware payments, and evasion of anti-money laundering (AML) controls. Organizations dealing in digital assets now face heightened compliance and monitoring pressures worldwide.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports