The Containment Era is here. →Explore

Industry Category

Banking/Mortgage

Breach intelligence, attack campaigns, and threat reports targeting the Banking/Mortgage sector.

447 threat reports
Page 34 of 38

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Banking/Mortgage Threat Reports

Showing 397408 / 447 reports
PassiveNeuron: Unraveling the 2024–2025 Advanced Persistent Attack on Global Servers
Impact· low

PassiveNeuron: Unraveling the 2024–2025 Advanced Persistent Attack on Global Servers

Between June 2024 and August 2025, the advanced persistent threat (APT) campaign codenamed "PassiveNeuron" targeted government, financial, and industrial organizations primarily across Asia, Africa, and Latin America. Attackers exploited SQL servers—likely leveraging vulnerabilities or credential brute-forcing—to gain initial access, followed by repeated attempts to deploy web shells. When thwarted by robust endpoint protections, the attackers escalated to advanced techniques, implementing a multi-stage DLL loader chain to deliver custom implants ('Neursite' and 'NeuralExecutor') and leveraging Cobalt Strike for lateral movement and persistence. These tools enabled sophisticated data gathering, process management, and network proxying, all while leveraging various encryption and obfuscation tactics to evade detection. This incident exemplifies the ongoing evolution of targeted cyberespionage against server infrastructure, with attribution leaning towards a Chinese-speaking threat actor based on tactics and C2 infrastructure, though with some ambiguity due to apparent false flags. It reflects a rise in multi-stage, stealthy attacks leveraging both custom and widely abused tools, highlighting the elevated risk posed to internet-exposed critical servers.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Europol Takedown of SIMCARTEL: SIM Box Fraud Network Disrupted
Impact· high

Europol Takedown of SIMCARTEL: SIM Box Fraud Network Disrupted

In October 2024, Europol led a coordinated international operation to dismantle a sophisticated cybercrime syndicate known as "SIMCARTEL". This network, spanning Austria, Estonia, and Latvia, leveraged over 1,200 SIM box devices and 40,000 active SIM cards to conduct large-scale phishing, credential theft, and financial fraud across more than 3,200 recorded cases. Authorities linked the group to $5.8 million in financial losses, the creation of 49 million fraudulent accounts, and infrastructure facilitating criminal services in over 80 countries. The takedown resulted in seven arrests, seizure of servers, SIMs, websites, luxury vehicles, and the freezing of suspect assets. This incident highlights the growing global threat posed by SIM farms and SIM box networks, which enable scammers to evade detection, commit diverse types of fraud, and undermine trust in online communications. The rapid adoption of similar tactics worldwide puts financial institutions, telecoms, and consumers increasingly at risk.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Europol Busts Massive SIM-Box Cybercrime Network in 2025
Impact· high

Europol Busts Massive SIM-Box Cybercrime Network in 2025

In October 2025, Europol led a major operation codenamed 'SIMCARTEL' that dismantled an extensive SIM-box network servicing global cybercriminals. The illicit operation spanned multiple countries, employed 1,200 SIM-box devices and 40,000 SIM cards, and provided fake phone numbers for cybercrimes such as phishing, fraud, impersonation, and extortion. Two key websites, gogetsms.com and apisim.com, were seized. Authorities arrested seven suspects, confiscated servers and luxury assets, and froze significant cryptocurrency and bank funds. Investigators linked the service to at least 3,200 fraud cases and a direct financial loss exceeding €4.5 million, with indications the service was used to create over 49 million fraudulent online accounts. This incident underscores a growing trend in Cybercrime-as-a-Service, where sophisticated tools enable large-scale identity obfuscation and fraud. The takedown reflects mounting law enforcement pressure on criminal infrastructure rentals fueling online financial crime, highlighting urgent regulatory and security challenges for organizations reliant on voice and messaging account verification.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Hackers Exploit Cisco SNMP Zero-Day to Deploy Rootkit on Switches
Impact· high

Hackers Exploit Cisco SNMP Zero-Day to Deploy Rootkit on Switches

In October 2025, threat actors exploited a zero-day vulnerability (CVE-2025-20352) in Cisco networking devices, leveraging flaws in the Simple Network Management Protocol (SNMP) to gain remote code execution on affected IOS and IOS XE switches. Trend Micro reported that attackers primarily targeted Cisco 9400, 9300, and legacy 3750G series devices, deploying rootkits on switches and unprotected Linux systems. These rootkits established a persistent backdoor, allowing attackers to control device behavior, evade logging, bypass security controls, and move laterally across VLANs. Cisco acknowledged active exploitation and classified the issue as a zero-day, urging immediate firmware and ROM analysis if compromise is suspected. The incident highlights the continued targeting of network infrastructure via legacy vulnerabilities and sophisticated rootkits, as well as the pressing need for organizations to update detection capabilities, even on older or end-of-life systems. The use of unpatched infrastructure and the absence of robust endpoint detection provided attackers with a broad attack surface, underpinning the current urgency around zero trust networking and east-west traffic monitoring.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(low)
I
Impact(high)
Read Report
Prosper 2024 Data Breach: What Happened and What's Next for Financial Data Security
Impact· high

Prosper 2024 Data Breach: What Happened and What's Next for Financial Data Security

In early 2024, Prosper, a leading US-based financial services platform, suffered a significant data breach that compromised the personal information of over 17.6 million users. Attackers reportedly exploited vulnerabilities in Prosper's online systems, gaining unauthorized access to names, addresses, dates of birth, phone numbers, and bank account details. The breach was confirmed after the stolen data appeared in cybercrime forums and data breach repositories, prompting Prosper to notify affected users and regulatory bodies. Although no evidence of financial fraud was immediately reported, the exposed data increases risks such as identity theft and targeted social engineering. This incident underscores the pressing need for robust data protection in the financial sector due to the continued targeting of financial institutions by cybercriminals. It highlights industry-wide challenges with sensitive data security and the growing regulatory focus on rapid breach disclosure and consumer protection.

6 months ago

Kill Chain

IC
Initial Compromise(low)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
F5 2025 Breach: Nation-State Attackers Target BIG-IP Source Code
Impact· high

F5 2025 Breach: Nation-State Attackers Target BIG-IP Source Code

In August 2025, cybersecurity giant F5 detected a sophisticated breach by nation-state hackers who gained unauthorized access to its BIG-IP product development environment and engineering knowledge management platforms. Over an extended period, attackers exfiltrated undisclosed BIG-IP vulnerabilities, product source code, and select customer configuration information. F5 asserts no evidence that the attackers modified software, exploited the stolen vulnerabilities in active attacks, or that critical customer data was exposed. Response actions included credential rotations, hardening of development environments, enhanced threat detection, and external code audits by firms such as CrowdStrike, Mandiant, NCC Group, and IOActive. F5 also proactively issued security updates and guidance to impacted customers. This incident underscores the growing trend of sophisticated, supply-chain-oriented intrusions targeting technology providers with a wide enterprise customer base. It illustrates the strategic value of source code and zero-day exploits to well-resourced threat actors, and raises ongoing concerns about the security of key software infrastructure used widely across industries.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Maverick: How WhatsApp Became the Gateway for Brazil’s Biggest Banking Trojan in 2024
Impact· medium

Maverick: How WhatsApp Became the Gateway for Brazil’s Biggest Banking Trojan in 2024

In October 2024, a sophisticated banking Trojan dubbed Maverick was detected actively targeting Brazilian users. The malware was delivered via malicious ZIP files sent through WhatsApp, bypassing platform detection. Victims executed an LNK file that triggered a fully fileless, multi-stage infection chain, utilizing PowerShell, .NET, and encrypted shellcode. Maverick, which shares code similarities with the Coyote Trojan, leverages locale checks to target only Brazilians and uses WPPConnect to automate the spread through hijacked WhatsApp accounts. Once established, the Trojan provides attackers full remote access, including keylogging, screen control, and phishing overlays to harvest banking and cryptocurrency credentials. This incident is notable for its complex multi-stage deployment, worm-like propagation, and use of AI-aided code, reflecting a new evolution in financially motivated malware. The attack demonstrates the increasing convergence of social engineering, sophisticated fileless techniques, and abuse of popular messaging platforms, signaling urgent challenges for both enterprises and end users.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Officials Dismantle Major Southeast Asia Cybercrime Network in $15B Bitcoin Seizure
Impact· high

Officials Dismantle Major Southeast Asia Cybercrime Network in $15B Bitcoin Seizure

In early 2024, federal authorities from the U.S. and U.K. conducted a large-scale operation against Southeast Asia cybercrime networks, seizing 127,271 Bitcoins worth approximately $15 billion from Chen Zhi, the alleged head of the Prince Group based in Cambodia. The Prince Group, operating since 2015, is accused of running transnational scam compounds utilizing human trafficking and forced labor to enact wide-reaching financial fraud across over 30 countries, including the U.S. where a Brooklyn network victimized more than 250 individuals. The operation resulted in sanctions on 146 people and organizations, the severing of Huione Group from the U.S. financial system, and the dismantling of 117 illicit Prince Group-affiliated businesses. This record-breaking crackdown underscores the severity and international scale of cyber-enabled financial fraud, money laundering, and the role of organized crime groups leveraging technology across borders. The incident highlights growing regulatory and enforcement focus, as well as the evolving threat posed by sophisticated scam and laundering operations exploiting multi-region financial networks.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
US Seizes $15B in Crypto from Global 'Pig Butchering' Syndicate
Impact· medium

US Seizes $15B in Crypto from Global 'Pig Butchering' Syndicate

In October 2025, the U.S. Department of Justice seized $15 billion in bitcoin from the leader of the Prince Group, a transnational criminal organization responsible for orchestrating large-scale cryptocurrency investment scams, widely known as 'pig butchering.' Operating from Cambodia since 2015, Prince Group exploited social media, dating apps, and messaging platforms to lure victims into fraudulent investment schemes, funneling billions via complex laundering tactics and a vast network of shell companies in over 30 countries. The syndicate trafficked and forced thousands into labor-intensive scam compounds, evading law enforcement and leveraging bribery, automated call centers, and violence. The stolen funds were laundered and spent on luxury assets and high-value goods. The Prince Group incident underscores the escalating threat of organized cyber-enabled financial fraud, particularly those leveraging cryptocurrency to obfuscate illicit gains. Despite large-scale law enforcement crackdowns, similar tactics—ranging from romance baiting to advanced obfuscation—have proliferated globally, highlighting persistent regulatory and security challenges for fintech and law enforcement agencies.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Microsoft 2025: Zero-Day Exploit Prompts Emergency IE Mode Restrictions
Impact· low

Microsoft 2025: Zero-Day Exploit Prompts Emergency IE Mode Restrictions

In October 2025, Microsoft announced urgent restrictions on Internet Explorer (IE) mode within the Edge browser following the discovery of active zero-day exploits targeting the Chakra JavaScript engine. Threat actors leveraged sophisticated social engineering tactics to lure users to spoofed sites, where a previously unknown vulnerability in Chakra enabled remote code execution. Attackers combined this with a privilege escalation flaw to escape the browser sandbox and seize complete device control. Microsoft responded by removing easy methods to activate IE mode in Edge for consumer users, instead requiring manual configuration limited to explicit, approved sites, and urged migration from legacy technologies. This incident underscores the persistent risks associated with maintaining legacy web compatibility features such as IE mode, especially as threat actors increasingly exploit these pathways with sophisticated chains of zero-day vulnerabilities and social engineering. It highlights heightened urgency for organizations to migrate from deprecated software and rigorously manage legacy access points.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
Spain Shuts Down GXC Team: Crime-as-a-Service Powerhouse Busted in 2025
Impact· high

Spain Shuts Down GXC Team: Crime-as-a-Service Powerhouse Busted in 2025

In May 2025, Spanish authorities dismantled the "GXC Team" cybercrime syndicate, arresting its alleged leader, a 25-year-old Brazilian known as "GoogleXcoder." Operating as a Crime-as-a-Service (CaaS) provider, the group developed and sold AI-powered phishing kits, multiple Android malware strains, and social engineering voice-scam tools, primarily via Telegram and Russian-speaking hacker forums. Their phishing operations targeted financial, transport, and e-commerce institutions in Spain, Slovakia, the UK, the US, and Brazil, facilitating large-scale credential theft through more than 250 spoofed sites. Law enforcement recovered stolen cryptocurrency, seized electronic evidence, and shut down illicit channels. The investigation, enabled by forensic analysis of devices and crypto transactions, remains ongoing, with further arrests anticipated. This incident highlights the rise of CaaS platforms using automation, AI, and malware-as-a-service approaches to accelerate phishing and fraud at scale. The GXC Team case underscores the evolving sophistication and reach of these criminal ventures, which now target numerous sectors globally and leverage encrypted communications to obfuscate operations.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Red Hat Breach 2025: ShinyHunters Escalate GitLab Data Extortion
Impact· high

Red Hat Breach 2025: ShinyHunters Escalate GitLab Data Extortion

In October 2025, Red Hat suffered a significant data breach after threat actor group Crimson Collective compromised its internal GitLab repositories, exfiltrating nearly 570GB of data including around 800 Customer Engagement Reports (CERs). These reports contained sensitive details about customers’ networks and infrastructure. Following unsuccessful ransom negotiations, Crimson Collective partnered with Scattered Lapsus$ Hunters and ShinyHunters to escalate extortion attempts, publicly posting data samples and demanding payment before a hard deadline. High-profile organizations such as Walmart, HSBC, Bank of Canada, and the US Department of Defense were among affected clients named in the leak. The collaboration between multiple threat actors and the rise of Extortion-as-a-Service operations like ShinyHunters highlight a new era of corporate extortion risk, with increasing pressure on organizations to proactively secure code repositories and sensitive customer communications against rapidly-evolving, multi-actor cyber threats.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports