The Containment Era is here. →Explore

Industry Category

Banking/Mortgage

Breach intelligence, attack campaigns, and threat reports targeting the Banking/Mortgage sector.

447 threat reports
Page 36 of 38

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Banking/Mortgage Threat Reports

Showing 421432 / 447 reports
Persistent Exploitation of Hikvision Camera Vulnerabilities (2017–2025): Lessons for IoT Security
Impact· low

Persistent Exploitation of Hikvision Camera Vulnerabilities (2017–2025): Lessons for IoT Security

Between 2017 and 2025, waves of exploit attempts have targeted Hikvision IP cameras using vulnerabilities such as CVE-2017-7921. Attackers abused easily guessable or default credentials passed via HTTP GET parameters, leveraging weak authentication mechanisms to access sensitive camera endpoints, user configurations, and device data. The entry vector relied on IoT device misconfigurations and insecure design, while brute-force attempts and credential stuffing remain prevalent. This activity has potential to expose live feeds, user data, and create a foothold into internal networks, with implications for privacy, compliance, and physical security. This breach is notable today as attempts to exploit Hikvision and similar IoT cameras continue at scale, highlighting persistent IoT security challenges due to poor credential hygiene, slow patch adoption, and device interface limitations. The incident demonstrates ongoing risk as attackers increasingly automate targeting of legacy and unpatched embedded devices across global networks.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Interpol's 2024 Crackdown: $439 Million Seized from Global Cybercrime Networks
Impact· medium

Interpol's 2024 Crackdown: $439 Million Seized from Global Cybercrime Networks

In 2024, Interpol coordinated a global operation targeting cybercrime rings responsible for large-scale financial crimes. Over a period of five months, law enforcement agencies from 61 countries worked together to investigate and disrupt online scams that included business email compromise (BEC), investment fraud, romance scams, and e-commerce fraud. The operation resulted in the seizure of more than $439 million in cash and cryptocurrency, exposing elaborate money laundering networks and identifying approximately 1,300 suspects linked to cyber-enabled financial crime groups. Thousands of victims worldwide were impacted by these schemes. This incident highlights the growing sophistication and international reach of financially motivated cybercrime, as well as the increasingly effective law enforcement collaborations to disrupt illicit networks. The operation reflects a heightened urgency for organizations to strengthen controls against online fraud and cyber-enabled theft, as attackers continually evolve their tactics.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Supermicro’s 2025 BMC Firmware Flaws Expose Critical Backdoor Risks
Impact· medium

Supermicro’s 2025 BMC Firmware Flaws Expose Critical Backdoor Risks

In September 2025, Supermicro disclosed critical firmware vulnerabilities (CVE-2025-7937 and CVE-2025-6198) affecting its server Baseboard Management Controller (BMC). Security researchers at Binarly demonstrated that attackers could leverage these flaws to bypass firmware signature verification and the BMC root of trust, allowing deployment of persistent, malicious firmware on widely used Supermicro servers. Exploits could grant adversaries complete, long-term control over both the BMC and host OS, enabling stealthy persistence and reliable evasion of security controls, while systems appeared to be running valid, signed code. Supermicro confirmed the vulnerabilities, releasing firmware patches, but proof-of-concept exploits are already public. This incident underscores the evolving challenge of hardware-level attacks, as advanced threat actors increasingly target supply chain and firmware layers to establish persistent, hard-to-detect footholds. Recent regulatory pressure and rising incidents of firmware-based threats highlight the urgency for security teams to elevate visibility and controls across hardware trust boundaries.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Iframe Security Exposed: The 2025 Rise of Payment Skimmer Attacks
Impact· high

Iframe Security Exposed: The 2025 Rise of Payment Skimmer Attacks

In September 2025, a widespread web application attack exploited payment iframes across major online retailers to deploy advanced payment skimmer malware. Attackers leveraged vulnerabilities in embedded iframe components on e-commerce checkout pages, bypassing client-side security controls and web isolation policies to secretly harvest customer credit card data. The campaign remained undetected for weeks, affecting thousands of transactions globally and prompting emergency mitigation efforts, reputational impact, and regulatory scrutiny for affected organizations. This incident highlights the urgent need for stronger web application and iframe security, as payment skimming through novel overlay techniques continues to surge. Organizations are under increased regulatory pressure to harden PCI compliance and prevent supply chain-driven client-side attacks.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Canada Seizes $40 Million in Historic Crackdown on TradeOgre Crypto Exchange
Impact· high

Canada Seizes $40 Million in Historic Crackdown on TradeOgre Crypto Exchange

In September 2025, the Royal Canadian Mounted Police (RCMP) dismantled the TradeOgre cryptocurrency exchange, seizing over $40 million in digital assets linked to alleged financial crimes. The operation was initiated following intelligence from Europol, leading to an investigation by the Money Laundering Investigative Team (MLIT) that uncovered the exchange's lack of regulatory compliance, such as evading Know Your Customer (KYC) protocols and failing to register with Canada's FINTRAC. The lack of oversight facilitated the laundering of cybercrime proceeds, particularly via privacy-focused cryptocurrencies like Monero, culminating in the country's largest-ever asset seizure. This incident underscores the growing scrutiny and regulatory pressure on privacy-centric platforms facilitating anonymous digital transactions. The enforcement action highlights heightened law enforcement capabilities targeting underground exchanges and reflects broader trends in global efforts to curb illicit finance within the crypto sector.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
Global Surge in PhaaS: 17,500 Phishing Domains Exploit 316 Brands
Impact· low

Global Surge in PhaaS: 17,500 Phishing Domains Exploit 316 Brands

In mid-2025, cybersecurity researchers exposed an extensive global phishing campaign orchestrated via Phishing-as-a-Service (PhaaS) platforms Lighthouse and Lucid. These services facilitated the deployment of more than 17,500 phishing domains impersonating 316 brands across 74 countries. The PhaaS operators provided subscription access to professionally maintained phishing kits targeting both enterprises and individual users, enabling attackers with minimal technical expertise to launch widespread credential theft attacks. As a result, organizations in sectors ranging from finance to technology experienced increases in fraudulent account access, financial loss, and reputational harm. The scale and automation lowered barriers for entry, allowing rapid exploitation and high turnover of malicious domains. This incident underscores the rapid evolution of cybercriminal business models, notably the rise of PhaaS, which commoditizes phishing attacks on a global scale. Its effectiveness and accessibility are driving a surge in targeted brand impersonation attempts and amplifying regulatory attention around authentication, threat monitoring, and user awareness.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Fortra GoAnywhere MFT 2025: CVE-2025-10035 Exposed Critical Enterprise File Transfers
Impact· medium

Fortra GoAnywhere MFT 2025: CVE-2025-10035 Exposed Critical Enterprise File Transfers

In September 2025, Fortra disclosed a critical security vulnerability (CVE-2025-10035) in its GoAnywhere Managed File Transfer (MFT) platform. The flaw, a deserialization weakness in the License Servlet, enabled remote attackers to execute arbitrary commands if they could submit a forged license request. Malicious activity leveraging this zero-day allowed threat actors to gain unauthorized access to sensitive file transfers, escalate privileges, and potentially exfiltrate confidential information before a patch was issued. The vulnerability received a maximum CVSS score of 10.0, emphasizing its severe risk and widespread exploitability. This incident highlights the ongoing surge in weaponization of zero-day vulnerabilities affecting popular enterprise software. Threat actors are increasingly exploiting deserialization bugs to bypass security controls and facilitate ransomware operations, putting organizations and their supply chains at heightened risk unless immediate mitigations are applied.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Synthetic Identity Fraud Surges: US Finance Faces $3.3B in Damages (2024)
Impact· medium

Synthetic Identity Fraud Surges: US Finance Faces $3.3B in Damages (2024)

In 2024, US financial institutions, particularly those in the automotive lending sector, experienced a significant surge in synthetic identity fraud, resulting in estimated damages of $3.3 billion. Cybercriminals leveraged data amassed from previous breaches to construct convincing synthetic profiles used to obtain loans and open accounts, often nurturing these fraudulent identities with legitimate activity to evade detection. Both individual and business identities were targeted, with institutions facing growing pressure to enhance detection capabilities amid an ongoing arms race with sophisticated attackers employing AI and cloud tools. This increase in synthetic identity fraud reflects an evolving threat landscape, where attackers capitalize on remote-first processes and richer data sources to outpace traditional defenses. The accelerating adoption of digital banking and lending has heightened urgency for adaptive, real-time security controls and improved identity verification as financial firms confront complex, persistent fraud schemes.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
NPM Phishing 2024: Developer Credentials Compromised by Sophisticated Email Lures
Impact· medium

NPM Phishing 2024: Developer Credentials Compromised by Sophisticated Email Lures

In September 2024, a targeted phishing campaign compromised multiple npm developer accounts by using convincing emails and deceptive landing pages such as "npmjs.help" and "npmjs.cam." Attackers exploited commonly overlooked weaknesses in email link validation and human trust, causing even experienced developers to disclose credentials. The attackers leveraged lookalike domains and effective social engineering, leading to account takeovers and enabling potential downstream attacks on open-source supply chains. The incident highlighted how traditional security awareness measures and multi-factor authentication (MFA) can be circumvented by advanced phishing tactics. This incident underscores the increasing effectiveness of credential compromise attacks in the software supply chain and the limitations of user training and legacy MFA solutions. As threat actors continue to innovate with sophisticated phishing techniques and pass-through attacks, businesses must urgently reconsider authentication strategies, emphasizing phishing-resistant technologies such as passkeys and cryptographic authenticators.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(medium)
Read Report
HybridPetya Ransomware: UEFI Secure Boot Under Attack in 2024
Impact· high

HybridPetya Ransomware: UEFI Secure Boot Under Attack in 2024

In June 2024, ESET researchers discovered a ransomware variant dubbed HybridPetya, modeled after the infamous Petya/NotPetya malware, with a significant escalation in its capabilities. HybridPetya leverages the CVE-2024-7344 vulnerability to compromise UEFI-based systems, effectively bypassing Secure Boot protections on outdated hardware. Although not known to be active in broad campaigns, this bootkit joins a small group of malware capable of undermining the fundamental trust mechanisms securing modern machines, representing a sophisticated evolution in ransomware delivery and persistence techniques. HybridPetya’s emergence highlights the rapid adaptation of cybercriminals to harden malware against defensive controls. UEFI bootkit methods—once advanced nation-state territory—are now appearing in ransomware. Organizations must urgently review endpoint protections, hardware patching, and secure boot configurations to lower exposure to these new attack paths.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
HybridPetya: Ransomware That Bypasses UEFI Secure Boot with CVE-2024-7344
Impact· high

HybridPetya: Ransomware That Bypasses UEFI Secure Boot with CVE-2024-7344

In September 2025, researchers at ESET identified a new ransomware variant named HybridPetya that combines destructive Petya/NotPetya traits with advanced UEFI attack capabilities. Leveraging the CVE-2024-7344 vulnerability, attackers were able to bypass UEFI Secure Boot, allowing the malware to execute at a privileged level prior to OS load. Initial infection vectors appear to include phishing emails and software supply-chain compromises, leading to widespread disruption of targeted organizations’ endpoints, encrypted data, and in some instances, bricked devices. The attack highlights a disturbing escalation in ransomware sophistication and targeting, with significant operational downtime and financial losses reported in affected sectors. HybridPetya represents an evolution in ransomware, merging firmware exploitation with traditional payload delivery to maximize impact. This incident underscores the expanding threat landscape as adversaries weaponize newly discovered vulnerabilities and aim higher up the trust chain, intensifying pressure on organizations to harden their endpoints and update defenses in real time.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Multilingual Phishing: FileFix Variant Delivers StealC Infostealer in 2025
Impact· high

Multilingual Phishing: FileFix Variant Delivers StealC Infostealer in 2025

In September 2025, security researchers identified a sophisticated phishing campaign delivering a new variant of the StealC information-stealer malware via a convincing, multilingual phishing website impersonating popular brands such as Facebook Security. The attackers leveraged advanced social engineering tactics, widespread language support, heavy anti-analysis measures, and advanced obfuscation to successfully bypass traditional security detections. The campaign’s initial access was achieved through social engineering, leading victims to download malicious payloads disguised as legitimate files, which, once executed, exfiltrated credentials and sensitive data at scale. This incident highlights an ongoing surge in multilingual, highly tailored phishing approaches that utilize advanced anti-detection techniques, making detection and mitigation more difficult. Organizations face mounting pressure to strengthen controls against information stealers as attackers adapt proven TTPs to bypass endpoint protection and target a global victim base.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports