✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Banking/Mortgage
Breach intelligence, attack campaigns, and threat reports targeting the Banking/Mortgage sector.
Explore Other Sectors
Banking/Mortgage Threat Reports
Phishing Empire Unmasked: How Cloud Phishing-as-a-Service Campaigns Evade Detection
In 2024, a sophisticated phishing-as-a-service (PhaaS) operation leveraged Google and Cloudflare infrastructure to host undetectable phishing sites for over three years. By employing advanced cloaking techniques and encrypted traffic, threat actors were able to evade detection by security platforms and browsers, targeting users globally and harvesting credentials at scale. The persistent campaign highlights the effectiveness of public cloud abuse for malicious operations and the operational difficulties organizations face in detecting and mitigating such well-cloaked threats. This incident underscores a growing trend: cybercriminals turning to public cloud providers for reliable infrastructure and exploiting their reputation to bypass security controls. It also signals the adaptability of phishing campaigns and the need for enhanced monitoring and zero trust strategies in response to evolving attacker TTPs.
6 months ago
Kill Chain
European Crypto Fraud Ring Dismantled After €100 Million Theft
In September 2025, European law enforcement agencies coordinated by Eurojust and Europol dismantled a cryptocurrency investment fraud ring, arresting five suspects linked to more than €100 million ($118 million) in stolen funds. The operation, spanning several countries including Spain, Portugal, Bulgaria, Italy, Lithuania, and Romania, targeted a sophisticated group that lured victims with promises of high returns through professional online platforms. Funds from over 100 victims across 23 countries were diverted into controlled accounts, masked by additional recovery fees and subsequent website takedowns, resulting in substantial losses and significant reputational damage. This incident underscores the growing scale and sophistication of crypto-based financial fraud targeting both individuals and organizations globally. The case highlights the necessity for robust fraud prevention, regulatory vigilance, and proactive threat detection in the rapidly evolving crypto investment landscape.
6 months ago
Kill Chain
2025’s Multichannel Phishing Surge: How Attackers Bypassed MFA and Hijacked Sessions
In early 2025, a wave of sophisticated phishing attacks exploited new multichannel vectors, including social media platforms, malicious search advertisements, and browser-based manipulation, to bypass multi-factor authentication and steal user sessions. Threat actors rapidly adapted to defensive advances, leveraging session hijacking and advanced social engineering to deceive users, often eclipsing legacy email-based phishing. Organizations reported credential compromise, unauthorized access to sensitive resources, and downstream data breaches as a result of these evolving techniques. The relevance of this incident is underscored by the acceleration of identity-based attacks, targeting hybrid and cloud environments and challenging traditional security controls. Regulatory focus on data privacy and authentication heightens the need for organizations to reassess their phishing defenses, user awareness, and session protection strategies.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports