The Containment Era is here. →Explore

Industry Category

Banking/Mortgage

Breach intelligence, attack campaigns, and threat reports targeting the Banking/Mortgage sector.

446 threat reports
Page 7 of 38

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Banking/Mortgage Threat Reports

Showing 7384 / 446 reports
INTERPOL's Operation Ramz Dismantles SniperDz Phishing Platform
Impact· MEDIUM

INTERPOL's Operation Ramz Dismantles SniperDz Phishing Platform

In a coordinated effort from October 2025 to February 2026, INTERPOL led Operation Ramz, targeting cybercriminal activities across 13 countries in the Middle East and North Africa. This operation resulted in 201 arrests, the identification of 3,867 victims, and the seizure of 53 servers. A significant outcome was the dismantling of SniperDz, a decade-old Phishing-as-a-Service platform, and the arrest of its primary developer in Algeria. SniperDz provided cybercriminals with ready-made phishing kits and infrastructure, facilitating global credential theft. ([interpol.int](https://www.interpol.int/News-and-Events/News/2026/201-arrests-in-first-of-its-kind-cybercrime-operation-in-MENA-region?utm_source=openai)) The takedown of SniperDz underscores the persistent threat posed by Phishing-as-a-Service platforms, which lower the barrier to entry for cybercriminals and enable widespread credential theft. This incident highlights the importance of international collaboration in combating cybercrime and the need for organizations to remain vigilant against evolving phishing tactics.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Europol Dismantles 'AudiA6' Crypto Laundering Service Used by Ransomware Gangs
Impact· MEDIUM

Europol Dismantles 'AudiA6' Crypto Laundering Service Used by Ransomware Gangs

In June 2026, an international law enforcement operation led by Europol dismantled 'AudiA6,' a cryptocurrency laundering service that processed over €336 million for ransomware gangs and cybercriminal networks between 2022 and 2025. The operation resulted in the arrest of two alleged administrators in Georgia, the seizure of more than 30 servers, 25 domains, over 80 vehicles, multiple properties, and the freezing of approximately €692,000 in cryptocurrency assets. 'AudiA6' was linked to over 15 international cybercrime investigations and was also associated with the dark web forum 'Dark2Web,' which facilitated illicit services and connections among cybercriminals. ([fdicoig.gov](https://www.fdicoig.gov/news/investigations-press-releases/ransomware-gangs-cut-eur-336-million-audia6-crypto-laundering?utm_source=openai)) This takedown underscores the growing industrialization of cryptocurrency laundering services that support the global cybercrime economy. The operation highlights the increasing reliance of ransomware groups on sophisticated laundering platforms to obscure illicit proceeds, emphasizing the need for enhanced international cooperation and advanced forensic capabilities to combat such threats. ([dig.watch](https://dig.watch/updates/europol-audia6-crypto-laundering-network?utm_source=openai))

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
International Authorities Dismantle 'AudiA6' Cryptocurrency Laundering Service
Impact· HIGH

International Authorities Dismantle 'AudiA6' Cryptocurrency Laundering Service

In June 2026, an international law enforcement operation dismantled 'AudiA6,' a cryptocurrency laundering service that allegedly processed over $389 million in illicit funds between 2022 and 2025. The service facilitated the laundering of proceeds from ransomware attacks and other cybercrimes by obfuscating transaction origins through complex routes, returning 'cleaned' funds to users for a commission. The operation led to the arrest of two individuals in Georgia, the seizure of 25 domains, 80 vehicles and properties, and the freezing of approximately $897,000 in cryptocurrency assets. This takedown underscores the growing global collaboration in combating cyber-enabled financial crimes and highlights the increasing scrutiny on cryptocurrency platforms used for illicit activities. Organizations are urged to enhance their monitoring of cryptocurrency transactions and implement robust compliance measures to detect and prevent money laundering activities.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
GreatXML Exploit: A New Threat to Windows BitLocker Encryption
Impact· MEDIUM

GreatXML Exploit: A New Threat to Windows BitLocker Encryption

In June 2026, security researcher Chaotic Eclipse disclosed a zero-day vulnerability named 'GreatXML' that allows attackers to bypass Windows BitLocker encryption. The exploit leverages artifacts left by Microsoft Defender's offline scan to gain SYSTEM-level access during Recovery Mode, effectively rendering BitLocker protections ineffective. Systems that have run an offline scan are particularly vulnerable, as the exploit involves placing specific XML files in the recovery partition and rebooting into the Windows Recovery Environment. This vulnerability poses a significant risk to data security, especially for devices that have utilized Defender's offline scanning feature. ([securityweek.com](https://www.securityweek.com/greatxml-zero-day-exploit-bypasses-bitlocker/?utm_source=openai)) The disclosure of GreatXML underscores the ongoing challenges in securing endpoint devices against sophisticated attacks. It highlights the need for organizations to reassess their reliance on built-in encryption tools and to implement additional layers of security to protect sensitive data. The incident also raises concerns about the effectiveness of current vulnerability disclosure practices and the timeliness of patches for critical security flaws.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Escalating Cyber Threats from North Korea and China Target Asia-Pacific Financial Institutions
Impact· CRITICAL

Escalating Cyber Threats from North Korea and China Target Asia-Pacific Financial Institutions

In 2025, cyber threat groups linked to North Korea and China intensified their attacks on financial institutions and cryptocurrency assets in the Asia-Pacific region. North Korean adversaries, notably PRESSURE CHOLLIMA, executed the largest financial theft to date, stealing $1.46 billion in cryptocurrency through a supply chain compromise. Concurrently, Chinese threat actors like HOLLOW PANDA targeted financial institutions across multiple countries, including the Philippines, Indonesia, and Brazil. These operations leveraged advanced techniques, including AI-generated identities and sophisticated social engineering tactics, to infiltrate organizations and exfiltrate sensitive data. ([crowdstrike.com](https://www.crowdstrike.com/en-us/press-releases/crowdstrike-2026-financial-services-threat-landscape-report/?utm_source=openai)) The escalation of these cyber activities underscores a growing trend of state-sponsored cybercrime aimed at financial gain and intelligence collection. The increasing sophistication and frequency of these attacks highlight the urgent need for enhanced cybersecurity measures and international collaboration to protect financial infrastructures from such persistent threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Microsoft's GitHub Repositories Compromised in Miasma Supply Chain Attack
Impact· MEDIUM

Microsoft's GitHub Repositories Compromised in Miasma Supply Chain Attack

In June 2026, Microsoft identified and removed 73 compromised repositories across its Azure, Microsoft, Azure-Samples, and MicrosoftDocs organizations on GitHub. The breach was attributed to the Miasma supply chain attack, which involved the insertion of malicious code into these repositories. This code was designed to harvest developer credentials when the repositories were accessed, particularly through AI coding tools such as Claude Code and Cursor. The immediate impact included disruptions to continuous integration pipelines and the temporary disabling of critical GitHub Actions, notably 'Azure/functions-action,' affecting numerous developers relying on these tools for deploying Azure Functions. This incident underscores the escalating threat of sophisticated supply chain attacks targeting open-source ecosystems. The Miasma campaign's ability to infiltrate and compromise widely-used repositories highlights the urgent need for enhanced security measures in software development processes. Organizations must prioritize the implementation of robust monitoring systems, regular security audits, and the adoption of zero-trust principles to mitigate the risks associated with such attacks.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
NFCShare Android Malware: A New Threat Exploiting Fake Banking App Updates
Impact· HIGH

NFCShare Android Malware: A New Threat Exploiting Fake Banking App Updates

In June 2026, the NFCShare Android malware emerged, targeting European banking customers by masquerading as legitimate banking app updates hosted on GitHub. Victims were lured through phishing sites impersonating real banks, prompting them to download malicious APK files. Once installed, the malware displayed fake verification screens, instructing users to place their payment cards near the device's NFC chip. Utilizing Android’s IsoDep interface and EMV commands, NFCShare extracted card details, including numbers, types, expiry dates, and PINs, transmitting this sensitive information to the attackers' command-and-control servers via WebSocket channels. This data facilitated unauthorized NFC payment relay schemes, leading to potential financial losses for the victims. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/nfcshare-android-malware-spreads-via-fake-banking-app-updates-on-github/?utm_source=openai)) The incident underscores a growing trend of sophisticated Android malware exploiting NFC technology to harvest payment card data. Similar campaigns, such as those involving NGate and SuperCard X malware, have been documented, indicating an escalating threat landscape. Organizations must enhance their mobile security measures and educate users on the risks associated with downloading apps from unverified sources to mitigate such threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
SoFi Hong Kong Data Breach: Lessons in Third-Party Risk Management
Impact· MEDIUM

SoFi Hong Kong Data Breach: Lessons in Third-Party Risk Management

In April 2026, SoFi Hong Kong, a subsidiary of the U.S.-based financial technology company SoFi Technologies, detected unauthorized access to a customer database managed by a third-party vendor. The breach, discovered on April 30, 2026, prompted SoFi to engage a cybersecurity firm to investigate. While the full scope of the incident remains under investigation, the company has advised customers to monitor their accounts for suspicious activity and has implemented additional security measures to protect affected accounts. This incident underscores the critical importance of robust third-party risk management in the financial sector. As financial institutions increasingly rely on external vendors for data management, ensuring these partners adhere to stringent security protocols is essential to prevent unauthorized access and protect sensitive customer information.

1 month ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
TA4922's Global Cybercrime Expansion in 2026
Impact· HIGH

TA4922's Global Cybercrime Expansion in 2026

In early 2026, the Chinese-speaking cybercrime group TA4922 significantly expanded its operations beyond East Asia, targeting organizations in Europe and Africa. Utilizing sophisticated social engineering tactics, TA4922 employed localized phishing campaigns impersonating tax authorities and financial departments to distribute malware such as Atlas RAT, RomulusLoader, and SilentRunLoader. These campaigns aimed to gain unauthorized access to systems for data theft, fraud, and resale of access. The group's rapid operational tempo and diverse malware arsenal have made detection and defense increasingly challenging. ([proofpoint.com](https://www.proofpoint.com/us/blog/threat-insight/ta4922-suspected-chinese-crime-group-going-global?utm_source=openai)) This expansion underscores a broader trend of cybercriminal groups diversifying their targets and techniques, highlighting the need for organizations worldwide to enhance their cybersecurity measures and remain vigilant against evolving threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
IronWorm Malware: A 2026 npm Supply Chain Attack
Impact· HIGH

IronWorm Malware: A 2026 npm Supply Chain Attack

In June 2026, a sophisticated supply chain attack named 'IronWorm' targeted the npm ecosystem, compromising 36 packages with over 32,000 combined monthly downloads. The Rust-written malware infiltrated developers' environments through malicious npm package updates, harvesting sensitive credentials such as API keys, cloud credentials, SSH keys, and npm publishing tokens. Utilizing a rootkit that exploits the Linux kernel's eBPF, IronWorm concealed its activities and communicated with command-and-control servers via the Tor network, enabling it to propagate further across the software supply chain. ([darkreading.com](https://www.darkreading.com/cyberattacks-data-breaches/rust-written-ironworm-npm-supply-chain?utm_source=openai)) This incident underscores the escalating threat of supply chain attacks within open-source ecosystems. The use of advanced techniques like eBPF rootkits and Tor-based communications highlights the increasing sophistication of threat actors. Organizations must enhance their security measures to protect development environments and prevent the infiltration of malicious code into trusted software projects. ([darkreading.com](https://www.darkreading.com/cyberattacks-data-breaches/rust-written-ironworm-npm-supply-chain?utm_source=openai))

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
FIFA World Cup 2026: Surge in Phishing Scams Targeting Fans
Impact· HIGH

FIFA World Cup 2026: Surge in Phishing Scams Targeting Fans

In the lead-up to the 2026 FIFA World Cup, cybercriminals have launched extensive phishing campaigns targeting fans worldwide. These operations involve over 4,300 fraudulent domains mimicking official FIFA websites, aiming to steal personal and financial information. Notably, a Chinese-speaking group dubbed 'GHOST STADIUM' has deployed sophisticated phishing kits across more than 300 cloned FIFA sites, effectively capturing user credentials and facilitating account takeovers. ([techradar.com](https://www.techradar.com/pro/this-enormous-demand-has-made-the-football-tournament-a-magnet-for-fraud-experts-warn-scammers-are-ramping-up-their-work-ahead-of-the-fifa-world-cup-2026-heres-how-to-avoid-being-hit?utm_source=openai)) The prevalence of these scams underscores the evolving tactics of cybercriminals who exploit major global events to execute large-scale fraud. The use of advanced phishing techniques and the sheer volume of fraudulent domains highlight the urgent need for heightened cybersecurity awareness and proactive measures among fans and organizations involved in the World Cup.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
DoJ's 'Disruption Week' Targets Southeast Asia Crypto Fraud Networks
Impact· HIGH

DoJ's 'Disruption Week' Targets Southeast Asia Crypto Fraud Networks

In May 2026, the U.S. Department of Justice (DoJ), in collaboration with major tech companies and international law enforcement agencies, launched 'Disruption Week' to combat cyber-enabled and cryptocurrency fraud targeting Americans. This operation led to the takedown of over 1.4 million fraudulent accounts across platforms like Facebook and Instagram, the suspension of approximately 20,000 Microsoft accounts, and the freezing of over $3.8 million in cryptocurrency assets. Additionally, seven individuals were arrested in Thailand, and multiple scam centers in Southeast Asia were disrupted. ([justice.gov](https://www.justice.gov/opa/pr/scam-center-strike-force-announces-results-us-private-industry-disruption-week?utm_source=openai)) This incident underscores the escalating threat of transnational cyber fraud, particularly involving cryptocurrencies. The significant financial losses reported in recent years highlight the urgent need for coordinated international efforts to dismantle these sophisticated scam networks and protect vulnerable individuals from financial exploitation. ([justice.gov](https://www.justice.gov/opa/pr/scam-center-strike-force-announces-results-us-private-industry-disruption-week?utm_source=openai))

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports