The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Banking/Mortgage
Breach intelligence, attack campaigns, and threat reports targeting the Banking/Mortgage sector.
Explore Other Sectors
Banking/Mortgage Threat Reports
Fraudsters Exploit Credit Union Verification Processes in 2026
In May 2026, cybersecurity researchers uncovered a sophisticated fraud scheme targeting small to mid-sized credit unions. Threat actors utilized stolen personal data to impersonate legitimate borrowers, navigating through credit checks and identity verification processes without triggering security alerts. This methodical approach exploited perceived weaknesses in the verification systems of smaller financial institutions, leading to unauthorized loan approvals and significant financial losses. This incident underscores a growing trend where cybercriminals focus on process exploitation rather than technical vulnerabilities. The increasing availability of personal data on underground forums, combined with advanced social engineering tactics, poses a heightened risk to financial institutions, especially those with limited fraud prevention resources.
4 months ago
Kill Chain
Rising Threat: Amazon SES Phishing Abuse in 2026
In May 2026, cybersecurity researchers identified a significant increase in phishing campaigns exploiting Amazon Simple Email Service (SES). Attackers leveraged exposed AWS Identity and Access Management (IAM) access keys, often found in public GitHub repositories, .ENV files, Docker images, and publicly accessible S3 buckets, to send convincing phishing emails that bypass standard security filters. These emails, appearing to originate from trusted sources, included fake document-signing notifications and sophisticated business email compromise (BEC) attacks, leading to unauthorized access and financial losses. This trend underscores the critical need for organizations to implement stringent security measures, such as enforcing least-privilege IAM policies, enabling multi-factor authentication, regularly rotating access keys, and applying IP-based access restrictions. The rise in such attacks highlights the evolving tactics of cybercriminals and the importance of proactive defense strategies to protect sensitive information and maintain trust.
4 months ago
Kill Chain
Exploitation of Amazon SES in Phishing and BEC Attacks: A 2026 Analysis
In early 2026, cybercriminals exploited Amazon Simple Email Service (SES) to conduct sophisticated phishing and Business Email Compromise (BEC) attacks. By leveraging exposed AWS Identity and Access Management (IAM) access keys, attackers sent large volumes of phishing emails that passed standard authentication checks, such as SPF, DKIM, and DMARC. These emails often impersonated trusted services like DocuSign, leading recipients to malicious sites designed to harvest sensitive information. The abuse of Amazon's legitimate infrastructure allowed these phishing campaigns to evade traditional email security measures, resulting in significant data breaches and financial losses for targeted organizations. This incident underscores a growing trend where attackers exploit trusted cloud services to enhance the credibility and effectiveness of their phishing campaigns. The increasing sophistication of such attacks highlights the urgent need for organizations to implement robust security measures, including strict IAM policies, regular key rotation, and comprehensive employee training to recognize and respond to phishing attempts.
4 months ago
Kill Chain
Global Crackdown Dismantles Major Crypto Scam Network
In April 2026, a coordinated international operation led by Dubai Police, in collaboration with the U.S. FBI and the Chinese Ministry of Public Security, resulted in the arrest of at least 276 individuals and the dismantling of nine scam centers involved in cryptocurrency investment fraud targeting American citizens. The operation uncovered that these centers employed 'pig butchering' schemes, where scammers built trust with victims through fake relationships before persuading them to invest in fraudulent cryptocurrency platforms, leading to millions of dollars in losses. Notably, the scams were linked to human trafficking, with individuals coerced into operating the fraudulent schemes under exploitative conditions. ([justice.gov](https://www.justice.gov/opa/pr/coordinated-takedown-scam-centers-leads-least-276-arrests-alleged-managers-and-recruiters?utm_source=openai)) This incident underscores the growing sophistication and international reach of cryptocurrency fraud schemes, highlighting the urgent need for enhanced global cooperation in combating such cybercrimes. The successful operation demonstrates the effectiveness of cross-border law enforcement collaboration in addressing complex financial frauds that exploit emerging technologies.
4 months ago
Kill Chain
North Korean Cyberattacks on DeFi Platforms Result in $577 Million Theft
In April 2026, North Korean state-sponsored hackers executed two significant cyberattacks on decentralized finance (DeFi) platforms, resulting in the theft of approximately $577 million. The first attack targeted Drift Protocol on April 1, exploiting social engineering tactics to compromise multisig governance and utilizing Solana's durable nonces to pre-sign administrative transactions, leading to a loss of $285 million. The second attack occurred on April 18 against KelpDAO, where attackers compromised internal RPC nodes and launched a denial-of-service attack on external nodes, facilitating the theft of $292 million. These incidents underscore the increasing sophistication and financial impact of North Korean cyber operations in the cryptocurrency sector. ([coinmarketcap.com](https://coinmarketcap.com/academy/article/north-korea-crypto-theft-76-percent-2026?utm_source=openai)) The prevalence of such high-value attacks highlights the urgent need for enhanced security measures within the DeFi ecosystem. The integration of artificial intelligence by threat actors to refine reconnaissance and social engineering tactics poses a growing challenge, necessitating proactive defense strategies to safeguard digital assets. ([coinmarketcap.com](https://coinmarketcap.com/academy/article/north-korea-crypto-theft-76-percent-2026?utm_source=openai))
4 months ago
Kill Chain
CVE-2026-31431: 'Copy Fail' Vulnerability Poses Critical Risk to Linux Systems
In April 2026, a critical local privilege escalation vulnerability, CVE-2026-31431, known as "Copy Fail," was disclosed, affecting Linux kernels released since 2017. This flaw allows unprivileged local users to gain root access by exploiting a logic error in the kernel's cryptographic subsystem, specifically within the `algif_aead` module. The vulnerability impacts major distributions, including Ubuntu, Red Hat Enterprise Linux, SUSE, and Amazon Linux, posing significant risks to cloud environments and containerized applications. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/05/01/cve-2026-31431-copy-fail-vulnerability-enables-linux-root-privilege-escalation/?utm_source=openai)) The availability of a reliable proof-of-concept exploit and the widespread nature of the vulnerability have raised concerns about potential exploitation. Organizations are urged to apply patches promptly and implement mitigation strategies to prevent unauthorized access and maintain system integrity. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/05/01/cve-2026-31431-copy-fail-vulnerability-enables-linux-root-privilege-escalation/?utm_source=openai))
4 months ago
Kill Chain
Global Crackdown on Cryptocurrency Fraud Leads to 276 Arrests
In April 2026, a coordinated international operation led by Dubai Police, in collaboration with U.S. and Chinese authorities, resulted in the arrest of at least 276 individuals and the dismantling of nine cryptocurrency investment fraud centers. These centers orchestrated 'pig-butchering' schemes, where scammers built trust with victims through fabricated relationships, ultimately luring them into fake cryptocurrency investment platforms that drained their funds. The operation targeted crime networks running these schemes, leading to significant arrests and the disruption of fraudulent activities. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/police-dismantles-9-crypto-investment-scam-centers-arrests-276-suspects/?utm_source=openai)) This incident underscores the escalating threat of sophisticated financial fraud schemes exploiting the cryptocurrency market. The substantial losses incurred highlight the urgent need for enhanced regulatory measures and public awareness to combat such deceptive practices effectively.
4 months ago
Kill Chain
Claude Mythos AI Exposes Critical Vulnerabilities in Japan's Financial Systems
In April 2026, Anthropic's advanced AI model, Claude Mythos, demonstrated the capability to autonomously identify and exploit previously unknown vulnerabilities across major operating systems and web browsers. This revelation prompted Japan's financial authorities, including the Financial Services Agency and the Bank of Japan, to establish a task force aimed at mitigating potential cybersecurity threats to the nation's financial infrastructure. The task force's formation underscores the urgency of addressing AI-driven cyber risks in a sector heavily reliant on interconnected and legacy systems. The emergence of AI models like Claude Mythos signifies a paradigm shift in cybersecurity, where the speed and sophistication of potential attacks could outpace traditional defense mechanisms. Financial institutions worldwide are now compelled to reassess and fortify their security postures to counteract the evolving threat landscape posed by advanced AI capabilities.
4 months ago
Kill Chain
U.S. Government Targets Southeast Asian Cyber Scam Networks Exploiting Forced Labor
In April 2026, the U.S. government executed a coordinated crackdown on Southeast Asian cyber scam operations targeting American citizens. This initiative led to the indictment of two Chinese nationals managing a scam compound in Myanmar, sanctions against 29 individuals—including a Cambodian senator—and the seizure of over 500 fraudulent investment websites. These operations exploited forced labor to conduct social engineering attacks, deceiving victims into transferring funds to fake cryptocurrency investment platforms. The financial impact on American victims was substantial, with losses amounting to billions of dollars. This incident underscores the escalating threat posed by transnational cybercrime networks employing sophisticated social engineering tactics. The involvement of high-ranking officials and the use of forced labor highlight the complexity and scale of these operations. It also reflects the increasing collaboration between international law enforcement agencies to combat such threats, emphasizing the need for continuous vigilance and adaptive cybersecurity measures.
5 months ago
Kill Chain
Toronto Authorities Dismantle SMS Blaster Operation, Arrest Three
In April 2026, Canadian authorities arrested three individuals in Toronto for operating an 'SMS blaster' device that impersonated legitimate cellular towers to send phishing text messages to nearby mobile phones. These devices tricked phones into connecting by emitting stronger signals, allowing operators to distribute fraudulent messages appearing to come from trusted entities like banks or government agencies. The investigation, dubbed 'Project Lighthouse,' revealed that the operation led to 13 million instances of mobile network entrapment, temporarily disconnecting devices from their legitimate networks and potentially blocking access to emergency services. This incident underscores the evolving tactics of cybercriminals in exploiting mobile network vulnerabilities. The use of mobile SMS blasters represents a significant escalation in smishing attacks, highlighting the need for enhanced security measures and public awareness to mitigate such threats.
5 months ago
Kill Chain
Deepfake Voice Attacks: The Rising Threat in 2025
In March 2025, a finance director at a multinational firm in Singapore participated in a Zoom call with individuals appearing as her senior leadership team, including the CFO. Unbeknownst to her, all participants were AI-generated deepfakes. She authorized a $499,000 transfer before the fraud was detected. This incident mirrors a 2024 attack on Arup, where $25.6 million was stolen using similar deepfake techniques. The proliferation of deepfake technology has led to a 680% increase in voice deepfake incidents in 2025, with over 100,000 attacks recorded in the United States alone. The accessibility of these tools, which require minimal audio samples and no technical expertise, underscores the urgent need for organizations to implement robust verification protocols and employee training to mitigate such sophisticated social engineering threats.
5 months ago
Kill Chain
Inside an OPSEC Playbook: How Threat Actors Evade Detection
In April 2026, cybersecurity researchers uncovered a detailed operational security (OPSEC) playbook authored by a threat actor specializing in high-volume carding operations. This playbook outlines a three-tier infrastructure model designed to evade detection: a public layer utilizing clean devices and rotating residential IPs, an operational layer with encrypted containers and dedicated infrastructure, and an extraction layer focused on isolated, air-gapped systems for monetization. The document also highlights common OPSEC failures, such as identity reuse and inadequate digital fingerprinting countermeasures, and recommends advanced techniques like time-delayed triggers and behavioral randomization to enhance operational resilience. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/inside-an-opsec-playbook-how-threat-actors-evade-detection/amp/?utm_source=openai)) This revelation underscores a significant shift in cybercriminal strategies towards more structured and methodical approaches to maintain long-term operational security. For defenders, understanding these sophisticated OPSEC frameworks is crucial to developing more effective detection and mitigation strategies against evolving cyber threats.
5 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports