The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Banking/Mortgage

Breach intelligence, attack campaigns, and threat reports targeting the Banking/Mortgage sector.

558 threat reports
Page 27 of 47

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Banking/Mortgage Threat Reports

Showing 313–324 / 558 reports
GoPIX Banking Trojan: A New Threat to Brazil's PIX Payment System
Impact· MEDIUM

GoPIX Banking Trojan: A New Threat to Brazil's PIX Payment System

In December 2022, the GoPIX banking Trojan emerged, targeting users of Brazil's PIX instant payment system. Disguised as a WhatsApp Web installer, it spread through malicious ads, leading victims to download malware that intercepts and manipulates PIX transactions. GoPIX employs sophisticated techniques, including IP Quality Score's anti-fraud tools, to evade detection and ensure successful infections. ([usa.kaspersky.com](https://usa.kaspersky.com/about/press-releases/kaspersky-crimeware-report-reveals-new-rhysida-ransomware-lumar-stealer-and-gopix-banking-malware?utm_source=openai)) The rise of GoPIX underscores a growing trend of cybercriminals exploiting popular payment systems in Latin America. Its advanced evasion methods and focus on real-time transaction manipulation highlight the need for enhanced security measures and user awareness to combat such evolving threats. ([usa.kaspersky.com](https://usa.kaspersky.com/about/press-releases/kaspersky-crimeware-report-reveals-new-rhysida-ransomware-lumar-stealer-and-gopix-banking-malware?utm_source=openai))

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Quantum Computing's 2026 Breakthrough: A Call to Action for Cryptographic Security
Impact· MEDIUM

Quantum Computing's 2026 Breakthrough: A Call to Action for Cryptographic Security

In March 2026, a new theoretical advancement in quantum factorization was reported, suggesting a potential acceleration in the ability of quantum computers to factor large numbers. This development raises concerns about the security of RSA encryption, which relies on the difficulty of factoring large integers. If quantum computers can perform this task efficiently, they could decrypt data protected by RSA, compromising sensitive information across various sectors. The urgency of this issue is underscored by the increasing feasibility of quantum computing technologies. Organizations must proactively assess their cryptographic infrastructures and consider transitioning to quantum-resistant algorithms to safeguard against future threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Exposing the Vulnerabilities in Facial Recognition Systems: A 2026 Analysis
Impact· CRITICAL

Exposing the Vulnerabilities in Facial Recognition Systems: A 2026 Analysis

In March 2026, cybersecurity expert Jake Moore demonstrated multiple methods to bypass facial recognition systems, highlighting significant vulnerabilities in this widely adopted technology. Utilizing modified smart glasses, Moore identified individuals in public spaces by matching their faces to online data sources in real-time. He also successfully opened a bank account using an AI-generated image, which was accepted by the bank's facial recognition and eKYC platform. Additionally, by employing real-time face swap software, Moore evaded detection by a facial recognition watchlist at a London train station. These experiments underscore the ease with which facial recognition systems can be deceived using readily available tools and techniques. The increasing reliance on facial recognition for security and authentication purposes necessitates a critical evaluation of its robustness. Moore's findings serve as a wake-up call for organizations to reassess the effectiveness of their biometric security measures and to consider implementing additional safeguards to mitigate potential exploitation.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Operation Synergia III: A Landmark in Global Cybercrime Enforcement
Impact· HIGH

Operation Synergia III: A Landmark in Global Cybercrime Enforcement

Between July 2025 and January 2026, INTERPOL coordinated Operation Synergia III, a global initiative involving 72 countries aimed at dismantling cybercriminal infrastructures. The operation resulted in the sinkholing of 45,000 malicious IP addresses, seizure of 212 electronic devices and servers, and the arrest of 94 individuals, with an additional 110 suspects under investigation. Notable actions included the arrest of 10 individuals in Togo involved in social engineering schemes and the identification of over 33,000 phishing websites in Macau impersonating financial institutions to steal sensitive information. This operation underscores the escalating sophistication and global reach of cybercrime, highlighting the necessity for international collaboration in combating these threats. The success of Operation Synergia III demonstrates the effectiveness of coordinated efforts in disrupting cybercriminal networks and mitigating their impact on global security.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
INTERPOL's Global Crackdown: 45,000 Malicious IPs Dismantled, 94 Arrested
Impact· HIGH

INTERPOL's Global Crackdown: 45,000 Malicious IPs Dismantled, 94 Arrested

Between July 18, 2025, and January 31, 2026, INTERPOL coordinated a global operation involving 72 countries, resulting in the dismantling of 45,000 malicious IP addresses and servers associated with phishing, malware, and ransomware activities. This effort led to the arrest of 94 individuals and the seizure of 212 electronic devices and servers. Notable actions included the arrest of 40 suspects in Bangladesh linked to various cybercrimes and the identification of over 33,000 fraudulent websites in Macau targeting critical infrastructure. This operation underscores the escalating threat of transnational cybercrime and the necessity for coordinated international responses. The increasing sophistication and scale of cybercriminal activities highlight the urgent need for enhanced cybersecurity measures and global cooperation to protect individuals and organizations from emerging digital threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
VENON Malware: A New Rust-Based Threat Targeting Brazilian Banks
Impact· HIGH

VENON Malware: A New Rust-Based Threat Targeting Brazilian Banks

In March 2026, cybersecurity researchers identified a new banking malware named VENON, written in Rust, targeting 33 Brazilian financial institutions. VENON employs sophisticated techniques, including DLL side-loading and credential-stealing overlays, to compromise Windows systems. The malware's distribution method involves social engineering tactics, such as enticing users to download malicious ZIP archives via PowerShell scripts. Once executed, VENON performs multiple evasion techniques before establishing a connection to its command-and-control server, enabling remote control over infected systems. This incident underscores a significant shift in the Latin American cybercrime landscape, with threat actors adopting advanced programming languages like Rust to enhance malware capabilities and evade detection. The emergence of VENON highlights the evolving sophistication of banking trojans in the region, necessitating heightened vigilance and advanced security measures among financial institutions.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Meta's 2026 Crackdown on Southeast Asia Scam Networks
Impact· LOW

Meta's 2026 Crackdown on Southeast Asia Scam Networks

In March 2026, Meta, in collaboration with international law enforcement agencies, disabled over 150,000 Facebook and Instagram accounts linked to sophisticated scam centers operating in Southeast Asia. This coordinated effort, involving authorities from countries including Thailand, the U.S., the U.K., and Singapore, also led to 21 arrests by the Royal Thai Police. The crackdown targeted criminal networks in countries like Cambodia, Myanmar, and Laos, which have been running large-scale scam operations designed to evade detection and cause significant harm to individuals globally. ([about.fb.com](https://about.fb.com/news/2026/03/meta-global-law-enforcement-disrupt-major-southeast-asia-criminal-scam-networks/?utm_source=openai)) This operation underscores the escalating threat posed by industrialized online scams and highlights the necessity for continuous collaboration between tech companies and global law enforcement to protect users from increasingly sophisticated fraudulent activities. ([about.fb.com](https://about.fb.com/news/2026/03/meta-global-law-enforcement-disrupt-major-southeast-asia-criminal-scam-networks/?utm_source=openai))

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
UniPass Wallet's 2023 Account Abstraction Vulnerability: A Critical Security Lesson
Impact· MEDIUM

UniPass Wallet's 2023 Account Abstraction Vulnerability: A Critical Security Lesson

In October 2023, Fireblocks researchers identified a critical vulnerability in UniPass's ERC-4337 smart contract wallets, allowing attackers to take full control by replacing the trusted EntryPoint. This flaw exposed hundreds of wallets to potential fund drainage. The UniPass team promptly executed a white-hat operation to secure all affected wallets and implemented necessary fixes to prevent future exploits. This incident underscores the importance of rigorous security audits in the rapidly evolving landscape of smart contract wallets. As account abstraction gains traction, ensuring the integrity of foundational components like EntryPoint is paramount to safeguard user assets.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Understanding LummaC2: The 2025 Advanced Evasion Malware
Impact· MEDIUM

Understanding LummaC2: The 2025 Advanced Evasion Malware

In 2025, LummaC2 emerged as a highly sophisticated information-stealing malware targeting Windows systems. Distributed through phishing emails, malicious advertisements, and compromised software, LummaC2 exfiltrated sensitive data, including browser credentials and cryptocurrency wallets. Notably, its v4.0 introduced advanced evasion techniques, such as trigonometry-based anti-sandbox mechanisms that detect human-like mouse movements to avoid detection. This evolution underscores a significant shift towards stealthy, persistent cyber threats that can bypass traditional security measures. The rise of LummaC2 highlights the increasing sophistication of malware-as-a-service platforms, enabling even low-skilled threat actors to deploy advanced attacks. Organizations must enhance their security postures by adopting proactive threat detection and response strategies to mitigate such evolving threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
BeatBanker Malware: A New Threat to Android Devices in 2026
Impact· HIGH

BeatBanker Malware: A New Threat to Android Devices in 2026

In March 2026, cybersecurity researchers identified a new Android malware named BeatBanker, which masquerades as a legitimate Starlink application to infiltrate devices. Once installed, BeatBanker combines banking trojan functionalities with Monero cryptocurrency mining capabilities. It can steal user credentials, manipulate cryptocurrency transactions, and grant attackers full remote control over the infected device. The malware employs sophisticated evasion techniques, including playing an inaudible audio file on a loop to maintain persistence and monitoring device conditions to optimize its operations without raising suspicion. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/new-beatbanker-android-malware-poses-as-starlink-app-to-hijack-devices/?utm_source=openai)) This incident underscores the evolving sophistication of mobile malware, highlighting the need for heightened vigilance among users and organizations. The use of legitimate app disguises and advanced persistence mechanisms signifies a trend towards more covert and resilient cyber threats targeting mobile platforms.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
BeatBanker: The Dual-Mode Android Malware Threatening Brazilian Users in 2026
Impact· HIGH

BeatBanker: The Dual-Mode Android Malware Threatening Brazilian Users in 2026

In March 2026, cybersecurity researchers identified 'BeatBanker,' a sophisticated Android malware campaign targeting users in Brazil. Disguised as legitimate applications, including a fake Google Play Store and a counterfeit Starlink app, BeatBanker employs phishing tactics to infiltrate devices. Once installed, it operates as both a cryptocurrency miner and a banking Trojan, enabling attackers to hijack devices, steal financial credentials, and manipulate cryptocurrency transactions. Notably, the malware maintains persistence by continuously playing an inaudible audio file, preventing system termination. The campaign has evolved to deploy the BTMOB remote administration tool, granting attackers full control over compromised devices. This incident underscores the escalating complexity of mobile malware threats and the critical need for users to download apps exclusively from official sources, scrutinize app permissions, and keep their systems updated to mitigate such risks.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Cybercriminals Exploit .arpa Domains and IPv6 to Bypass Phishing Defenses
Impact· MEDIUM

Cybercriminals Exploit .arpa Domains and IPv6 to Bypass Phishing Defenses

In March 2026, cybersecurity researchers identified a sophisticated phishing campaign exploiting the .arpa top-level domain (TLD) and IPv6 reverse DNS to bypass traditional security measures. Attackers acquired IPv6 address blocks and manipulated reverse DNS zones to create deceptive subdomains under the ip6.arpa domain. These subdomains hosted phishing sites that impersonated legitimate brands, luring victims through emails promising rewards or account notifications. The use of .arpa domains, typically reserved for internet infrastructure, allowed these malicious sites to evade detection by standard domain reputation checks and email security gateways. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/hackers-abuse-arpa-dns-and-ipv6-to-evade-phishing-defenses/?utm_source=openai)) This incident underscores a growing trend where threat actors exploit lesser-known internet protocols and infrastructure to conduct attacks. The abuse of reserved domains like .arpa highlights the need for enhanced monitoring and security measures that encompass all facets of the DNS ecosystem. Organizations must adapt to these evolving tactics to protect against increasingly sophisticated phishing schemes. ([infoblox.com](https://www.infoblox.com/blog/threat-intelligence/abusing-arpa-the-tld-that-isnt-supposed-to-host-anything/?utm_source=openai))

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports