The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Banking/Mortgage
Breach intelligence, attack campaigns, and threat reports targeting the Banking/Mortgage sector.
Explore Other Sectors
Banking/Mortgage Threat Reports
QuickLens Chrome Extension Compromised: A Cautionary Tale for Browser Security
In February 2026, the 'QuickLens - Search Screen with Google Lens' Chrome extension, initially a legitimate tool with approximately 7,000 users, was compromised following a change in ownership. The new version 5.8 introduced malicious scripts that stripped browser security headers and executed arbitrary JavaScript, enabling the theft of cryptocurrency wallets and sensitive user data. This incident underscores the risks associated with browser extensions, particularly those that undergo ownership changes, and highlights the need for vigilant monitoring of software supply chains to prevent similar attacks.
6 months ago
Kill Chain
AI-Powered Fake ID Operation Dismantled: Ukrainian Operator Pleads Guilty
In February 2026, Ukrainian national Yurii Nazarenko pleaded guilty to operating OnlyFake, an AI-driven website that generated and sold over 10,000 counterfeit identification documents globally. The platform allowed users to create realistic digital versions of passports, driver's licenses, and Social Security cards, which were primarily used to bypass Know Your Customer (KYC) verification processes at financial institutions and cryptocurrency exchanges. Nazarenko was extradited from Romania in September 2025, agreed to forfeit $1.2 million, and faces a maximum sentence of 15 years in prison, with sentencing scheduled for June 26, 2026. This case underscores the growing misuse of artificial intelligence in facilitating sophisticated cybercrimes, particularly in identity fraud. The incident highlights the urgent need for enhanced security measures and regulatory frameworks to address AI-powered threats in the digital landscape.
7 months ago
Kill Chain
DoJ Seizes $61 Million in Tether Linked to Pig Butchering Crypto Scams
In February 2026, the U.S. Department of Justice (DoJ) seized over $61 million in Tether (USDT) linked to 'pig butchering' cryptocurrency scams. These schemes involved fraudsters building trust with victims through fake romantic relationships, then persuading them to invest in fraudulent cryptocurrency platforms that displayed fabricated high returns. When victims attempted to withdraw funds, they were met with demands for additional fees, leading to further financial loss. The seized funds were traced to cryptocurrency addresses used to launder proceeds from these scams. ([justice.gov](https://www.justice.gov/usao-ednc/pr/us-attorneys-office-ednc-announces-seizure-61-million-dollars-worth-cryptocurrency?utm_source=openai)) This incident underscores the growing prevalence of sophisticated social engineering tactics in financial fraud, particularly within the cryptocurrency sector. It highlights the need for increased vigilance and regulatory measures to protect individuals from such deceptive practices.
7 months ago
Kill Chain
Cisco SD-WAN Zero-Day Exploited Since 2023
In February 2026, Cisco disclosed a critical zero-day vulnerability (CVE-2026-20127) in its Catalyst SD-WAN Controller and Manager, which had been actively exploited since at least 2023. The flaw allowed unauthenticated remote attackers to bypass authentication mechanisms, granting them high-privileged access to manipulate network configurations via the NETCONF protocol. This exploitation enabled the addition of rogue peers and potential disruption of network operations. ([thehackernews.com](https://thehackernews.com/2026/02/cisco-sd-wan-zero-day-cve-2026-20127.html?utm_source=openai)) The incident underscores the persistent targeting of network infrastructure by sophisticated threat actors, emphasizing the need for organizations to prioritize timely patching and robust security measures to protect critical systems. ([thehackernews.com](https://thehackernews.com/2026/02/cisco-sd-wan-zero-day-cve-2026-20127.html?utm_source=openai))
7 months ago
Kill Chain
Iran's 2026 Internet Blackout: A New Era of Digital Repression
In January 2026, the Iranian government imposed a comprehensive internet blackout amid escalating nationwide protests. This shutdown disrupted all forms of digital communication, including mobile networks, landlines, and even satellite services like Starlink. The blackout aimed to suppress the coordination of protests and conceal human rights violations. Concurrently, Iran implemented a two-tiered internet system, granting unrestricted access to government officials and loyalists via 'white SIM cards,' while the general populace faced severe restrictions. This strategy effectively isolated citizens, preventing both internal coordination and external information dissemination. The incident underscores a growing trend among authoritarian regimes to leverage internet control as a tool for social suppression. The international community has condemned these actions, emphasizing the need for global efforts to uphold internet freedom and human rights.
7 months ago
Kill Chain
Recorded Future and CYBERA Join Forces to Tackle Escalating Money Mule Fraud
In February 2026, Recorded Future announced an expansion of its payment fraud prevention capabilities through a partnership with CYBERA, a leader in detecting and verifying data on scam-linked bank accounts. This collaboration introduces Money Mule Intelligence, a tool designed to help fraud teams identify accounts used by criminals to extract and move stolen funds. The initiative addresses the escalating threat of Authorized Push Payment (APP) fraud, which is projected to reach nearly $15 billion in the U.S. by 2028, up from $8.3 billion in 2024. The rise in APP fraud is driven by factors such as AI-generated deepfakes, personalized scam scripts, and instant payment systems that outpace traditional fraud controls. Money mule accounts serve as critical infrastructure for these scams, enabling the conversion of stolen payments into untraceable cash or cryptocurrency. The sophistication of mule operations has increased, with criminals employing 'mule herders' who manage numerous accounts and use AI to simulate normal transaction behavior, making detection challenging. Regulators are responding by shifting liability to banks, emphasizing the need for proactive detection and disruption of mule accounts to prevent fraud and comply with emerging reimbursement requirements.
7 months ago
Kill Chain
Marquis Software Solutions Ransomware Attack: A Supply Chain Vulnerability Exposed
In August 2025, Marquis Software Solutions, a Texas-based fintech firm serving over 700 financial institutions, experienced a ransomware attack that compromised sensitive data of more than 780,000 individuals across at least 80 banks and credit unions. The attackers exploited a vulnerability in SonicWall's firewall backup service, gaining unauthorized access to Marquis's network and exfiltrating personal information, including names, addresses, Social Security numbers, and financial account details. This breach underscores the critical importance of securing third-party services and the potential cascading effects of supply chain vulnerabilities. The incident highlights the growing trend of cybercriminals targeting supply chain weaknesses to infiltrate organizations, emphasizing the need for comprehensive security assessments and robust vendor management practices to mitigate such risks.
7 months ago
Kill Chain
Understanding TOAD Attacks: Bypassing Email Security Through Social Engineering
In early 2025, cybercriminals escalated the use of Telephone-Oriented Attack Delivery (TOAD) techniques to bypass traditional email security measures. These attacks involve sending emails that appear to be from legitimate services, such as Microsoft Entra, Zoom, or Hulu+, containing fake invoices or alerts with a phone number for recipients to call. Upon calling, victims are connected to fraudulent call centers where they are manipulated into downloading remote access software, granting attackers control over their systems. This method effectively circumvents email filters by excluding malicious links or attachments, relying instead on social engineering tactics to exploit human trust. ([cybernews.com](https://cybernews.com/security/new-toad-phishing-campaign-targets-microsoft-entra-invitees-with-fake-invoices/?utm_source=openai)) The prevalence of TOAD attacks underscores a significant shift in phishing strategies, emphasizing the need for organizations to enhance their security awareness training and adopt multi-layered defense mechanisms. As these attacks exploit trusted communication channels and human psychology, traditional technical defenses alone are insufficient, highlighting the urgency for comprehensive security approaches that address both technological and human factors. ([phishcloud.com](https://phishcloud.com/toad-phishing-attack-prevention/?utm_source=openai))
7 months ago
Kill Chain
Operation Red Card 2.0: A Landmark Cybercrime Crackdown in Africa
Between December 8, 2025, and January 30, 2026, Operation Red Card 2.0, coordinated by INTERPOL, led to the arrest of 651 individuals across 16 African countries, including Nigeria and Kenya. The operation targeted high-yield investment scams, mobile money fraud, and fraudulent mobile loan applications, resulting in the recovery of over $4.3 million and the dismantling of 1,442 malicious infrastructures. Investigations revealed financial losses exceeding $45 million, affecting 1,247 victims globally. Notable actions included the dismantling of a high-yield investment fraud ring in Nigeria and the arrest of 27 individuals in Kenya linked to scams exploiting messaging apps and social media platforms. ([nairametrics.com](https://nairametrics.com/2026/02/19/interpol-backed-operation-recovers-4-3m-from-cybercrime-in-nigeria-kenya-others/?utm_source=openai)) This operation underscores the escalating threat of cybercrime in Africa, driven by rapid digitalization and the proliferation of online financial services. The success of Operation Red Card 2.0 highlights the critical importance of international collaboration and intelligence sharing in combating transnational cyber threats. Organizations are urged to enhance their cybersecurity measures and remain vigilant against evolving cybercriminal tactics.
7 months ago
Kill Chain
UAC-0050's Expansion: European Financial Institution Targeted with RMS Malware
In February 2026, the Russia-aligned threat actor UAC-0050, also known as Mercenary Akula, targeted a European financial institution involved in regional development and reconstruction initiatives. The attack began with a spear-phishing email that spoofed a Ukrainian judicial domain, directing the recipient—a senior legal and policy advisor—to download a malicious archive file. This file initiated a multi-layered infection chain, ultimately deploying the Remote Manipulator System (RMS), a legitimate remote desktop software, granting the attackers persistent and stealthy access to the victim's system. This incident underscores a significant shift in UAC-0050's operations, expanding their focus beyond Ukraine to entities supporting the nation. The use of legitimate remote access tools like RMS highlights the evolving tactics of threat actors to evade detection. Organizations, especially those involved in sensitive geopolitical areas, must remain vigilant against such sophisticated social engineering attacks.
7 months ago
Kill Chain
ATM Jackpotting Attacks Surge in 2025, Resulting in Over $20 Million in Losses
In 2025, the United States experienced a significant surge in ATM "jackpotting" attacks, with over 700 incidents reported, resulting in losses exceeding $20 million. ([thehackernews.com](https://thehackernews.com/2026/02/fbi-reports-1900-atm-jackpotting.html?utm_source=openai)) These attacks involve criminals gaining physical access to ATMs, often using generic keys to open the machines. Once inside, they install or replace hard drives with malware, such as the Ploutus family, which exploits the eXtensions for Financial Services (XFS) API to dispense cash without bank authorization. ([livemint.com](https://www.livemint.com/news/world/fbi-warns-of-rising-atm-jackpotting-cases-reports-20-million-in-losses-in-2025-5-indicators-to-detect-foul-play-11771729139858.html?utm_source=openai)) This alarming trend underscores the evolving tactics of cybercriminals targeting financial institutions. The FBI has issued warnings and recommended mitigation strategies, including enhancing physical security measures, regularly updating ATM software, and monitoring for unauthorized access, to combat this growing threat. ([thehackernews.com](https://thehackernews.com/2026/02/fbi-reports-1900-atm-jackpotting.html?utm_source=openai))
7 months ago
Kill Chain
CEO Deepfake Scam 2019: A Wake-Up Call for Corporate Security
In March 2019, a UK-based energy firm's CEO was deceived by a deepfake audio impersonation of his German parent company's chief executive. The fraudster, using AI-generated voice technology, instructed the CEO to transfer €220,000 (approximately $243,000) to a Hungarian supplier's account. Believing the request was legitimate, the CEO complied. Subsequent attempts for additional transfers raised suspicions, leading to the discovery of the scam. The initial funds were moved from Hungary to Mexico and then dispersed to other locations, making recovery challenging. ([forbes.com](https://www.forbes.com/sites/jessedamiani/2019/09/03/a-voice-deepfake-was-used-to-scam-a-ceo-out-of-243000/?utm_source=openai)) This incident underscores the escalating threat of AI-driven deepfake technologies in corporate fraud. As these tools become more sophisticated and accessible, organizations face increased risks of impersonation attacks targeting financial transactions and sensitive information. The event highlights the urgent need for enhanced security measures and employee training to detect and prevent such advanced social engineering tactics.
7 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports