The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Banking/Mortgage

Breach intelligence, attack campaigns, and threat reports targeting the Banking/Mortgage sector.

558 threat reports
Page 40 of 47

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Banking/Mortgage Threat Reports

Showing 469–480 / 558 reports
Yanluowang Ransomware & Access Broker Target U.S. Firms: Volkov Convicted
Impact· high

Yanluowang Ransomware & Access Broker Target U.S. Firms: Volkov Convicted

Between July 2021 and November 2022, multiple U.S. businesses—including an engineering firm and a bank—were targeted by the Yanluowang ransomware group, using access broker Aleksei Olegovich Volkov to gain initial entry. Volkov, operating as “chubaka.kor,” exploited vulnerabilities in victim networks, facilitated data theft and encryption, and coordinated ransom payments, some of which totaled $1.5 million. Victims suffered operational disruption, including temporary shutdowns and extortion attempts such as DDoS attacks and executive harassment. Forensic analysis linked the activities to Volkov via cryptocurrency tracing and communication evidence; $24 million in ransoms was demanded in total. This case highlights growing cooperation among cybercriminals, where access brokers sell or share footholds with ransomware operators, fueling larger-scale, multi-faceted cyber-extortion campaigns. The high-profile prosecution also sets precedent for international arrests and restitution, amid increasingly aggressive ransomware trends and evolving attack tactics.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
WhatsApp’s Screen-Sharing Feature: The 2024 Social Engineering Scam You Didn’t See Coming
Impact· medium

WhatsApp’s Screen-Sharing Feature: The 2024 Social Engineering Scam You Didn’t See Coming

In early 2024, a growing wave of cyber scams exploited WhatsApp’s new screen-sharing feature. Threat actors, posing as trusted contacts or customer support agents, lured victims into screen-sharing sessions under false pretenses—most often by claiming to offer help or resolve issues. Once shared, attackers gained access to sensitive information displayed on victims’ devices, including banking credentials and one-time passwords (OTPs), resulting in significant financial losses and compromised personal data. The scam’s speed and sophistication allowed fraudsters to bypass traditional awareness training and exploit even tech-savvy users. This incident highlights how social engineering threats adapt quickly to new app features, and underscores the need for rapid security responses. With mobile devices playing a pivotal role in personal and financial life, the exploitation of trusted communication platforms marks a critical evolution in phishing and remote fraud tactics.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Capital One’s 2019 Cloud Breach: Insider Threats & Misconfiguration Risks
Impact· high

Capital One’s 2019 Cloud Breach: Insider Threats & Misconfiguration Risks

In 2019, Capital One suffered a major data breach when Paige Thompson, a former AWS engineer, exploited a cloud misconfiguration—specifically a poorly secured firewall running in Capital One's AWS environment—to access the personal information of over 100 million customers. The attacker leveraged insider knowledge and a misconfigured identity and access management policy to move laterally and exfiltrate sensitive data, including social security numbers and bank account details. The breach resulted in substantial financial costs, regulatory scrutiny, and reputational damage to Capital One, with Thompson ultimately convicted of wire fraud and computer intrusion. This incident remains relevant as organizations increasingly migrate to the cloud and face similar risks of configuration errors, compounded by the complexity of managing access controls and real-time monitoring in cloud-native infrastructures. The Capital One breach exemplifies the critical need for robust cloud security measures and continuous compliance with evolving regulatory requirements.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
US Sanctions North Korean Banks for Cryptocurrency Cybercrime in 2024
Impact· medium

US Sanctions North Korean Banks for Cryptocurrency Cybercrime in 2024

In May 2024, the U.S. Treasury sanctioned two North Korean banks and eight individuals believed to be heavily involved in high-profile cryptocurrency laundering operations linked to state-sponsored cybercrime. The sanctioned parties allegedly laundered millions of dollars in digital assets stolen through cyberattacks and IT worker fraud, often hiding illicit proceeds to evade international detection. North Korean operatives reportedly posed as legitimate IT contractors for Western firms to gain unauthorized access to sensitive systems and divert funds, fueling further malicious operations and funding government programs in Pyongyang. This incident exemplifies shifting tactics in cyber-enabled financial crime, where attackers exploit advanced laundering techniques and foggy compliance areas around cryptocurrency. The urgency of improved detection and policy enforcement is fueled by growing international regulatory pressure and the adaptation of state-sponsored groups to exploit digital infrastructure.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Global Credit Card Fraud Rings Dismantled in Europol-Led €300M Operation
Impact· high

Global Credit Card Fraud Rings Dismantled in Europol-Led €300M Operation

In 2024, international law enforcement agencies, coordinated by Europol, dismantled three interconnected credit card fraud and money laundering rings responsible for more than €300 million in losses, impacting 4.3 million cardholders worldwide across 193 countries. The sophisticated criminal groups orchestrated large-scale thefts using stolen and counterfeit credit card data, leveraging advanced technology and vast dark web networks to execute fraudulent transactions on a global scale. Their activities spanned several years, with victims spread across multiple financial institutions, highlighting significant vulnerabilities in payment security and international collaboration. The bust resulted in arrests, asset seizures, and cut off a major underground economy impacting consumers and businesses. This case illustrates the increasing scale and complexity of financially motivated cybercrime, as threat actors use digital platforms and cross-border tactics to avoid detection. Ongoing regulatory and industry attention to payment fraud and anti-money-laundering measures underscores the need for improved threat detection and international cooperation.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
US Sanctions North Korean Network for $12.7M Crypto Laundering and IT Fraud
Impact· high

US Sanctions North Korean Network for $12.7M Crypto Laundering and IT Fraud

In November 2025, the U.S. Treasury Department sanctioned ten North Korean individuals and entities after uncovering a multi-year scheme involving crypto laundering and IT-related financial fraud totaling $12.7 million. These actors, linked to North Korea’s state-sponsored cyber operations, leveraged encrypted and unencrypted channels to move illicit funds across international financial systems. Their activities supported North Korea’s nuclear weapons ambitions and exploited gaps in network segmentation, egress controls, and threat detection processes. This incident underscores an escalation in nation-state cryptocurrency laundering methods and demonstrates continued exploitation of global IT workforce outsourcing, heightening regulatory focus and increasing the cyber risk to organizations transacting digitally or hiring remote technical staff.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
U.S. Treasury Sanctions North Korean Firms for Cryptocurrency Crime and IT Fraud (2024)
Impact· high

U.S. Treasury Sanctions North Korean Firms for Cryptocurrency Crime and IT Fraud (2024)

In June 2024, the U.S. Treasury Department sanctioned eight individuals and two companies linked to North Korea for laundering proceeds from cybercrime and IT worker schemes. These sanctioned parties allegedly funneled over $3 billion in stolen cryptocurrency and hundreds of millions in illicitly earned IT wages to the North Korean regime, supporting its weapons programs. Entities sanctioned include North Korean banking officials, an IT company operating in China, and financial institution representatives in both China and Russia, all accused of violating international sanctions, managing illicit funds, and enabling large-scale money laundering through sophisticated cyber and identity subterfuge. This incident underscores the advanced capabilities of North Korea’s cyber operations and their direct link to geopolitical threats, as well as the ongoing shift towards state-sponsored cryptocurrency theft and IT fraud as major funding sources for sanctioned regimes.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
European Crypto Fraud Ring Dismantled in €600M Money Laundering Bust (2024)
Impact· high

European Crypto Fraud Ring Dismantled in €600M Money Laundering Bust (2024)

In early 2024, European law enforcement agencies dismantled a sophisticated cryptocurrency fraud ring responsible for laundering over €600 million across multiple countries. Nine suspects were arrested as part of coordinated raids targeting a network that deceived victims via fake crypto investment platforms. The ring used professional call centers and complex money laundering techniques, including anonymized cryptocurrency transfers and shell companies, to obfuscate financial trails. Victims were drawn in via social engineering and manipulated into making significant deposits, resulting in substantial financial losses for businesses and individuals. This incident highlights the escalation of large-scale crypto-based fraud and the growing cross-border collaboration required to counter such threats. The bust underlines the increased scrutiny and regulation of digital asset markets, as attackers adapt fraud and laundering methods to evade detection.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Malicious Android Apps on Google Play Downloaded 42 Million Times: 2024–2025 Mobile Malware Breach
Impact· high

Malicious Android Apps on Google Play Downloaded 42 Million Times: 2024–2025 Mobile Malware Breach

Between June 2024 and May 2025, a widespread mobile malware campaign was uncovered in which hundreds of malicious Android applications were distributed via the official Google Play Store. According to Zscaler, these apps managed to bypass Google’s initial security checks, amassing over 42 million downloads before removal. The attackers embedded various forms of malware—including adware, information stealers, and spyware—into seemingly legitimate apps ranging from utilities to lifestyle tools. Victims experienced invasive ads, data theft, and privacy breaches, affecting both consumers and businesses relying on Android devices within their enterprise environments. This breach underscores mounting challenges in mobile application vetting and the growing sophistication of threat actors targeting official app marketplaces. The scale and reach highlight the ongoing risk of mobile malware, urging organizations and users alike to adopt enhanced threat detection, segmentation, and zero trust practices to mitigate emerging mobile threats.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Inside the 2025 Cybercrime Merger: Scattered Spider, LAPSUS$, and ShinyHunters Unite
Impact· medium

Inside the 2025 Cybercrime Merger: Scattered Spider, LAPSUS$, and ShinyHunters Unite

In August 2025, a powerful new cybercrime collective emerged from the merger of Scattered Spider, LAPSUS$, and ShinyHunters—three of the most notorious threat groups involved in high-profile data theft, ransomware, and extortion. This unified entity quickly established 16 Telegram channels to coordinate attacks, evade platform moderation, and amplify operations. Leveraging advanced social engineering and data exfiltration techniques, the collective launched a string of multinational breaches targeting enterprises, exposing sensitive information and causing significant financial and reputational harm to victims. Security teams observed an uptick in lateral movement, exploitation of hybrid/cloud environments, and sophisticated policy evasion tied to these actors. This incident exemplifies a growing trend where cybercriminal syndicates combine resources and expertise, accelerating the pace and scale of attacks. The merger highlights the urgent need for organizations to adapt to evolving threat actor alliances and reinforces the importance of advanced segmentation, zero trust, and robust monitoring frameworks.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
European Authorities Bust €600M Crypto Fraud Network in Pan-European Operation
Impact· high

European Authorities Bust €600M Crypto Fraud Network in Pan-European Operation

In late October 2025, European authorities led by Europol and Eurojust dismantled a sophisticated cryptocurrency money laundering network responsible for stealing €600 million (around $688 million) through large-scale crypto fraud schemes. The coordinated operation spanned Cyprus, Spain, and Germany, resulting in the arrest of nine suspects linked to elaborate investment scams, phishing, and online fraud. The network leveraged complex cross-border laundering methods, making use of encrypted digital transactions and a web of services to obfuscate stolen funds, ultimately victimizing thousands of individuals across multiple nations. The case spotlights the emergence of organized crime groups exploiting cryptocurrency platforms for large-scale financial fraud and money laundering. It underscores the urgent need for robust regulatory frameworks and advanced monitoring tools, as law enforcement agencies worldwide face growing challenges combating tech-enabled fraud tied to the volatile, largely unregulated crypto sector.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Android BankBot-YNRK: 2024 Indonesian Mobile Wallets Targeted by Muting Malware
Impact· high

Android BankBot-YNRK: 2024 Indonesian Mobile Wallets Targeted by Muting Malware

In 2024, a variant of the Android/BankBot malware known as YNRK targeted mobile users in Indonesia by disguising itself as legitimate applications, often distributed via third-party app stores or phishing campaigns. Once installed, the malware muted system alerts and abused accessibility services to perform unauthorized actions, including theft of credentials and the draining of cryptocurrency and mobile banking wallets. The attack leveraged overlays to capture user inputs and bypassed security mechanisms, resulting in significant financial losses for affected users, with widespread impacts across consumer mobile banking apps in the country. This incident highlights the ongoing evolution and sophistication of mobile banking malware, which increasingly targets emerging markets and exploits weak security controls on non-official app stores. The rapid adoption of mobile wallets and cryptocurrency platforms has made these attacks more lucrative and frequent, intensifying the need for proactive mobile security, user awareness, and regulatory oversight.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports