✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Capital Markets/Hedge Fund/Private Equity
Breach intelligence, attack campaigns, and threat reports targeting the Capital Markets/Hedge Fund/Private Equity sector.
Explore Other Sectors
Capital Markets/Hedge Fund/Private Equity Threat Reports
Balancer DeFi Protocol Hit by $128M Crypto Heist: How the 2023 Breach Happened
In August 2023, the Balancer DeFi protocol suffered a sophisticated cyberattack when unidentified hackers exploited vulnerabilities in its v2 pools’ smart contract logic. By manipulating pool configurations and utilizing flash loans, attackers drained over $128 million worth of cryptocurrency assets. Balancer immediately paused affected pools, notified users, and worked to contain losses. The exploit drew industry-wide concern due to the depth and speed of the attack, which bypassed several security checks and resulted in substantial losses for protocol users and liquidity providers. This incident underscores the growing security challenges facing decentralized finance platforms, as attackers increasingly target smart contracts and protocol logic. The Balancer breach highlights the need for advanced anomaly detection, smart contract auditing, and zero trust security controls in Web3 environments as DeFi adoption accelerates.
6 months ago
Kill Chain
LinkedIn Phishing Scam Exploits Finance Executives with Fake Board Invites
In May 2024, attackers launched a highly targeted phishing campaign abusing LinkedIn’s direct messaging system to impersonate executive board invitations and target finance executives. The phishing messages enticed victims to a spoofed Microsoft authentication page designed to steal their credentials. These attacks demonstrated careful social engineering, relying on the professional trust inherent to LinkedIn. Stolen credentials could be leveraged for unauthorized access to sensitive corporate financial data or for follow-on business email compromise attacks, creating substantial business risk and potential regulatory exposure. This incident underscores an ongoing surge in sophisticated, identity-driven phishing attacks against senior business leadership. As attackers increasingly exploit trusted professional platforms and personalize their lures, organizations face mounting pressure to adopt advanced detection, multi-factor authentication, and user awareness to counter modern credential theft threats.
- Banking/Mortgage
- Capital Markets/Hedge Fund/Private Equity
- Investment Management/Hedge Fund/Private Equity
6 months ago
Kill Chain
Fake Homebrew and LogMeIn Sites Spread Infostealer Malware via Google Ads in 2025
In October 2025, a sophisticated malvertising campaign exploited Google Ads to distribute infostealing malware via fake Homebrew, LogMeIn, and TradingView websites targeting macOS users and developers. The threat actors registered over 85 convincing domains and lured victims to enter terminal commands that downloaded malware such as AMOS (Atomic macOS Stealer) and Odyssey Stealer. Once executed, these payloads bypassed security controls, harvested browser credentials, cryptocurrency wallets, and sensitive files, and forwarded the stolen data to threat actor-controlled servers. This campaign underscores the effectiveness of ClickFix social engineering techniques and highlights the risks of trust in search advertising. The incident is particularly relevant as infostealer malware continues to evolve with new tactics, including sophisticated social engineering, supply chain targeting, and persistent access capabilities. Organizations face increasing pressure to defend against rapidly shifting malware delivery channels and enforce user education to reduce the likelihood of compromise.
6 months ago
Kill Chain
UK’s £5.5B Bitcoin Seizure: ‘Bitcoin Queen’ Convicted in Landmark Crypto Laundering Case
In September 2025, UK authorities secured a conviction in the world’s largest cryptocurrency seizure, arresting Zhimin Qian, also known as "Bitcoin Queen," for orchestrating a multi-billion pound fraudulent Bitcoin investment scheme between 2014 and 2017. Promising returns of up to 300%, Qian defrauded over 128,000 victims in China, amassing 40 billion yuan, which she later converted into Bitcoin and laundered through the UK after fleeing China. Metropolitan Police seized 61,000 Bitcoin—worth over £5.5 billion today—after a complex multi-year investigation involving international law enforcement and property laundering attempts. This landmark case highlights both the scale and sophistication of modern financial cybercrime, underscoring the growing global focus on cryptocurrency abuse for money laundering. As regulators and law enforcement agencies adapt, similar techniques threaten new sectors and jurisdictions, making robust compliance, asset tracing, and cross-border cooperation critical in cyber risk management.
6 months ago
Kill Chain
Eurojust 2025: €100M Cryptocurrency Fraud Unraveled Across 23 Countries
In September 2025, Eurojust and European law enforcement agencies coordinated the arrest of five individuals linked to an extensive cryptocurrency investment fraud ring that defrauded victims of over €100 million ($118 million) across at least 23 countries. Operating mainly out of Spain, Portugal, Italy, Romania, and Bulgaria, the suspects lured victims with promises of high returns from fake crypto investment platforms before illegally transferring funds using sophisticated laundering channels. The campaign targeted high-net-worth individuals in France, Germany, Italy, and Spain, and the operation included simultaneous raids and seizures of assets, including bank accounts and electronic devices. This case highlights the persistent threat of cross-border financial crimes leveraging digital currencies and online investment schemes. The complexity and scale of the operation reflect a broader shift towards technology-enabled fraud, making swift international law enforcement collaboration and strong cyber defense practices more critical than ever.
- Investment Banking/Venture
- Capital Markets/Hedge Fund/Private Equity
- Investment Management/Hedge Fund/Private Equity
6 months ago
Kill Chain
2025's Multichannel Phishing Campaigns: The End of Email-Only Defense
In September 2025, organizations experienced a surge of sophisticated credential harvesting attacks that moved beyond traditional email phishing, utilizing instant messaging, social media, and malicious advertising channels. Attackers deployed advanced Attacker-in-the-Middle (AiTM) phishing kits and leveraged compromised accounts, cloned login pages, and rapid domain rotation to evade both detection and remediation. Case studies included targeted spear-phishing via LinkedIn and malvertising on Google Search, resulting in high-value session theft and lateral account compromise. These attacks not only bypassed email security but exploited any channel where business users could be reached, often leading to the breach of core cloud platforms and widespread internal access. This campaign marks a critical evolution in attacker tactics, underlining that perimeter-focused and email-only defenses are insufficient. The surge in non-email phishing brings new urgency for organizations to secure east-west traffic, implement zero trust segmentation, and enhance visibility across all cloud and SaaS environments.
6 months ago
Kill Chain
Scattered Spider Returns: New Wave of Social Engineering Attacks on Financial Services
In late 2025, cybersecurity researchers at ReliaQuest linked a new wave of attacks in the financial services sector to the notorious cybercrime collective Scattered Spider, despite previous claims that the group had disbanded. These attacks featured advanced social engineering tactics, the registration of lookalike domains, and exploitation of internal access paths to facilitate credential compromise and lateral movement inside targeted organizations. Impact resulted in unauthorized access to sensitive financial data, disruption of key operations, and raised concerns about the sector’s preparedness for sophisticated, identity-driven threats. The re-emergence of Scattered Spider underscores a resurgence of high-profile, financially motivated cybercrime against critical industries. The campaign highlights the evolving threat landscape—where even 'retired' threat groups rapidly adapt their tactics—reinforcing the urgency of east-west security monitoring, identity protections, and robust zero trust strategies.
6 months ago
Kill Chain
GodRAT: New RAT Targets Financial Institutions via Skype with Evolved Tactics in 2024
In late 2024, a targeted campaign leveraged a new remote access trojan, GodRAT, to infiltrate trading and brokerage firms across Hong Kong, the UAE, and other countries. Attackers, likely linked to the Winnti APT group, distributed malicious .scr and .pif files disguised as financial documents via Skype. These files deployed GodRAT—an evolved variant of Gh0st RAT—using innovative techniques like steganography to evade detection. Once inside victim networks, the campaign used file management plugins and browser password stealers to exfiltrate sensitive credentials, while also deploying secondary implants such as AsyncRAT for persistent control. This ongoing incident highlights both the durability of legacy RAT codebases and the adaptability of threat actors employing advanced delivery and evasion tactics. It reflects a wider trend where financial institutions face persistent threats from intelligent, identity- and credential-focused attacks using proven malware frameworks.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports