The Containment Era is here. →Explore

Industry Category

Financial Services

Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.

3529 threat reports
Page 10 of 295

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Financial Services Threat Reports

Showing 109120 / 3529 reports
GoldenEyeDog Subgroup's Infiltration of DigiCert: A Wake-Up Call for Digital Trust
Impact· HIGH

GoldenEyeDog Subgroup's Infiltration of DigiCert: A Wake-Up Call for Digital Trust

In April 2026, DigiCert, a leading Certificate Authority, experienced a security breach attributed to the CylindricalCanine subgroup of the GoldenEyeDog cybercrime group. The attackers infiltrated DigiCert's internal support portal by compromising two support analyst workstations through a malicious screensaver file delivered via a customer chat channel. This access enabled them to issue 27 fraudulent Extended Validation (EV) Code Signing certificates, which were subsequently used to sign malware, notably the Zhong Stealer, facilitating its distribution and evasion of security measures. The incident underscores the critical vulnerabilities within trusted digital infrastructure and the potential for widespread impact when such systems are compromised. ([thehackernews.com](https://thehackernews.com/2026/07/goldeneyedog-subgroup-linked-to.html?utm_source=openai)) This breach highlights a concerning trend of cybercriminals targeting Certificate Authorities to obtain legitimate certificates for malicious purposes. The use of social engineering tactics to exploit support channels emphasizes the need for enhanced security protocols and employee training to prevent similar incidents in the future.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
ViteVenom: Unveiling the Blockchain-Powered Supply Chain Attack on Vite npm Packages
Impact· HIGH

ViteVenom: Unveiling the Blockchain-Powered Supply Chain Attack on Vite npm Packages

In July 2026, cybersecurity researchers identified a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem. This campaign, dubbed ViteVenom, expanded upon the earlier ChainVeil attack by utilizing a sophisticated four-tier blockchain-based command-and-control (C2) infrastructure spanning Tron, Aptos, and Binance Smart Chain. The attackers, attributed to the group SuccessKey, employed this infrastructure to deliver a remote access trojan (RAT) capable of reverse shell operations, credential harvesting, file exfiltration, and persistent backdoor injection. The malicious packages, published between June 29 and July 3, 2026, impersonated legitimate Vite packages, thereby deceiving developers into incorporating them into their projects. This incident underscores the escalating complexity and persistence of supply chain attacks, particularly those leveraging decentralized technologies to evade detection and takedown efforts. The use of blockchain for C2 infrastructure presents significant challenges for traditional security measures, highlighting the need for enhanced vigilance and advanced threat detection capabilities within the software development community.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Salt Typhoon Cyberattack 2024: A Wake-Up Call for Surveillance System Security
Impact· CRITICAL

Salt Typhoon Cyberattack 2024: A Wake-Up Call for Surveillance System Security

In October 2024, the Salt Typhoon cyberattack, allegedly backed by China, targeted U.S. wiretap systems, granting attackers access to sensitive intelligence and law enforcement communications collected by major U.S. internet service providers such as Verizon, AT&T, and Lumen Technologies. The breach exploited systems designed for lawful surveillance, highlighting vulnerabilities in government-mandated surveillance infrastructure. This incident underscores the critical need for robust cybersecurity measures to protect sensitive communication channels from state-sponsored cyber espionage. The Salt Typhoon attack is part of a broader pattern of advanced persistent threats linked to Beijing, raising significant national security concerns regarding foreign access to critical U.S. surveillance infrastructure.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
AI Exploit Highlights Risks of Autonomous Systems in Financial Transactions
Impact· HIGH

AI Exploit Highlights Risks of Autonomous Systems in Financial Transactions

In May 2026, an attacker exploited vulnerabilities in AI systems by sending a Morse code message to Grok, an AI chatbot developed by xAI. Grok decoded the message and relayed it to Bankrbot, an autonomous financial agent, which then executed unauthorized cryptocurrency transactions totaling approximately $200,000. This incident underscores the risks associated with AI systems possessing excessive autonomy and the potential for 'authority laundering,' where AI systems transform untrusted input into authorized actions without adequate oversight. As organizations increasingly integrate AI into critical operations, it is imperative to implement robust governance frameworks to prevent such exploits and ensure AI systems operate within clearly defined authority boundaries.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
BoryptGrab Malware Campaign Exploits Fake GitHub Repositories in 2026
Impact· HIGH

BoryptGrab Malware Campaign Exploits Fake GitHub Repositories in 2026

In July 2026, cybersecurity researchers uncovered a large-scale malware campaign involving 292 fake GitHub repositories impersonating legitimate software projects. These repositories distributed a variant of the BoryptGrab infostealer, which targets sensitive data from web browsers, cryptocurrency wallets, and messaging applications. The malware was delivered through trojanized installers that exploited DLL side-loading techniques, allowing attackers to harvest credentials and financial information from unsuspecting users. The campaign primarily targeted users in the United States, Germany, Romania, and Venezuela, leading to significant data breaches and financial losses. This incident underscores the growing trend of cybercriminals leveraging trusted platforms like GitHub to distribute malware. The sophistication of the campaign, including the use of search engine optimization to promote malicious repositories, highlights the need for enhanced vigilance and verification processes when downloading software from online sources.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Phishing Attacks Exploit Hidden Text to Bypass AI Security Filters
Impact· MEDIUM

Phishing Attacks Exploit Hidden Text to Bypass AI Security Filters

Since April 2026, Barracuda Networks has identified over one million phishing emails employing 'text salting' techniques to evade both traditional and AI-powered email security filters. These emails, often retail-themed, use hidden text within their HTML code to manipulate security gateways, allowing malicious content to bypass detection and reach users' inboxes. ([darkreading.com](https://www.darkreading.com/threat-intelligence/1m-emails-hidden-text-dupe-ai-security-filters?utm_source=openai)) The resurgence of text salting, facilitated by large language models (LLMs), highlights the evolving sophistication of phishing attacks. This trend underscores the need for advanced security measures capable of analyzing the full context of email content, including hidden elements, to effectively combat such evasive tactics. ([blog.barracuda.com](https://blog.barracuda.com/2026/07/16/text-salting-ai-email-security?utm_source=openai))

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Google's Agentic Defense: Revolutionizing Cybersecurity with AI
Impact· LOW

Google's Agentic Defense: Revolutionizing Cybersecurity with AI

In March 2026, Google completed its $32 billion acquisition of cloud security firm Wiz, aiming to enhance its cloud-native security capabilities. Wiz's graph-based analysis technology enables correlation of cloud assets, identities, vulnerabilities, and exposures across multi-cloud environments. This acquisition led to the development of Google's 'agentic defense' platform, which automates threat detection, investigation, and remediation using intelligent security agents. The platform addresses the increasing speed and sophistication of AI-powered cyberattacks by shifting from human-led to AI-led cyber defense strategies. ([darkreading.com](https://www.darkreading.com/cloud-security/google-bets-agentic-defense-strategy-outpace-attackers?utm_source=openai)) The urgency of adopting AI-driven security measures is underscored by the rapid acceleration of machine-based attacks. According to Google Cloud's Mandiant threat detection unit, the average time from initial breach to handoff of access to another threat actor has decreased from 8 hours to just 22 seconds over the past three years. This trend highlights the necessity for organizations to implement automated, AI-driven defense mechanisms to effectively counteract evolving cyber threats. ([darkreading.com](https://www.darkreading.com/cloud-security/google-bets-agentic-defense-strategy-outpace-attackers?utm_source=openai))

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
ACR Stealer's ClickFix Campaign: A Wake-Up Call for Cybersecurity
Impact· HIGH

ACR Stealer's ClickFix Campaign: A Wake-Up Call for Cybersecurity

In mid-2026, the ACR Stealer malware exploited ClickFix social engineering tactics to infiltrate enterprise networks. By deceiving users into executing commands via fake verification prompts, attackers deployed two primary infection chains: one utilizing WebDAV and PowerShell scripts, and another employing mshta.exe with obfuscated PowerShell. Both methods aimed to exfiltrate browser-stored credentials, session tokens, and sensitive Microsoft 365 documents, including files from OneDrive and SharePoint. This incident underscores a significant shift towards sophisticated social engineering attacks that bypass traditional security measures. The reliance on user interaction highlights the critical need for enhanced user awareness and robust endpoint protection strategies to mitigate such threats.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
Impact· CRITICAL

CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV

In July 2026, Microsoft disclosed CVE-2026-58644, a critical deserialization vulnerability in SharePoint Server, allowing unauthenticated remote code execution. This flaw affects SharePoint Server Subscription Edition, 2019, and Enterprise Server 2016. Exploitation requires an attacker to send a specially crafted network request, leading to potential full server compromise. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerabilities catalog, mandating federal agencies to apply patches by July 19, 2026. The inclusion of CVE-2026-58644 in CISA's catalog underscores the urgency of addressing this vulnerability, as it has been actively exploited in the wild. Organizations using affected SharePoint versions should prioritize patching to mitigate the risk of unauthorized access and potential data breaches.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Armenia Detains Russian Tourist Mistaken for REvil Hacker
Impact· HIGH

Armenia Detains Russian Tourist Mistaken for REvil Hacker

In June 2026, Armenian authorities detained Russian tourist Aleksandr Yuryevich Ermakov at Yerevan's Zvartnots airport, acting on a U.S. extradition request for a REvil ransomware suspect named Aleksandr Gennadievich Ermakov. The U.S. alleges that the wanted individual participated in Sodinokibi/REvil attacks from April 2019 to July 2021, affecting over 1,000 victims, including entities in the Northern District of Texas. However, the detained man's lawyers assert that he is not the individual sought by the U.S., highlighting discrepancies in personal details and emphasizing that the actual suspect is serving a sentence in Russia, restricting his travel. This incident underscores the complexities and potential misidentifications in international cybercrime enforcement efforts, especially when dealing with common names and limited identifying information. It also highlights the ongoing global pursuit of REvil affiliates, reflecting the persistent threat posed by ransomware groups and the challenges in dismantling their networks.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
CISA Adds Three Exploited Vulnerabilities to KEV Catalog
Impact· CRITICAL

CISA Adds Three Exploited Vulnerabilities to KEV Catalog

On July 16, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating active exploitation. The vulnerabilities include two OS command injection flaws in Fortinet FortiSandbox (CVE-2026-25089 and CVE-2026-39808) and a deserialization of untrusted data vulnerability in Microsoft SharePoint (CVE-2026-58644). These vulnerabilities are commonly exploited by malicious actors and pose significant risks to federal enterprises. The inclusion of these vulnerabilities in the KEV Catalog underscores the critical need for organizations to prioritize patching and remediation efforts. With the increasing frequency of such exploits, it is imperative for entities to adopt risk-based vulnerability management practices to safeguard their systems against potential breaches.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
North Korean Hackers Exploit Fake Coding Tests to Deploy OtterCookie Malware via Steganography
Impact· HIGH

North Korean Hackers Exploit Fake Coding Tests to Deploy OtterCookie Malware via Steganography

In July 2026, North Korean state-sponsored hackers initiated a sophisticated campaign targeting software developers through fake job postings and coding assessments. These assessments contained repositories with malicious code concealed within SVG image files, employing steganography to evade detection. Upon execution, the code deployed a multi-stage payload associated with the OtterCookie malware, capable of stealing browser credentials, cryptocurrency wallets, and sensitive files, as well as establishing remote access via a Socket.IO-based trojan. This operation underscores the persistent threat posed by North Korean cyber actors to the software development community, aiming to exfiltrate valuable data and financial assets. The use of steganography in SVG files highlights the evolving tactics employed by these adversaries to bypass traditional security measures, emphasizing the need for heightened vigilance and advanced detection capabilities within the industry.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports