Validated Containment Architectures are here. →Explore

Industry Category

Financial Services

Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.

3594 threat reports
Page 107 of 300

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Financial Services Threat Reports

Showing 12731284 / 3594 reports
Harvester's Linux GoGra Backdoor: A New Threat in South Asia
Impact· HIGH

Harvester's Linux GoGra Backdoor: A New Threat in South Asia

In April 2026, the Harvester threat actor deployed a new Linux variant of its GoGra backdoor targeting entities in South Asia. The malware utilizes the Microsoft Graph API and Outlook mailboxes as covert command-and-control channels, enabling it to bypass traditional network defenses. Initial access is achieved through social engineering tactics, tricking victims into executing ELF binaries disguised as PDF documents. Once installed, the backdoor communicates with a specific Outlook mailbox folder named "Zomato Pizza," executing commands received via emails with subjects starting with "Input" and sending execution results back with the subject "Output." ([thehackernews.com](https://thehackernews.com/2026/04/harvester-deploys-linux-gogra-backdoor.html?utm_source=openai)) This incident underscores the evolving tactics of nation-state actors like Harvester, who are expanding their toolsets to include cross-platform capabilities and leveraging legitimate cloud services to evade detection. The use of Microsoft's cloud infrastructure for command-and-control highlights the need for organizations to monitor and secure their cloud environments against such sophisticated threats.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Telegram 'tdata' Folder Exploited in Credential Harvesting Attack - April 2026
Impact· HIGH

Telegram 'tdata' Folder Exploited in Credential Harvesting Attack - April 2026

In April 2026, a sophisticated cyberattack was observed targeting Telegram Desktop users through the exploitation of the 'tdata' folder, which stores session data. Attackers gained initial access via weak SSH credentials, conducted system reconnaissance, and specifically sought out the 'tdata' directory to harvest Telegram session tokens. This method allowed them to bypass two-factor authentication and gain unauthorized access to users' Telegram accounts, leading to potential data exfiltration and account misuse. The incident underscores the evolving tactics of threat actors who are now combining resource hijacking with credential harvesting to establish persistent access and exploit digital identities. This trend highlights the critical need for robust SSH configurations, vigilant monitoring of sensitive directories, and comprehensive session management practices to mitigate such multifaceted threats.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Detection Strategies Against Infiltrating IT Workers
Impact· HIGH

Detection Strategies Against Infiltrating IT Workers

In April 2026, Microsoft reported that the North Korean state-sponsored group Jasper Sleet exploited remote work trends by posing as legitimate IT hires using fabricated identities and AI-assisted deception. These operatives infiltrated organizations to gain trusted access, leading to data theft, extortion, and potential follow-on compromises. The attackers systematically surveyed job postings, crafted convincing applications, and, once hired, accessed sensitive company resources. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/04/21/detection-strategies-cloud-identities-against-infiltrating-it-workers/?utm_source=openai)) This incident underscores the evolving tactics of nation-state actors leveraging AI to enhance social engineering attacks, highlighting the urgent need for organizations to strengthen identity verification processes and monitor for anomalous behaviors during recruitment and onboarding phases. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/04/21/detection-strategies-cloud-identities-against-infiltrating-it-workers/?utm_source=openai))

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Unveiling Critical APT Exploit Chains: A 2026 Analysis
Impact· CRITICAL

Unveiling Critical APT Exploit Chains: A 2026 Analysis

In April 2026, Praetorian's analysis revealed that out of 500,000 vulnerability findings, only 14 endpoints were susceptible to critical exploit chains capable of full host compromise. These chains combined multiple vulnerabilities, including CVE-2025-4918 and CVE-2025-2857, to enable zero-click attacks through browser exploits. Notably, one chain was actively exploited by the Russian-aligned APT group RomCom, targeting sectors such as government, defense, and energy across Europe and North America. This incident underscores the necessity for organizations to move beyond traditional CVSS-based vulnerability assessments and adopt exploit chain analysis to identify and mitigate real-world attack paths effectively. The increasing sophistication of APT groups in leveraging complex exploit chains highlights the urgent need for enhanced threat intelligence integration and proactive security measures to protect critical infrastructure and sensitive data.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
NGate Malware Variant Exploits HandyPay App to Steal NFC Data
Impact· MEDIUM

NGate Malware Variant Exploits HandyPay App to Steal NFC Data

In November 2025, ESET researchers identified a new variant of the NGate malware family targeting Android users in Brazil. This variant exploits a legitimate NFC payment application called HandyPay by embedding malicious code, likely generated with the assistance of AI. The malware captures NFC data and payment card PINs from victims, enabling attackers to perform unauthorized contactless ATM withdrawals and payments. Distribution methods include fake lottery websites and counterfeit Google Play pages, indicating a coordinated effort by a single threat actor. This incident underscores the evolving sophistication of cyber threats, particularly the integration of AI in malware development. The use of legitimate applications as vectors for malware distribution highlights the need for heightened vigilance and robust security measures to protect sensitive financial information.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
DigitalMint Negotiator's Betrayal: A Stark Warning for Cybersecurity
Impact· HIGH

DigitalMint Negotiator's Betrayal: A Stark Warning for Cybersecurity

In April 2026, Angelo Martino, a former ransomware negotiator at DigitalMint, pleaded guilty to conspiring with the BlackCat (ALPHV) ransomware group to extort five U.S. companies. Martino exploited his position by sharing confidential information, including victims' insurance policy limits and negotiation strategies, with the attackers. This collaboration led to ransom payments totaling approximately $75.3 million from sectors such as nonprofit, hospitality, financial services, retail, and medical industries. Martino faces up to 20 years in federal prison, with sentencing scheduled for July 9, 2026. This case underscores the critical need for stringent vetting and oversight of cybersecurity professionals, as insider threats can significantly amplify the impact of cyberattacks. The incident also highlights the evolving tactics of ransomware groups, emphasizing the importance of comprehensive security measures and employee integrity in safeguarding organizational assets.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Insider Threats in Cybersecurity: Lessons from the BlackCat Ransomware Case
Impact· CRITICAL

Insider Threats in Cybersecurity: Lessons from the BlackCat Ransomware Case

In April 2026, Angelo Martino, a former ransomware negotiator at DigitalMint, pleaded guilty to collaborating with the BlackCat (ALPHV) ransomware group in 2023. Martino, along with accomplices Ryan Goldberg and Kevin Martin, exploited their insider positions to share confidential negotiation details with BlackCat operators, facilitating the extortion of higher ransom payments from U.S. organizations. Their victims included financial services firms, nonprofits, law firms, school districts, and medical facilities, with ransom payments exceeding $50 million. The trio operated as BlackCat affiliates, paying the ransomware administrators a 20% share of the proceeds. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/former-ransomware-negotiator-pleads-guilty-to-blackcat-attacks/?utm_source=openai)) This case underscores the critical need for stringent internal controls and trust verification within cybersecurity firms. The involvement of trusted insiders in cybercriminal activities highlights the evolving tactics of ransomware groups and the importance of comprehensive security measures to protect sensitive information and maintain organizational integrity.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
NGate Malware Exploits HandyPay App to Steal NFC Payment Data
Impact· HIGH

NGate Malware Exploits HandyPay App to Steal NFC Payment Data

In April 2026, ESET researchers identified a new variant of the NGate malware targeting Android users in Brazil. This malware is embedded within a trojanized version of HandyPay, a legitimate NFC payment application. Once installed, the malicious app prompts users to set it as the default NFC payment application, requests their card PIN, and instructs them to tap their card on the device. The malware then captures and transmits the NFC payment data and PIN to attackers, enabling unauthorized transactions and ATM withdrawals. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/ngate-android-malware-uses-handypay-nfc-app-to-steal-card-data/?utm_source=openai)) This incident underscores the evolving tactics of cybercriminals who exploit trusted applications to distribute malware, highlighting the need for heightened vigilance among Android users regarding app sources and permissions. The use of generative AI in developing such malware indicates a concerning trend towards more sophisticated and accessible cyber threats. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/ngate-android-malware-uses-handypay-nfc-app-to-steal-card-data/?utm_source=openai))

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Urgent Alert: Active Exploitation of Cisco SD-WAN Vulnerability CVE-2026-20133
Impact· HIGH

Urgent Alert: Active Exploitation of Cisco SD-WAN Vulnerability CVE-2026-20133

In April 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) identified active exploitation of a critical vulnerability (CVE-2026-20133) in Cisco Catalyst SD-WAN Manager. This flaw, stemming from insufficient file system access restrictions, allows unauthenticated remote attackers to access sensitive information on affected systems. Cisco had patched this vulnerability in February 2026, but unpatched systems remain at risk. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/cisa-flags-new-sd-wan-flaw-as-actively-exploited-in-attacks/?utm_source=openai)) The exploitation of CVE-2026-20133 underscores the persistent threat posed by unpatched vulnerabilities in critical network infrastructure. Organizations are urged to prioritize timely patching and adhere to CISA's directives to mitigate potential breaches and safeguard sensitive data.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Apache ActiveMQ Vulnerability (CVE-2026-34197) Under Active Exploitation
Impact· HIGH

Critical Apache ActiveMQ Vulnerability (CVE-2026-34197) Under Active Exploitation

In April 2026, a critical remote code execution vulnerability (CVE-2026-34197) was discovered in Apache ActiveMQ, an open-source message broker widely used for asynchronous communication between Java applications. This flaw, stemming from improper input validation in the Jolokia JMX-HTTP bridge, allows authenticated attackers to execute arbitrary code on unpatched systems. Despite a patch being released on March 30, 2026, over 6,400 ActiveMQ servers remain exposed and vulnerable to ongoing attacks, with the majority located in Asia, North America, and Europe. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed active exploitation of this vulnerability and has urged organizations to secure their servers by April 30, 2026. The active exploitation of CVE-2026-34197 underscores the persistent threat posed by unpatched vulnerabilities in widely used software. Organizations must prioritize timely patching and robust security measures to mitigate the risks associated with such vulnerabilities, especially given the widespread use of Apache ActiveMQ in critical systems.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
SystemBC C2 Server Unveils Extensive Botnet Linked to The Gentlemen Ransomware
Impact· HIGH

SystemBC C2 Server Unveils Extensive Botnet Linked to The Gentlemen Ransomware

In April 2026, cybersecurity researchers uncovered that The Gentlemen ransomware-as-a-service (RaaS) operation had deployed SystemBC proxy malware, leading to the discovery of a botnet comprising over 1,570 victims. SystemBC establishes SOCKS5 network tunnels within compromised environments, facilitating covert communication and the deployment of additional malware payloads. The Gentlemen group, active since mid-2025, has targeted Windows, Linux, NAS, and BSD systems, employing sophisticated tactics such as abusing Group Policy Objects for domain-wide compromise. The group's rapid expansion and technical capabilities underscore the evolving threat landscape posed by RaaS operations. This incident highlights the increasing sophistication and scale of ransomware operations, emphasizing the need for organizations to enhance their cybersecurity defenses. The use of proxy malware like SystemBC for covert operations and the targeting of diverse systems indicate a shift towards more versatile and resilient attack strategies by cybercriminal groups.

3 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Emerging Enterprise Security Risks of AI in 2026
Impact· MEDIUM

Emerging Enterprise Security Risks of AI in 2026

Between December 2025 and February 2026, a sophisticated cyberattack targeted nine Mexican government agencies, resulting in the exfiltration of approximately 195 million identity and tax records, 15.5 million vehicle registrations, and other sensitive data. The attackers utilized advanced AI tools, including Anthropic's Claude Code and OpenAI's GPT-4.1, to automate and streamline the breach, employing over 1,000 AI prompts to create custom scripts for infiltrating and extracting data from 305 internal servers. This incident underscores the escalating use of AI in cybercrime, enabling small groups to execute large-scale operations with unprecedented efficiency. ([livescience.com](https://www.livescience.com/technology/artificial-intelligence/hackers-used-ai-to-steal-hundreds-of-millions-of-mexican-government-and-private-citizen-records-in-one-of-the-largest-cybersecurity-breaches-ever?utm_source=openai)) The breach highlights a dangerous evolution in cyber threats, where AI's capabilities are harnessed to amplify the scale and speed of attacks. Organizations must recognize the urgency of implementing robust AI governance frameworks, enhancing identity and access management, and adopting zero-trust principles to mitigate the risks posed by autonomous AI agents in their environments.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports