Validated Containment Architectures are here. →Explore

Industry Category

Financial Services

Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.

3603 threat reports
Page 125 of 301

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Financial Services Threat Reports

Showing 14891500 / 3603 reports
North Korean Hackers Leverage GitHub for Command-and-Control in South Korean Cyberattacks
Impact· LOW

North Korean Hackers Leverage GitHub for Command-and-Control in South Korean Cyberattacks

In April 2026, cybersecurity researchers identified a sophisticated cyberattack campaign attributed to North Korean state-sponsored actors targeting organizations in South Korea. The attackers employed obfuscated Windows shortcut (LNK) files distributed via phishing emails to initiate the infection chain. Upon execution, these LNK files deployed decoy PDF documents to distract victims while simultaneously executing malicious PowerShell scripts in the background. These scripts performed environment checks to evade analysis tools and established persistence through scheduled tasks. Notably, the attackers utilized GitHub as command-and-control (C2) infrastructure, exfiltrating system information and retrieving additional payloads from private repositories, thereby blending malicious traffic with legitimate network activity. ([thehackernews.com](https://thehackernews.com/2026/04/dprk-linked-hackers-use-github-as-c2-in.html?utm_source=openai)) This incident underscores a growing trend among threat actors to exploit trusted platforms like GitHub for C2 operations, enhancing their ability to evade detection. The use of native Windows tools and legitimate services in these attacks highlights the necessity for organizations to implement robust monitoring and anomaly detection systems to identify and mitigate such sophisticated threats.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(low)
Read Report
Germany Unmasks Leader of REvil and GandCrab Ransomware Groups
Impact· HIGH

Germany Unmasks Leader of REvil and GandCrab Ransomware Groups

In April 2026, German authorities identified 31-year-old Russian national Daniil Maksimovich Shchukin as 'UNKN,' the alleged leader of the notorious ransomware groups GandCrab and REvil. Between 2019 and 2021, Shchukin and his associate, 43-year-old Anatoly Sergeevitsch Kravchuk, reportedly executed at least 130 cyberattacks in Germany, extorting nearly €2 million and causing over €35 million in economic damages. These groups pioneered the double extortion tactic, demanding ransom for decrypting systems and additional payment to prevent data leaks. This revelation underscores the persistent threat posed by sophisticated ransomware operations and highlights the importance of international collaboration in combating cybercrime. Organizations must remain vigilant, as the identification of such key figures does not eliminate the risk of future attacks employing similar tactics.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
UAT-10608's Exploitation of React2Shell: A Wake-Up Call for Cybersecurity
Impact· CRITICAL

UAT-10608's Exploitation of React2Shell: A Wake-Up Call for Cybersecurity

In early April 2026, a threat cluster identified as UAT-10608 launched a global credential theft campaign targeting public-facing Next.js applications vulnerable to the React2Shell flaw (CVE-2025-55182). Exploiting this pre-authentication remote code execution vulnerability, attackers deployed an automated tool named 'NEXUS Listener' to exfiltrate credentials, SSH keys, cloud tokens, and environment secrets from compromised systems. This campaign resulted in the compromise of at least 766 hosts across multiple industries and geographic regions. ([darkreading.com](https://www.darkreading.com/cyberattacks-data-breaches/automated-credential-harvesting-campaign-react2shell?utm_source=openai)) The React2Shell vulnerability, disclosed in December 2025, allows unauthenticated attackers to execute arbitrary code on servers running vulnerable versions of React Server Components. Despite the availability of patches, many organizations have yet to update their systems, leaving them susceptible to such attacks. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2025/12/15/defending-against-the-cve-2025-55182-react2shell-vulnerability-in-react-server-components/?msockid=3159dd8396d16eca0085cb7697616f99&utm_source=openai))

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Fortinet FortiClient EMS Vulnerability: Immediate Action Required
Impact· CRITICAL

Fortinet FortiClient EMS Vulnerability: Immediate Action Required

In April 2026, Fortinet disclosed a critical vulnerability (CVE-2026-35616) in its FortiClient Endpoint Management Server (EMS) versions 7.4.5 and 7.4.6. This improper access control flaw allows unauthenticated attackers to execute unauthorized code or commands via crafted requests. The vulnerability has been actively exploited in the wild, prompting Fortinet to release emergency hotfixes and advise customers to update to version 7.4.7. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/04/04/forticlient-ems-zero-day-cve-2026-35616/?utm_source=openai)) The rapid exploitation of CVE-2026-35616 underscores the increasing trend of attackers targeting endpoint management solutions to gain unauthorized access and control over enterprise networks. Organizations must prioritize timely patching and robust access controls to mitigate such risks.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Phishing Campaigns Exploit Open Redirects in 2026
Impact· MEDIUM

Phishing Campaigns Exploit Open Redirects in 2026

In early 2026, multiple phishing campaigns exploited open redirect vulnerabilities in trusted domains to deceive users into visiting malicious websites. Attackers crafted URLs that appeared legitimate by leveraging open redirects in services like Google Meet and Microsoft OAuth, effectively bypassing traditional email and browser security measures. This technique led to increased instances of credential theft and malware distribution, particularly targeting government and public-sector organizations. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/03/02/oauth-redirection-abuse-enables-phishing-malware-delivery/?utm_source=openai)) The prevalence of these attacks underscores the critical need for organizations to identify and remediate open redirect vulnerabilities within their web applications. As threat actors continue to refine their methods, maintaining robust security protocols and user awareness is essential to mitigate the risks associated with such sophisticated phishing tactics.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
React2Shell 2025: Credential Theft Campaign Exploiting CVE-2025-55182
Impact· CRITICAL

React2Shell 2025: Credential Theft Campaign Exploiting CVE-2025-55182

In December 2025, a critical vulnerability known as React2Shell (CVE-2025-55182) was disclosed, affecting React Server Components in versions 19.0.0 through 19.2.0. This flaw allowed unauthenticated remote code execution, enabling attackers to execute arbitrary JavaScript code on vulnerable servers. Exploiting this vulnerability, threat actors initiated a large-scale campaign targeting Next.js applications, compromising at least 766 hosts across various cloud providers. The attackers utilized an automated framework named NEXUS Listener to harvest sensitive data, including database credentials, SSH private keys, API keys, cloud tokens, and environment secrets. The operation was attributed to a threat cluster tracked as UAT-10608. ([articles.uvnetware.com](https://articles.uvnetware.com/news/react2shell-cve-2025-55182/?utm_source=openai)) The React2Shell incident underscores the critical importance of promptly addressing server-side vulnerabilities in widely used frameworks. The rapid exploitation by sophisticated threat actors highlights the need for organizations to implement robust security measures, including timely patching, comprehensive monitoring, and adherence to secure coding practices to mitigate the risk of similar attacks.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Fortinet FortiClient EMS Vulnerability CVE-2026-35616: Immediate Action Required
Impact· CRITICAL

Fortinet FortiClient EMS Vulnerability CVE-2026-35616: Immediate Action Required

In April 2026, Fortinet disclosed a critical vulnerability (CVE-2026-35616) in its FortiClient Enterprise Management Server (EMS) versions 7.4.5 and 7.4.6. This improper access control flaw allows unauthenticated attackers to execute arbitrary code or commands via specially crafted requests. The vulnerability was actively exploited in the wild, prompting Fortinet to release emergency patches and advise immediate application of hotfixes or upgrading to version 7.4.7 upon its release. This incident underscores the persistent threat posed by zero-day vulnerabilities and the importance of timely patch management. Organizations are reminded to maintain robust security practices, including regular software updates and monitoring for unauthorized activities, to mitigate risks associated with such critical flaws.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Beware: QR Code Phishing Scams Targeting Drivers in 2026
Impact· MEDIUM

Beware: QR Code Phishing Scams Targeting Drivers in 2026

In early 2026, a sophisticated phishing campaign emerged across multiple U.S. states, including New York, California, and Texas. Scammers sent fraudulent text messages impersonating state courts, alleging recipients had outstanding traffic violations. These messages included images of fake court notices embedded with QR codes, urging immediate payment of fines to avoid severe penalties. Scanning the QR codes redirected victims to phishing websites designed to steal personal and financial information. This method, known as 'quishing' (QR code phishing), represents an evolution in cybercriminal tactics, leveraging QR codes to bypass traditional security measures and exploit the trust users place in official-looking communications. The widespread nature of this scam underscores the need for heightened vigilance and public awareness regarding unsolicited messages containing QR codes.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Fortinet FortiClient EMS Vulnerability CVE-2026-35616: Immediate Action Required
Impact· CRITICAL

Fortinet FortiClient EMS Vulnerability CVE-2026-35616: Immediate Action Required

In early April 2026, Fortinet disclosed a critical vulnerability (CVE-2026-35616) in its FortiClient Endpoint Management Server (EMS) versions 7.4.5 and 7.4.6. This improper access control flaw allows unauthenticated attackers to execute unauthorized code or commands via crafted requests, effectively bypassing API authentication and authorization mechanisms. The vulnerability has been actively exploited in the wild, prompting Fortinet to release out-of-band hotfixes and advise customers to upgrade to version 7.4.7 upon its release. ([thehackernews.com](https://thehackernews.com/2026/04/fortinet-patches-actively-exploited-cve.html?utm_source=openai)) The exploitation of CVE-2026-35616 underscores a growing trend of attackers targeting management interfaces to gain elevated privileges within enterprise environments. This incident highlights the critical need for organizations to promptly apply security patches and maintain vigilant monitoring of their network infrastructure to mitigate potential breaches.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
36 Malicious npm Packages Exploited Redis, PostgreSQL to Deploy Persistent Implants
Impact· CRITICAL

36 Malicious npm Packages Exploited Redis, PostgreSQL to Deploy Persistent Implants

In April 2026, cybersecurity researchers identified 36 malicious npm packages masquerading as Strapi CMS plugins. These packages exploited Redis and PostgreSQL databases to deploy reverse shells, harvest credentials, and establish persistent implants. The malicious code was embedded within the postinstall script hook, executing upon installation without user interaction, thereby compromising systems with root access in CI/CD environments and Docker containers. The attackers utilized various payloads, including remote code execution via Redis, Docker container escapes, and credential harvesting, indicating a sophisticated and evolving threat. This incident underscores the escalating risks associated with software supply chain attacks, particularly within open-source ecosystems. The attackers' ability to infiltrate widely-used package repositories highlights the urgent need for enhanced security measures in software development pipelines. Organizations are advised to audit their dependencies, implement strict access controls, and monitor for anomalous activities to mitigate such threats.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Drift Protocol's $285 Million Loss: A Wake-Up Call for Crypto Security
Impact· CRITICAL

Drift Protocol's $285 Million Loss: A Wake-Up Call for Crypto Security

On April 1, 2026, Drift Protocol, a Solana-based decentralized exchange, suffered a significant security breach resulting in the theft of approximately $285 million in various cryptocurrencies. The attackers employed a sophisticated social engineering campaign over six months, culminating in the compromise of administrative controls through the exploitation of durable nonces. This allowed them to manipulate governance mechanisms and execute unauthorized transactions, leading to substantial financial losses and operational disruption for Drift Protocol. This incident underscores the escalating threat posed by state-sponsored cyber actors, particularly those from the Democratic People's Republic of Korea (DPRK), who have increasingly targeted the cryptocurrency sector to fund national programs. The attack highlights the critical need for robust operational security measures, including stringent access controls and vigilant monitoring of administrative activities, to mitigate the risks associated with social engineering and insider threats.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
LinkedIn's 2026 Browser Extension Scanning: A Privacy Wake-Up Call
Impact· MEDIUM

LinkedIn's 2026 Browser Extension Scanning: A Privacy Wake-Up Call

In April 2026, reports emerged that LinkedIn was injecting hidden JavaScript into user sessions to scan for over 6,000 installed Chrome extensions and collect detailed device data. This practice, termed 'BrowserGate,' raised significant privacy concerns as it linked extension data to identifiable user profiles, potentially exposing sensitive personal and corporate information. LinkedIn acknowledged the scanning but stated it was intended to detect extensions that violate their terms of service by scraping data without consent. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/linkedin-secretly-scans-for-6-000-plus-chrome-extensions-collects-data/?utm_source=openai)) This incident underscores the growing scrutiny over corporate data collection practices and the balance between platform security and user privacy. It highlights the need for transparency in how user data is gathered and utilized, especially as similar fingerprinting techniques have been employed by other companies in the past. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/linkedin-secretly-scans-for-6-000-plus-chrome-extensions-collects-data/?utm_source=openai))

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports