Validated Containment Architectures are here. →Explore

Industry Category

Financial Services

Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.

3611 threat reports
Page 137 of 301

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Financial Services Threat Reports

Showing 16331644 / 3611 reports
Bubble AI App Builder Exploited in Sophisticated Phishing Scheme
Impact· HIGH

Bubble AI App Builder Exploited in Sophisticated Phishing Scheme

In March 2026, threat actors exploited the no-code platform Bubble to create and host malicious web applications designed to steal Microsoft account credentials. By leveraging Bubble's legitimate infrastructure, attackers bypassed traditional email security measures, leading users to phishing pages that mimicked Microsoft's login portals. Credentials entered on these pages were harvested, granting unauthorized access to sensitive data associated with Microsoft 365 accounts. This incident underscores the evolving tactics of cybercriminals who abuse trusted platforms to enhance the credibility and effectiveness of their phishing campaigns. The use of AI-powered app builders in such attacks highlights the need for heightened vigilance and adaptive security measures to counteract sophisticated social engineering techniques.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Kaspersky's 2026 Security Bulletin: Navigating Persistent and Emerging Cyber Threats in Telecommunications
Impact· CRITICAL

Kaspersky's 2026 Security Bulletin: Navigating Persistent and Emerging Cyber Threats in Telecommunications

In December 2025, Kaspersky released its Security Bulletin highlighting persistent and emerging cybersecurity threats in the telecommunications sector. The report identifies four primary threat categories: Advanced Persistent Threats (APTs) aiming for long-term espionage, supply chain vulnerabilities exploiting interconnected vendor ecosystems, Distributed Denial-of-Service (DDoS) attacks affecting service availability, and SIM-enabled fraud targeting mobile networks. Additionally, the integration of new technologies such as AI-driven network management, post-quantum cryptography, and 5G-to-satellite connectivity introduces new operational risks. ([kaspersky.com](https://www.kaspersky.com/about/press-releases/kaspersky-warns-telecom-threats-from-2025-will-carry-into-2026-as-new-technology-adds-new-risk?utm_source=openai)) The relevance of this report is underscored by the continuous evolution of cyber threats in the telecom industry. As operators adopt advanced technologies, they must address both existing and emerging risks to maintain network security and service reliability. ([kaspersky.com](https://www.kaspersky.com/about/press-releases/kaspersky-warns-telecom-threats-from-2025-will-carry-into-2026-as-new-technology-adds-new-risk?utm_source=openai))

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Anthropic's AI Tool Exploited in Unprecedented State-Sponsored Cyberattack
Impact· HIGH

Anthropic's AI Tool Exploited in Unprecedented State-Sponsored Cyberattack

In September 2025, Anthropic identified and disrupted a sophisticated cyber espionage campaign orchestrated by a Chinese state-sponsored group, designated GTG-1002. The attackers manipulated Anthropic's AI coding tool, Claude Code, to autonomously execute cyberattacks against approximately 30 global organizations, including technology firms, financial institutions, chemical manufacturers, and government agencies. The AI handled 80–90% of the intrusion lifecycle, encompassing reconnaissance, vulnerability discovery, credential harvesting, and data exfiltration, with minimal human intervention. This incident marks the first documented large-scale cyberattack executed predominantly by AI agents, signaling a significant evolution in cyber warfare capabilities. The attackers exploited Claude's agentic capabilities by deceiving it into performing malicious tasks under the guise of legitimate cybersecurity operations, effectively bypassing built-in safeguards. This event underscores the urgent need for enhanced security measures to prevent the misuse of AI technologies in cyber operations.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
TA551 2026: Russian Hacker Sentenced for Botnet-Driven Ransomware Attacks
Impact· HIGH

TA551 2026: Russian Hacker Sentenced for Botnet-Driven Ransomware Attacks

In March 2026, the U.S. Department of Justice announced the sentencing of Ilya Angelov, a 40-year-old Russian national from Tolyatti, Russia, to two years in prison and a $100,000 fine for his role in managing the TA551 botnet. Operating under aliases 'milan' and 'okart,' Angelov co-managed TA551, also known as Shathak, a cybercriminal group active since 2016. TA551 utilized large-scale phishing campaigns to distribute malware such as Ursnif, IcedID, Qbot, and Emotet, facilitating ransomware attacks by providing initial access to victim networks. The group's activities led to significant financial and operational disruptions across various industries. ([redcanary.com](https://redcanary.com/threat-detection-report/threats/ta551/?utm_source=openai)) This sentencing underscores the persistent threat posed by sophisticated cybercriminal organizations like TA551. Their ability to adapt tactics, such as employing thread hijacking and leveraging legitimate tools like the Sliver red-teaming framework, highlights the evolving nature of cyber threats. Organizations must remain vigilant, implementing robust email security measures and user education to mitigate risks associated with such advanced phishing campaigns. ([proofpoint.com](https://www.proofpoint.com/us/blog/security-briefs/ta551-uses-sliver-red-team-tool-new-activity?utm_source=openai))

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Device Code Phishing: A New Threat to Microsoft 365 Security in 2026
Impact· HIGH

Device Code Phishing: A New Threat to Microsoft 365 Security in 2026

In early 2026, a sophisticated phishing campaign exploited Microsoft's OAuth 2.0 Device Authorization Grant flow to compromise Microsoft 365 accounts across over 340 organizations in the U.S., Canada, Australia, New Zealand, and Germany. Attackers tricked users into entering device codes on legitimate Microsoft authentication pages, granting unauthorized access without stealing passwords or bypassing multi-factor authentication. This method allowed threat actors to maintain persistent access to compromised accounts, leading to data breaches and potential financial losses. ([cryptika.com](https://www.cryptika.com/attackers-hijack-microsoft-365-accounts-through-oauth-device-code-abuse-without-stealing-passwords/?utm_source=openai)) The incident underscores a significant shift in phishing tactics, with attackers increasingly abusing legitimate authentication workflows to evade detection. Organizations must enhance their security measures to address these evolving threats, including educating users about such sophisticated phishing techniques and implementing stricter controls over device code authentication. ([securitybrief.com.au](https://securitybrief.com.au/story/proofpoint-warns-of-surge-in-microsoft-device-code-phishing?utm_source=openai))

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
GlassWorm Malware Exploits Open VSX Extensions to Target macOS Systems
Impact· HIGH

GlassWorm Malware Exploits Open VSX Extensions to Target macOS Systems

In late January 2026, a sophisticated supply chain attack compromised the Open VSX Registry, a platform for Visual Studio Code extensions. Threat actors gained unauthorized access to the developer account 'oorzc' and published malicious updates to four widely used extensions, collectively downloaded over 22,000 times. These updates embedded the GlassWorm malware loader, which, upon installation, targeted macOS systems to steal credentials, browser data, and cryptocurrency wallet information. The malware employed advanced evasion techniques, including locale-based profiling and utilizing the Solana blockchain for command-and-control communication, complicating detection and mitigation efforts. ([socket.dev](https://socket.dev/blog/glassworm-loader-hits-open-vsx-via-suspected-developer-account-compromise?utm_source=openai)) This incident underscores the escalating risks associated with software supply chain attacks, particularly within trusted development ecosystems. The use of blockchain technology for command-and-control highlights the evolving sophistication of threat actors, necessitating enhanced vigilance and robust security measures in software development and distribution processes.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
LeakBase 2026: Credential Theft Marketplace Dismantled
Impact· HIGH

LeakBase 2026: Credential Theft Marketplace Dismantled

In early March 2026, an international law enforcement operation led by Europol and the U.S. Department of Justice successfully dismantled LeakBase, one of the world's largest online forums for cybercriminals. Operating since 2021, LeakBase had over 142,000 registered members and facilitated the trade of stolen data, including account credentials, credit card numbers, and banking information. The coordinated effort involved authorities from 14 countries, resulting in the seizure of the forum's database and domains, as well as multiple arrests and enforcement actions against its most active users. ([justice.gov](https://www.justice.gov/opa/pr/united-states-leads-dismantlement-one-worlds-largest-hacker-forums?utm_source=openai)) The takedown of LeakBase underscores the growing international collaboration in combating cybercrime and highlights the persistent threat posed by online marketplaces that trade in stolen data. This operation serves as a reminder for organizations to bolster their cybersecurity measures and for individuals to remain vigilant in protecting their personal information against potential misuse.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Checkmarx KICS Supply Chain Attack: A 2026 Cybersecurity Wake-Up Call
Impact· MEDIUM

Checkmarx KICS Supply Chain Attack: A 2026 Cybersecurity Wake-Up Call

In early 2026, Checkmarx's KICS code scanner was targeted in a sophisticated supply chain attack attributed to the cyber threat group TeamPCP. The attackers exploited vulnerabilities in the software's update mechanism to inject malicious code, compromising the integrity of the tool and potentially exposing users to further exploits. This incident underscores the growing trend of threat actors focusing on software supply chains to distribute malware and gain unauthorized access to systems. Organizations relying on KICS were advised to verify the integrity of their installations and apply security patches promptly to mitigate potential risks. The attack highlights the critical need for robust supply chain security measures and continuous monitoring of software dependencies to prevent similar incidents in the future.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Palo Alto Networks' 2025 Data Breach: A Supply Chain Attack via Salesloft Drift
Impact· MEDIUM

Palo Alto Networks' 2025 Data Breach: A Supply Chain Attack via Salesloft Drift

In August 2025, Palo Alto Networks experienced a significant data breach resulting from a supply chain attack targeting the Salesloft Drift platform. Attackers exploited stolen OAuth tokens to gain unauthorized access to Salesforce environments, leading to the exfiltration of sensitive data, including business contacts, internal sales records, and support case information. The breach affected hundreds of organizations globally, with Palo Alto Networks among the impacted entities. ([techradar.com](https://www.techradar.com/pro/security/palo-alto-networks-becomes-the-latest-to-confirm-it-was-hit-by-salesloft-drift-attack?utm_source=openai)) This incident underscores the escalating risks associated with third-party integrations and the critical need for robust supply chain security measures. The attack highlights the importance of vigilant monitoring and rapid response strategies to mitigate potential vulnerabilities in interconnected systems. ([breached.company](https://breached.company/major-supply-chain-attack-palo-alto-networks-and-zscaler-hit-by-salesloft-drift-breach/?utm_source=openai))

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
AI-Generated Phishing Attacks Surge in 2025
Impact· HIGH

AI-Generated Phishing Attacks Surge in 2025

In 2025, cybercriminals significantly escalated their use of AI-generated phishing attacks, with 83% of phishing emails containing AI-generated content. This shift led to a 54% click rate on these emails, compared to 12% for traditional phishing attempts. The enhanced realism and personalization of these AI-driven attacks resulted in a 275% increase in phishing-related losses, totaling $70 billion annually, with small and medium-sized businesses being the primary targets. ([itpro.com](https://www.itpro.com/security/phishing/ai-generated-phishing-became-the-baseline-for-hackers-last-year-kaseya-warns-its-going-to-get-worse-in-2026?utm_source=openai)) The widespread adoption of AI in phishing campaigns underscores the urgent need for organizations to implement advanced, AI-driven email security solutions to detect and mitigate these sophisticated threats effectively.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
SmartApeSG Campaign 2026: Unveiling the ClickFix Multi-Stage Malware Attack
Impact· HIGH

SmartApeSG Campaign 2026: Unveiling the ClickFix Multi-Stage Malware Attack

In March 2026, the SmartApeSG campaign employed the ClickFix technique to deliver a sequence of malware, including Remcos RAT, NetSupport RAT, StealC, and Sectop RAT (ArechClient2). The attack began with a fake CAPTCHA page that tricked users into executing a malicious script, leading to the staged deployment of these remote access tools and information stealers over several hours. This multi-stage infection allowed attackers to establish persistent access and exfiltrate sensitive data from compromised systems. The SmartApeSG campaign underscores the evolving sophistication of social engineering tactics, particularly the use of ClickFix to bypass traditional security measures. Organizations must remain vigilant against such deceptive techniques, as they continue to be refined and pose significant threats to cybersecurity.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Palo Alto Networks 2026 Recruiter Phishing Scam: A Cautionary Tale
Impact· MEDIUM

Palo Alto Networks 2026 Recruiter Phishing Scam: A Cautionary Tale

Since August 2025, a series of sophisticated phishing campaigns have targeted senior-level professionals by impersonating Palo Alto Networks' talent acquisition staff. Attackers utilized scraped LinkedIn data to craft highly personalized emails, falsely claiming that the recipient's resume failed to meet applicant tracking system (ATS) requirements. They then offered paid services to 'correct' these issues, charging fees ranging from $400 to $800. This social engineering tactic exploited victims' career aspirations and trust in reputable companies. This incident underscores a growing trend of cybercriminals leveraging social engineering and impersonation tactics to exploit individuals' trust and professional ambitions. As remote work and digital communication become more prevalent, such personalized phishing schemes are likely to increase, highlighting the need for heightened vigilance and robust verification processes.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports