✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
Iran MOIS's 2026 Cyber Collaboration with Criminal Groups
In March 2026, Iran's Ministry of Intelligence and Security (MOIS) intensified its cyber operations by collaborating with cybercriminal groups to enhance the scale and effectiveness of its attacks. This partnership led to a series of sophisticated cyberattacks targeting critical infrastructure and private sector entities in the United States and Europe. The MOIS leveraged the expertise and tools of cybercriminals to conduct operations that included data breaches, ransomware attacks, and disruptive activities against government and corporate networks. ([forbes.com](https://www.forbes.com/sites/steveweisman/2026/03/03/irans-cyberwarfare-attacks-will-be-targeting-critical-infrastructure/?utm_source=openai)) This incident underscores a concerning trend where state-sponsored actors are increasingly partnering with cybercriminal organizations to achieve geopolitical objectives. Such collaborations blur the lines between nation-state and criminal cyber activities, complicating attribution and response efforts. Organizations must remain vigilant and adapt their cybersecurity strategies to address this evolving threat landscape.
4 months ago
Kill Chain
Sophisticated Phishing Campaign Leverages React and EmailJS for Credential Theft
In March 2026, a sophisticated phishing campaign was identified, utilizing a React-based web application to create a dynamic and convincing fake Dropbox Transfer page. The attackers distributed emails impersonating WeTransfer notifications, enticing recipients to click on a link leading to the fraudulent site. Upon attempting to download the purported files, users were prompted to enter their email credentials. These credentials were then exfiltrated using EmailJS, a legitimate email service, allowing the attackers to collect sensitive information without deploying their own infrastructure. This method not only enhanced the credibility of the phishing page but also helped evade traditional security measures. The use of React for dynamic content rendering and the exploitation of legitimate services like EmailJS signify an evolution in phishing tactics, making detection and prevention more challenging. Organizations must remain vigilant and educate users about such sophisticated social engineering techniques to mitigate the risk of credential theft.
4 months ago
Kill Chain
Critical Reverse Proxy Vulnerabilities in Fabio and OAuth2-Proxy Expose Web Applications to Attacks
In 2025, critical vulnerabilities were identified in two widely used reverse proxy applications: Fabio and OAuth2-Proxy. CVE-2025-48865 in Fabio allowed attackers to manipulate the Connection header, enabling the removal of security-critical X-Forwarded headers, potentially leading to unauthorized access to backend systems. Similarly, CVE-2025-64484 in OAuth2-Proxy permitted authenticated users to inject underscore variants of X-Forwarded-* headers, bypassing the proxy's filtering logic and potentially escalating privileges in upstream applications. Both vulnerabilities stemmed from improper handling and normalization of HTTP headers, exposing significant security risks in web architectures. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2025-48865?utm_source=openai)) These incidents underscore the systemic issues in reverse proxy implementations, highlighting the need for rigorous validation and normalization of HTTP headers to prevent similar exploits. Organizations must prioritize updating affected systems and implementing robust security measures to mitigate such vulnerabilities.
4 months ago
Kill Chain
Stryker's 2026 Cyberattack: A Wake-Up Call for the Medical Tech Industry
In March 2026, Stryker Corporation, a leading U.S.-based medical technology company, suffered a significant cyberattack orchestrated by the Iran-linked group Handala Hack. The attackers infiltrated Stryker's network, deploying wiper malware that erased data from over 200,000 devices and exfiltrated more than 50 terabytes of sensitive information. This breach disrupted operations across 79 countries, affecting both corporate and personal devices connected through Stryker's mobile device management software. ([tomshardware.com](https://www.tomshardware.com/tech-industry/cyber-security/iran-hacking-group-claims-attack-on-med-tech-company-stryker-says-over-200-000-devices-have-been-wiped-clean-and-over-50tb-of-data-extracted?utm_source=openai)) This incident underscores the escalating threat of state-sponsored cyberattacks targeting critical infrastructure and private sector entities. The use of wiper malware by nation-state actors highlights the need for robust cybersecurity measures and proactive defense strategies to mitigate such risks.
4 months ago
Kill Chain
SocksEscort Botnet Dismantled in 2025: A Major Blow to Cybercrime
In May 2025, an international law enforcement operation dismantled the SocksEscort botnet, a vast network of compromised small office/home office (SOHO) routers infected with the AVrecon malware. This botnet, active since at least 2023, had infiltrated over 70,000 devices across 20 countries, creating a covert network used for various cybercriminal activities, including digital advertising fraud and password spraying. The takedown involved seizing 34 domains and 23 servers across seven countries, as well as freezing $3.5 million in cryptocurrency linked to the botnet's operations. The operation also led to the indictment of four foreign nationals charged with conspiracy and damage to protected computers. ([justice.gov](https://www.justice.gov/usao-ndok/pr/botnet-dismantled-international-operation-russian-and-kazakhstani-administrators?utm_source=openai)) The SocksEscort botnet's extensive reach and prolonged undetected activity underscore the critical need for enhanced security measures in SOHO routers. This incident highlights the growing trend of cybercriminals exploiting less secure devices to build large-scale botnets, emphasizing the importance of regular firmware updates, robust security configurations, and vigilant monitoring to prevent similar infiltrations.
4 months ago
Kill Chain
DigitalMint 2023 BlackCat Ransomware Insider Attack
In 2023, former employees of DigitalMint and Sygnia, cybersecurity firms specializing in ransomware incident response, exploited their positions to collaborate with the BlackCat (ALPHV) ransomware group. They conducted multiple ransomware attacks against U.S. organizations, including a medical device company that paid approximately $1.2 million in ransom. The perpetrators utilized their insider knowledge to infiltrate systems, encrypt data, and extort victims, sharing a portion of the ransoms with BlackCat administrators. This case underscores the critical risk posed by insider threats within cybersecurity firms. The incident highlights the necessity for robust internal controls and continuous monitoring to prevent such breaches. Organizations must remain vigilant against the evolving tactics of ransomware groups and the potential for trusted insiders to become malicious actors.
4 months ago
Kill Chain
Apple 2026: Coruna Exploit Kit Targets iOS Devices
In early 2025, the Coruna exploit kit emerged as a sophisticated tool targeting Apple iOS devices, leveraging 23 vulnerabilities across five exploit chains to compromise devices running iOS versions 13.0 through 17.2.1. Initially utilized by a surveillance vendor's client, it was later deployed by Russian state-backed group UNC6353 in mid-2025 and by Chinese financially motivated actor UNC6691 by late 2025, leading to significant data breaches and financial losses. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/spyware-grade-coruna-ios-exploit-kit-now-used-in-crypto-theft-attacks/?utm_source=openai)) The Coruna exploit kit's evolution underscores the escalating sophistication of cyber threats targeting mobile devices, highlighting the critical need for timely security updates and robust defense mechanisms to protect sensitive user data and maintain device integrity.
4 months ago
Kill Chain
Telus Digital's 2026 Data Breach: A Wake-Up Call for Cloud Security
In March 2026, Telus Digital, the business process outsourcing arm of Canadian telecommunications provider Telus, confirmed a significant data breach orchestrated by the cybercriminal group ShinyHunters. The attackers exploited Google Cloud Platform credentials obtained from a previous breach, enabling them to access Telus Digital's systems over several months. This intrusion led to the exfiltration of nearly 1 petabyte of sensitive data, including customer support records, call logs, and internal corporate information. The breach not only compromised Telus Digital's data but also affected numerous client companies relying on their services. ShinyHunters attempted to extort Telus Digital for $65 million, threatening to release the stolen data publicly. Telus Digital has since engaged cybersecurity experts and law enforcement to investigate and mitigate the breach's impact. This incident underscores the escalating threat posed by sophisticated cybercriminal groups like ShinyHunters, who have been linked to multiple high-profile data thefts and extortion campaigns targeting major organizations worldwide. Their tactics often involve exploiting misconfigured cloud services and leveraging stolen credentials to infiltrate systems, highlighting the critical need for robust security configurations and vigilant monitoring of cloud environments.
4 months ago
Kill Chain
Caesars Entertainment 2023 Loyalty Program Data Breach: A Wake-Up Call for Cybersecurity
In September 2023, Caesars Entertainment disclosed a cyberattack that compromised the personal data of its loyalty program members, including Social Security and driver's license numbers. The breach, attributed to the cybercriminal group 'Scattered Spider' operating under the ALPHV/BlackCat syndicate, did not disrupt casino or online operations. Reports suggest Caesars may have paid a partial ransom of $15 million, though the total demand was $30 million. This incident underscores the growing threat of loyalty program fraud, where attackers exploit personal data for financial gain. The rise in such breaches highlights the need for enhanced security measures and consumer vigilance to protect sensitive information.
4 months ago
Kill Chain
US Authorities Dismantle SocksEscort Proxy Network Exploiting Linux Malware
In March 2026, U.S. and European law enforcement agencies, in collaboration with private partners, dismantled the SocksEscort cybercrime proxy network, which had been operational for over a decade. This network utilized the AVRecon malware to compromise approximately 70,000 small office/home office (SOHO) routers, creating a botnet that offered cybercriminals access to 'clean' residential IP addresses from major ISPs. The service facilitated various illicit activities, including cryptocurrency thefts and financial frauds, resulting in significant monetary losses. ([securityaffairs.com](https://securityaffairs.com/149007/hacking/avrecon-bot-socksescort.html?utm_source=openai)) The disruption of SocksEscort underscores the persistent threat posed by malware targeting SOHO routers, which often lack regular security updates and monitoring. This incident highlights the critical need for enhanced security measures and vigilance in protecting network infrastructure to prevent similar exploitations in the future.
4 months ago
Kill Chain
Veeam's 2026 Critical RCE Vulnerabilities: Immediate Action Required
In March 2026, Veeam Software disclosed and patched multiple critical remote code execution (RCE) vulnerabilities in its Backup & Replication (VBR) solution, specifically CVE-2026-21666, CVE-2026-21667, CVE-2026-21669, and CVE-2026-21708. These flaws allowed low-privileged domain users to execute remote code on vulnerable backup servers, posing significant risks to data integrity and system security. The vulnerabilities were addressed in Veeam Backup & Replication versions 12.3.2.4465 and 13.0.1.2067. The disclosure underscores the persistent targeting of backup solutions by ransomware groups, as compromised VBR servers can facilitate lateral movement within networks and impede data restoration efforts. Organizations are urged to promptly apply the patches to mitigate potential exploitation and enhance their cybersecurity posture.
4 months ago
Kill Chain
Critical n8n RCE Vulnerability (CVE-2025-68613) Leads to System Compromise
In December 2025, a critical Remote Code Execution (RCE) vulnerability, identified as CVE-2025-68613, was discovered in n8n, an open-source workflow automation platform. This flaw, present in versions from 0.211.0 up to but not including 1.120.4, 1.121.1, and 1.122.0, allows authenticated users to execute arbitrary code with the privileges of the n8n process. Exploitation can lead to full system compromise, including unauthorized data access and workflow manipulation. Despite patches being released, as of early February 2026, over 24,700 unpatched instances remain exposed online, with significant concentrations in North America and Europe. The inclusion of CVE-2025-68613 in CISA's Known Exploited Vulnerabilities catalog underscores the urgency for organizations to address this issue. The widespread exposure highlights the critical need for prompt patching and vigilant security practices to mitigate potential exploitation risks.
4 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports