Validated Containment Architectures are here. →Explore

Industry Category

Financial Services

Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.

3618 threat reports
Page 160 of 302

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Financial Services Threat Reports

Showing 19091920 / 3618 reports
Malicious Go Module Exploits Open-Source Ecosystem to Steal Credentials and Deploy Backdoor
Impact· HIGH

Malicious Go Module Exploits Open-Source Ecosystem to Steal Credentials and Deploy Backdoor

In February 2026, cybersecurity researchers uncovered a malicious Go module named 'github.com/xinfeisoft/crypto' that impersonated the legitimate 'golang.org/x/crypto' library. This module was designed to harvest passwords entered via terminal prompts and deploy a Linux backdoor known as Rekoobe. Upon execution, the module exfiltrated captured credentials to a remote server and executed a shell script that installed the backdoor, granting attackers persistent access to compromised systems. The campaign exploited GitHub's infrastructure to host and distribute the malicious code, highlighting the risks associated with supply chain attacks in open-source ecosystems. This incident underscores the growing trend of supply chain attacks targeting developers and the open-source community. By leveraging trusted platforms and repositories, attackers can distribute malicious code to a wide audience, emphasizing the need for enhanced vigilance and security measures in software development and distribution processes.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Trojanized Gaming Tools Deploy Java-Based RAT via Browsers and Chat Platforms
Impact· MEDIUM

Trojanized Gaming Tools Deploy Java-Based RAT via Browsers and Chat Platforms

In February 2026, threat actors distributed trojanized gaming utilities via browsers and chat platforms, deploying a Java-based Remote Access Trojan (RAT). The attack utilized a malicious downloader to stage a portable Java runtime and execute a JAR file named jd-gui.jar, employing PowerShell and living-off-the-land binaries like cmstp.exe for stealthy execution. The malware established persistence through scheduled tasks and startup scripts, connecting to an external server for command-and-control communications, enabling data exfiltration and deployment of additional payloads. ([thehackernews.com](https://thehackernews.com/2026/02/trojanized-gaming-tools-spread-java.html?utm_source=openai)) This incident underscores the evolving tactics of cybercriminals, highlighting the increasing use of legitimate tools for malicious purposes and the targeting of gaming communities. Organizations must remain vigilant against such sophisticated attack vectors to protect sensitive data and maintain operational integrity.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
ScarCruft's 'Ruby Jumper' Campaign: A New Era in Air-Gapped Network Breaches
Impact· HIGH

ScarCruft's 'Ruby Jumper' Campaign: A New Era in Air-Gapped Network Breaches

In December 2025, the North Korean state-sponsored group ScarCruft (APT37) launched the 'Ruby Jumper' campaign, deploying sophisticated malware to infiltrate air-gapped networks. The attack began with malicious LNK files that, when executed, initiated a multi-stage infection chain. This chain utilized Zoho WorkDrive for command-and-control communications and leveraged removable media to bridge air-gapped systems, enabling data exfiltration and command execution. The campaign introduced new malware tools, including RESTLEAF, SNAKEDROPPER, THUMBSBD, VIRUSTASK, and FOOTWINE, each designed to facilitate various stages of the attack, from initial compromise to surveillance and data theft. ([thehackernews.com](https://thehackernews.com/2026/02/scarcruft-uses-zoho-workdrive-and-usb.html?utm_source=openai)) This incident underscores the evolving tactics of nation-state actors in targeting isolated networks, highlighting the need for enhanced security measures to protect sensitive environments. The use of legitimate cloud services for C2 communications and the exploitation of removable media to breach air-gapped systems represent significant advancements in cyber-espionage techniques, posing increased risks to critical infrastructure and sensitive data repositories. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/apt37-hackers-use-new-malware-to-breach-air-gapped-networks/?utm_source=openai))

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
DoJ Seizes $61 Million in Tether Linked to Pig Butchering Crypto Scams
Impact· HIGH

DoJ Seizes $61 Million in Tether Linked to Pig Butchering Crypto Scams

In February 2026, the U.S. Department of Justice (DoJ) seized over $61 million in Tether (USDT) linked to 'pig butchering' cryptocurrency scams. These schemes involved fraudsters building trust with victims through fake romantic relationships, then persuading them to invest in fraudulent cryptocurrency platforms that displayed fabricated high returns. When victims attempted to withdraw funds, they were met with demands for additional fees, leading to further financial loss. The seized funds were traced to cryptocurrency addresses used to launder proceeds from these scams. ([justice.gov](https://www.justice.gov/usao-ednc/pr/us-attorneys-office-ednc-announces-seizure-61-million-dollars-worth-cryptocurrency?utm_source=openai)) This incident underscores the growing prevalence of sophisticated social engineering tactics in financial fraud, particularly within the cryptocurrency sector. It highlights the need for increased vigilance and regulatory measures to protect individuals from such deceptive practices.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Sangoma FreePBX 2025 INJ3CTOR3 Web Shell Attacks
Impact· HIGH

Sangoma FreePBX 2025 INJ3CTOR3 Web Shell Attacks

In December 2025, over 900 Sangoma FreePBX instances were compromised through the exploitation of CVE-2025-64328, a high-severity command injection vulnerability. This flaw allowed authenticated users to execute arbitrary shell commands, leading to the deployment of the EncystPHP web shell by the threat actor group INJ3CTOR3. The attacks resulted in unauthorized remote access and control over affected VoIP infrastructures, with significant concentrations of compromised systems in the U.S., Brazil, Canada, Germany, and France. ([thehackernews.com](https://thehackernews.com/2026/02/900-sangoma-freepbx-instances.html?utm_source=openai)) The incident underscores the critical importance of timely patch management and restricting administrative access to prevent exploitation of known vulnerabilities. Organizations are urged to update their FreePBX deployments to the latest version and implement stringent access controls to mitigate similar threats. ([securityweek.com](https://www.securityweek.com/900-sangoma-freepbx-instances-infected-with-web-shells/?utm_source=openai))

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Marquis 2025 Ransomware Attack via SonicWall Breach
Impact· CRITICAL

Marquis 2025 Ransomware Attack via SonicWall Breach

In August 2025, Marquis Software Solutions, a Texas-based fintech firm serving over 700 banks and credit unions, experienced a ransomware attack. The breach was traced back to unauthorized access through its SonicWall firewall, leading to the exposure of sensitive data, including names, addresses, Social Security numbers, and financial account information of over 400,000 individuals associated with 74 financial institutions. The attackers exploited a known but unpatched vulnerability in SonicWall’s firewall software (CVE-2024-40766), allowing them to infiltrate Marquis's network and deploy ransomware. This incident underscores the critical importance of timely patch management and the potential risks associated with third-party service providers. ([techradar.com](https://www.techradar.com/pro/security/over-70-us-banks-and-credit-unions-affected-by-marquis-ransomware-breach-heres-what-we-know?utm_source=openai)) The Marquis breach highlights the escalating trend of cyberattacks targeting supply chain vulnerabilities, emphasizing the need for organizations to scrutinize the security postures of their vendors. Additionally, it serves as a stark reminder of the consequences of delayed patching, as threat actors increasingly exploit known vulnerabilities to gain unauthorized access to sensitive data.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
FedEx Phishing Scam Unleashes XWorm Malware
Impact· MEDIUM

FedEx Phishing Scam Unleashes XWorm Malware

In February 2026, a sophisticated phishing campaign impersonated FedEx to distribute the XWorm malware. Victims received emails claiming undelivered packages, prompting them to open malicious attachments. These attachments executed scripts that installed XWorm, a Remote Access Trojan (RAT) capable of stealing sensitive information, hijacking accounts, and executing commands remotely. The malware utilized advanced techniques like process injection and encrypted communication to evade detection. This incident underscores the evolving nature of phishing attacks, which now employ multi-stage payloads and sophisticated evasion tactics. Organizations must enhance their email security measures and educate employees on recognizing such deceptive schemes to mitigate the risk of similar threats.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
GCP Cloud SQL Vulnerability 2023: A Wake-Up Call for Cloud Security
Impact· CRITICAL

GCP Cloud SQL Vulnerability 2023: A Wake-Up Call for Cloud Security

In April 2023, a critical security vulnerability was discovered in Google Cloud Platform's (GCP) Cloud SQL service, potentially allowing unauthorized access to sensitive data. The flaw enabled attackers to escalate privileges from a basic user to a sysadmin role, granting access to internal GCP data, customer information, secrets, sensitive files, and passwords. By exploiting this misconfiguration, attackers could gain full control over the database server, posing significant risks to data integrity and confidentiality. Google addressed the issue promptly upon disclosure, mitigating the potential impact on affected systems. This incident underscores the persistent challenges associated with cloud service misconfigurations and the importance of continuous monitoring and timely remediation. As cloud adoption accelerates, organizations must prioritize robust security practices to prevent similar vulnerabilities from being exploited in the future.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
HexStrike-AI: AI-Powered Exploitation of Citrix Vulnerabilities in 2025
Impact· CRITICAL

HexStrike-AI: AI-Powered Exploitation of Citrix Vulnerabilities in 2025

In September 2025, cybersecurity firm Check Point Research identified that cybercriminals were leveraging HexStrike-AI, an AI-driven offensive security framework, to exploit vulnerabilities in Citrix NetScaler ADC and Gateway systems. HexStrike-AI integrates large language models with over 150 cybersecurity tools, enabling automated penetration testing and vulnerability research. Attackers utilized this tool to target specific Citrix vulnerabilities—CVE-2025-7775, CVE-2025-7776, and CVE-2025-8424—achieving unauthenticated remote code execution, installing webshells, and maintaining persistent access. The automation capabilities of HexStrike-AI significantly reduced the time required to exploit these vulnerabilities, narrowing the window for organizations to implement patches and defenses. This incident underscores the escalating sophistication of cyber threats, where AI-powered tools are employed to automate and enhance attack vectors. Organizations must prioritize timely patch management and adopt advanced security measures to mitigate such rapidly evolving threats.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
North Korean Hackers Exploit Fake Job Interviews to Target Crypto Developers
Impact· HIGH

North Korean Hackers Exploit Fake Job Interviews to Target Crypto Developers

In early 2026, North Korean state-sponsored hackers, notably the Lazarus Group, intensified their cyberattacks by posing as recruiters targeting JavaScript and Python developers in the cryptocurrency sector. They initiated contact through platforms like LinkedIn, offering fake job opportunities that included coding challenges embedded with malicious code. Upon execution, these challenges installed malware designed to steal cryptocurrency and sensitive information from the victims' systems. ([techradar.com](https://www.techradar.com/pro/security/north-korean-job-scammers-target-javascript-and-python-developers-with-fake-interview-tasks-spreading-malware?utm_source=openai)) This incident underscores a significant evolution in cyberattack strategies, highlighting the increasing sophistication of social engineering tactics. The use of trusted platforms and realistic job offers to deliver malware emphasizes the need for heightened vigilance among professionals in the tech and cryptocurrency industries.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Europol's Project Compass: A Milestone in Combating The Com Cybercrime Network
Impact· HIGH

Europol's Project Compass: A Milestone in Combating The Com Cybercrime Network

In January 2025, Europol initiated Project Compass, a coordinated international effort involving 28 countries, including all Five Eyes nations, to dismantle 'The Com,' a decentralized network of minors and young adults engaged in cybercrime, extortion, and physical violence. Over the past year, this operation has led to the arrest of 30 individuals, the identification of 179 perpetrators, and the safeguarding of 62 victims. The Com operates across various online platforms, making it challenging to disrupt due to its fragmented structure. ([cyberscoop.com](https://cyberscoop.com/project-compass-the-com-europol/?utm_source=openai)) The significance of this operation lies in its demonstration of effective international collaboration in combating complex cybercriminal networks. The Com's activities, including high-profile ransomware attacks and exploitation of vulnerable individuals, underscore the evolving nature of cyber threats. Project Compass highlights the necessity for continuous global cooperation and adaptive strategies to address such multifaceted cybercrime challenges. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/02/27/europol-the-com-network-arrests/?utm_source=openai))

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Jaguar Land Rover 2025 Cyberattack: Lessons in Industrial Cybersecurity
Impact· CRITICAL

Jaguar Land Rover 2025 Cyberattack: Lessons in Industrial Cybersecurity

In August 2025, Jaguar Land Rover (JLR) experienced a significant cyberattack that led to a complete halt in vehicle production across its global facilities, including those in the UK, Slovakia, China, India, and Brazil. The attack, attributed to the hacking group 'Scattered Lapsus$ Hunters,' resulted in the shutdown of production lines starting August 31, 2025, with operations remaining suspended until at least October 1, 2025. This disruption caused substantial financial losses, with JLR reporting a pre-tax loss of £485 million for the quarter ending September 30, 2025, marking a stark contrast to the £398 million profit recorded in the same period the previous year. The incident also had a ripple effect on the UK automotive industry, impacting JLR's extensive supply chain and leading to significant economic repercussions. ([theguardian.com](https://www.theguardian.com/business/2025/nov/14/jaguar-land-rover-loss-cyber-attack?utm_source=openai)) The JLR cyberattack underscores the escalating threat of sophisticated cyber incidents targeting critical infrastructure and major corporations. The involvement of 'Scattered Lapsus$ Hunters,' a group comprising elements from notorious hacking collectives like Scattered Spider, Lapsus$, and ShinyHunters, highlights the evolving tactics of cybercriminals who exploit social engineering and known vulnerabilities to infiltrate organizations. This incident serves as a stark reminder for industries worldwide to bolster their cybersecurity measures, enhance incident response strategies, and ensure robust supply chain security to mitigate the risks posed by such advanced persistent threats. ([tomshardware.com](https://www.tomshardware.com/tech-industry/cyber-security/jaguar-land-rover-shuts-down-production-due-to-ransomware-attack-scattered-lapsus-usd-hunters-takes-responsibility?utm_source=openai))

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports