Validated Containment Architectures are here. →Explore

Industry Category

Financial Services

Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.

3618 threat reports
Page 173 of 302

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Financial Services Threat Reports

Showing 20652076 / 3618 reports
Windows Screensaver Malware Attack 2026: A New Vector for Remote Access Exploitation
Impact· MEDIUM

Windows Screensaver Malware Attack 2026: A New Vector for Remote Access Exploitation

In early February 2026, cybersecurity researchers identified a spear-phishing campaign exploiting Windows screensaver files (.scr) to deploy remote access tools (RATs) on corporate networks. Attackers sent business-themed phishing emails containing links to download files disguised as routine documents, which were actually malicious screensaver files. When executed, these files installed legitimate remote monitoring and management (RMM) tools, such as SimpleHelp, providing attackers with persistent remote access to compromised systems. This method allowed adversaries to bypass traditional security controls, as screensaver files are often overlooked as potential threats. The campaign underscores the evolving tactics of threat actors who leverage unconventional file types and legitimate software to infiltrate networks, emphasizing the need for organizations to reassess and strengthen their security postures against such sophisticated social engineering attacks.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
CISA's 2025 KEV Catalog Expansion: A Wake-Up Call for Cybersecurity
Impact· CRITICAL

CISA's 2025 KEV Catalog Expansion: A Wake-Up Call for Cybersecurity

In 2025, the Cybersecurity and Infrastructure Security Agency (CISA) expanded its Known Exploited Vulnerabilities (KEV) catalog by 245 entries, marking a 20% increase and bringing the total to 1,484 vulnerabilities. Notably, 24 of these newly added vulnerabilities were actively exploited in ransomware attacks, targeting products from vendors such as Microsoft, Apple, and Oracle. This surge underscores the escalating threat landscape where attackers rapidly exploit both new and legacy vulnerabilities. The inclusion of older vulnerabilities, some dating back to 2007, highlights the persistent risk posed by unpatched systems. The rapid weaponization of these vulnerabilities by threat actors emphasizes the critical need for organizations to prioritize timely patching and robust vulnerability management practices to mitigate potential breaches and operational disruptions.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Phishing Campaign 2026: Malformed URLs Bypass Security Measures
Impact· MEDIUM

Phishing Campaign 2026: Malformed URLs Bypass Security Measures

In early February 2026, a sophisticated phishing campaign emerged, utilizing malformed URLs to bypass traditional email security measures. Attackers embedded URLs with irregular parameter structures in phishing emails, leading recipients to malicious websites. This technique effectively evaded detection systems that rely on standard URL parsing and validation, thereby increasing the likelihood of successful credential theft and malware distribution. The campaign underscores the evolving tactics of cybercriminals in circumventing established security protocols. The resurgence of such techniques highlights the need for organizations to continuously adapt their security strategies. As attackers refine their methods to exploit weaknesses in URL parsing and detection, it becomes imperative for security systems to incorporate advanced analysis capabilities to identify and mitigate these sophisticated threats.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Microsoft's 2026 Breakthrough in AI Language Model Backdoor Detection
Impact· CRITICAL

Microsoft's 2026 Breakthrough in AI Language Model Backdoor Detection

In February 2026, Microsoft unveiled a novel approach to detect backdoors in open-weight language models, addressing the growing concern of model poisoning where adversaries embed hidden behaviors during training. This research introduces a scalable scanner capable of identifying backdoored models by analyzing distinctive attention patterns and output behaviors, thereby enhancing trust in AI systems. The significance of this development is underscored by prior findings that even minimal malicious data can implant backdoors in large language models, emphasizing the urgency for robust detection mechanisms. Microsoft's initiative represents a proactive step towards securing AI deployments against such covert threats.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Notepad++ Supply Chain Attack: A Wake-Up Call for Software Security
Impact· HIGH

Notepad++ Supply Chain Attack: A Wake-Up Call for Software Security

Between June and December 2025, Notepad++, a widely used text editor, was compromised through a sophisticated supply chain attack attributed to Chinese state-sponsored hackers. The attackers infiltrated the hosting provider's infrastructure, allowing them to intercept and redirect update traffic to malicious servers. This enabled the delivery of backdoored versions of Notepad++ to selected users, primarily targeting sectors such as government, telecommunications, and critical infrastructure. The breach was identified in early February 2026, prompting immediate security enhancements and advisories for users to update to version 8.9.1 or later. This incident underscores the escalating threat of supply chain attacks, where adversaries exploit trusted software distribution channels to infiltrate target systems. Organizations are urged to reassess and fortify their software update mechanisms, implement stringent verification processes, and remain vigilant against such sophisticated attack vectors.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Coinbase Insider Breach 2025: A Cautionary Tale of Insider Threats in the Financial Sector
Impact· HIGH

Coinbase Insider Breach 2025: A Cautionary Tale of Insider Threats in the Financial Sector

In May 2025, Coinbase, the largest U.S.-based cryptocurrency exchange, disclosed a significant data breach affecting approximately 69,461 customers. The breach, which occurred on December 26, 2024, was orchestrated by cybercriminals who bribed overseas customer support agents to gain unauthorized access to sensitive customer information. The compromised data included names, addresses, phone numbers, email addresses, masked Social Security numbers, masked bank account numbers, government-issued ID images, and account transaction histories. Notably, no passwords, private keys, or funds were exposed, and Coinbase Prime accounts remained unaffected. The attackers demanded a $20 million ransom, which Coinbase refused to pay, instead offering a $20 million bounty for information leading to the attackers' arrest. The company estimated remediation costs between $180 million and $400 million and pledged to reimburse affected customers. This incident underscores the critical importance of robust insider threat detection and prevention measures, especially in the financial sector. The breach highlights the vulnerabilities associated with third-party service providers and the need for stringent access controls and monitoring. As insider threats continue to pose significant risks, organizations must prioritize comprehensive security strategies to safeguard sensitive customer data and maintain trust.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
Dark Web Drug Kingpin Sentenced: The Fall of Incognito Market
Impact· CRITICAL

Dark Web Drug Kingpin Sentenced: The Fall of Incognito Market

In February 2026, Rui-Siang Lin, a 24-year-old Taiwanese national, was sentenced to 30 years in U.S. federal prison for operating 'Incognito Market,' a dark web platform that facilitated over $105 million in illegal drug transactions from October 2020 to March 2024. Lin, known online as 'Pharoah,' managed the marketplace's operations, overseeing more than 1,800 vendors and 400,000 customer accounts. The platform processed over 640,000 transactions involving substantial quantities of narcotics, including cocaine, methamphetamine, and fentanyl-laced pills, which were linked to at least one fatal overdose. ([yahoo.com](https://www.yahoo.com/news/articles/incognito-market-founder-rui-siang-150954026.html?utm_source=openai)) This case underscores the persistent threat posed by dark web marketplaces in the global drug trade. Despite law enforcement's efforts to dismantle such platforms, their sophisticated use of anonymizing technologies and cryptocurrencies continues to challenge regulatory and enforcement agencies worldwide. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/02/04/incognito-dark-web-drug-market-operator-prison-sentence/?utm_source=openai))

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Home Depot's 2024 GitHub Token Leak: A Cautionary Tale in Credential Management
Impact· HIGH

Home Depot's 2024 GitHub Token Leak: A Cautionary Tale in Credential Management

In early 2024, a Home Depot employee inadvertently published a private GitHub access token, exposing the company's internal systems for over a year. This token granted unauthorized access to hundreds of private source code repositories, cloud infrastructure, order fulfillment, and inventory management systems. Despite multiple attempts by security researcher Ben Zimmermann to alert Home Depot, the token remained active until December 2025, when media intervention prompted its revocation. This incident underscores the critical need for robust credential management and proactive security measures to prevent unauthorized access to sensitive systems. The prolonged exposure highlights systemic gaps in credential governance and the importance of timely response to security disclosures.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
EDR Killer Tool Exploits EnCase Driver: A Wake-Up Call for Cybersecurity
Impact· HIGH

EDR Killer Tool Exploits EnCase Driver: A Wake-Up Call for Cybersecurity

In early February 2026, cybersecurity researchers identified a sophisticated attack where threat actors utilized a legitimate but revoked EnCase kernel driver to disable endpoint detection and response (EDR) tools. The attackers gained initial access through compromised SonicWall SSL VPN credentials, exploiting the absence of multi-factor authentication. Once inside, they deployed a custom EDR killer tool disguised as a firmware update utility, which installed the 'EnPortv.sys' driver—a component of the EnCase forensic software. This driver, despite its certificate being revoked, was accepted by Windows due to the operating system's handling of driver signatures. The malware leveraged the driver's kernel-mode capabilities to terminate 59 security processes, effectively neutralizing the system's defenses. The attack was halted before ransomware deployment, but it underscores the critical need for robust access controls and vigilant monitoring of security infrastructure. This incident highlights a growing trend where attackers exploit vulnerable or outdated drivers to disable security mechanisms, a technique known as 'Bring Your Own Vulnerable Driver' (BYOVD). The persistence of such methods, despite existing security measures, emphasizes the necessity for organizations to implement comprehensive defense strategies, including regular updates to security protocols and the enforcement of multi-factor authentication across all access points.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Ransomware Groups Exploit VMware ESXi Vulnerability in 2026
Impact· HIGH

Ransomware Groups Exploit VMware ESXi Vulnerability in 2026

In March 2025, Broadcom patched a high-severity VMware ESXi vulnerability (CVE-2025-22225) that allowed attackers with VMX process privileges to perform arbitrary kernel writes, leading to sandbox escapes. Despite the patch, by February 2026, ransomware groups began exploiting this flaw to gain unauthorized access to ESXi hypervisors, encrypting virtual machines and disrupting critical services. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed these exploitations and added the vulnerability to its Known Exploited Vulnerabilities catalog, urging organizations to apply mitigations or discontinue use if patches are unavailable. This incident underscores the persistent threat posed by unpatched vulnerabilities in widely used virtualization platforms, highlighting the need for timely updates and robust security practices to prevent exploitation by ransomware operators.

5 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Critical GitLab Vulnerability CVE-2023-7028 Exploited in the Wild
Impact· HIGH

Critical GitLab Vulnerability CVE-2023-7028 Exploited in the Wild

In January 2024, GitLab disclosed a critical vulnerability (CVE-2023-7028) affecting versions 16.1.0 through 16.7.1 of its Community and Enterprise Editions. This flaw allowed attackers to send password reset emails to unverified email addresses, enabling account takeovers without user interaction. Exploitation of this vulnerability could lead to unauthorized access to sensitive data, code repositories, and potential supply chain attacks. ([arstechnica.com](https://arstechnica.com/security/2024/05/0-click-gitlab-hijacking-flaw-under-active-exploit-with-thousands-still-unpatched/?utm_source=openai)) The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2023-7028 to its Known Exploited Vulnerabilities catalog in May 2024, indicating active exploitation in the wild. Organizations using affected GitLab versions were urged to apply patches immediately to mitigate the risk of account hijacking and associated threats. ([computerweekly.com](https://www.computerweekly.com/news/366583457/Patch-GitLab-vuln-without-delay-users-warned?utm_source=openai))

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
SolarWinds Web Help Desk 2026 Untrusted Data Deserialization RCE
Impact· CRITICAL

SolarWinds Web Help Desk 2026 Untrusted Data Deserialization RCE

In January 2026, a critical vulnerability (CVE-2025-40551) was discovered in SolarWinds Web Help Desk (WHD), allowing unauthenticated remote code execution through untrusted data deserialization. Exploitation of this flaw enables attackers to execute arbitrary commands on the host system, potentially leading to full system compromise. SolarWinds released WHD version 2026.1 on January 28, 2026, addressing this and other vulnerabilities. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/cve-2025-40551?utm_source=openai)) The inclusion of CVE-2025-40551 in CISA's Known Exploited Vulnerabilities catalog underscores the urgency for organizations to apply the patch promptly. This incident highlights the persistent threat posed by deserialization vulnerabilities and the importance of timely software updates to mitigate such risks. ([securityweek.com](https://www.securityweek.com/fresh-solarwinds-vulnerability-exploited-in-attacks/?utm_source=openai))

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports