Validated Containment Architectures are here. →Explore

Industry Category

Financial Services

Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.

3619 threat reports
Page 183 of 302

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Financial Services Threat Reports

Showing 21852196 / 3619 reports
NPM Supply Chain Bypass: PackageGate and Shai-Hulud Exploits Expose Open-Source Risks in 2026
Impact· high

NPM Supply Chain Bypass: PackageGate and Shai-Hulud Exploits Expose Open-Source Risks in 2026

In January 2026, critical vulnerabilities dubbed "PackageGate" were revealed in NPM and several popular JavaScript package managers, exposing gaps in defenses against supply chain attacks like last year's Shai-Hulud incidents. Despite previous security improvements, attackers could still bypass NPM's safeguard against malicious package scripts by leveraging Git dependencies and malicious .npmrc configuration files, leading to unauthorized code execution—even when script blocking features were enabled. The flaws, discovered by Koi Security researchers, allowed full code compromise and had potential for massive developer credential and secret exfiltration, threatening tens of thousands of projects and their downstream users. These findings highlight the persistent risks in open-source supply chains and the accelerating pace of software supply chain attacks. As threat actors become more adept at exploiting package management tools, organizations face renewed urgency to bolster visibility, enforce granular access controls, and adopt defense-in-depth measures to protect development workflows and critical assets.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Microsoft Patches Active Office Zero-Day: What Your Security Team Must Know
Impact· low

Microsoft Patches Active Office Zero-Day: What Your Security Team Must Know

In June 2024, Microsoft urgently released security patches addressing a high-severity zero-day vulnerability in Microsoft Office. Threat actors exploited this flaw in-the-wild prior to disclosure, using malicious documents to achieve remote code execution and gain access to targeted systems without user awareness. The vulnerability impacted multiple Office versions, with proof-of-concept exploits circulating even before patch release. Microsoft’s security teams identified active exploitation, prompting swift response to curb potential corporate data exposure, loss of confidentiality, and operational disruption for both private and public sector users worldwide. This incident spotlights the persistent risk of zero-day exploits in mainstream productivity software. It underscores both attackers’ increasing sophistication in rapidly weaponizing new vulnerabilities and the escalating need for organizations to prioritize timely patch application and robust monitoring to mitigate the business impact of emerging threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Konni APT Leverages AI-Generated PowerShell to Breach Blockchain Developers
Impact· medium

Konni APT Leverages AI-Generated PowerShell to Breach Blockchain Developers

In January 2026, the North Korean-linked APT group Konni conducted a sophisticated phishing campaign targeting blockchain developers and engineering teams in Japan, Australia, and India. Using AI-generated PowerShell malware, attackers successfully penetrated targeted organizations by delivering malicious payloads through convincing spear-phishing emails. Once inside, the adversaries leveraged lateral movement and exfiltration techniques to access sensitive intellectual property and digital assets, expanding their historical targeting beyond South Korea and parts of Europe. The breach underscores the evolution of attacker tradecraft—adopting AI to evade traditional defenses and efficiently craft malicious code. This incident is highly relevant as it marks a notable surge in both AI-driven malware and the targeting of the blockchain sector. With threat actors broadening their geographic reach and operational sophistication, organizations must urgently re-evaluate their security controls, specifically around code execution, endpoint monitoring, and identity access management, to defend against emerging threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Blackmoon Malware Hits Indian Taxpayers Through Sophisticated Phishing in 2026
Impact· medium

Blackmoon Malware Hits Indian Taxpayers Through Sophisticated Phishing in 2026

In January 2026, Indian users became the focus of a sophisticated cyber espionage campaign involving tax-themed phishing emails masquerading as legitimate communications from the Income Tax Department of India. These emails distributed malicious archive files, which, once opened, executed the infostealer Blackmoon malware. This multi-stage attack enabled threat actors to quietly exfiltrate personal and financial information from compromised systems, potentially exposing sensitive tax details and compromising the victims' digital environments. The attackers applied advanced phishing techniques and evasion tactics to bypass traditional security defenses and maintain persistent access. This incident highlights a broader trend in targeted social engineering attacks leveraging local themes and timely events to increase victim engagement. The resurgence of infostealer malware like Blackmoon underscores the importance of endpoint protection, awareness training, and zero trust controls, particularly in high-risk seasons such as tax filing periods.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Malicious AI-Powered VS Code Extensions Trigger Global Supply Chain Breach (2026)
Impact· medium

Malicious AI-Powered VS Code Extensions Trigger Global Supply Chain Breach (2026)

In January 2026, cybersecurity researchers uncovered that two widely-distributed AI-powered Microsoft Visual Studio Code extensions, with over 1.5 million combined installs, were covertly exfiltrating developer source code and sensitive project data to servers based in China. The malicious extensions masqueraded as legitimate AI coding tools, enticing developers globally through the official VS Code marketplace. Once installed, these extensions surreptitiously uploaded confidential code and intellectual property, potentially endangering enterprise software assets and customer data. Investigators highlighted the supply chain risk, noting the threat’s scalability via trusted software distribution channels and the delays in detecting such activity. This incident underscores the escalating risks associated with third-party development tools, particularly those leveraging AI branding. The popularity and trust in official marketplaces can allow sophisticated advanced persistent threats (APTs) or criminal groups to exploit developers and organizations, necessitating enhanced scrutiny and continuous security monitoring of supply chain dependencies.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
DPRK's Konni: AI-Generated Backdoor Hits Blockchain Developers in 2024
Impact· low

DPRK's Konni: AI-Generated Backdoor Hits Blockchain Developers in 2024

In early 2024, the North Korean threat group Konni launched a sophisticated supply-chain attack targeting blockchain developers by deploying an AI-generated PowerShell backdoor within compromised development environments. The operation exploited development tools to surreptitiously gain access to cryptocurrency assets, leveraging advanced evasion techniques and encrypted communications to avoid detection. Victims faced risks of cryptocurrency theft, business disruption, and potential regulatory exposure, with the attackers demonstrating a deep understanding of both blockchain technologies and modern security controls. This incident highlights the growing convergence of AI-generated malware and targeted supply-chain attacks, especially against financially lucrative industries like cryptocurrency. As threat actors increasingly leverage custom malware and automated tools, organizations with high-value digital assets face mounting pressure to improve internal visibility, zero-trust enforcement, and incident response capabilities.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(low)
Read Report
Exposed Environment Files: The $(pwd) Webserver Reconnaissance Surge of Jan 2026
Impact· low

Exposed Environment Files: The $(pwd) Webserver Reconnaissance Surge of Jan 2026

In January 2026, multiple sensors and the SANS Internet Storm Center reported a wave of targeted web application scans probing for exposed environment and configuration files on webservers using the /$(pwd)/ path pattern. Attackers, active since at least January 13th, systematically searched for sensitive files such as .env, docker-compose.yml, and terraform.tfstate, potentially exposing credentials and secrets. Two identified IP addresses (185.177.72.52, 185.177.72.23) led these scans, illustrating an automated approach likely leveraging misconfigured servers. While no confirmed breaches have been disclosed, such activity significantly raises the risk of follow-on exploitation or credential theft if vulnerable files are found. This incident highlights growing attacker sophistication in discovering misconfigurations and automating reconnaissance. The use of predictable directory traversal patterns and attempts to surface hidden files underscore the need for robust web application hardening and monitoring, especially as threat actors increasingly leverage similar tactics to bypass traditional defenses.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
ShinyHunters 2026: SSO Vishing Attacks Trigger Major SaaS Data Breaches
Impact· medium

ShinyHunters 2026: SSO Vishing Attacks Trigger Major SaaS Data Breaches

In January 2026, the cybercriminal group ShinyHunters orchestrated a series of sophisticated voice-phishing (vishing) attacks targeting corporate Single Sign-On (SSO) platforms, including Okta, Microsoft Entra, and Google. The attackers posed as IT support staff, manipulated employees into entering their credentials and multi-factor authentication tokens on fake login pages, and subsequently gained unauthorized access to SSO accounts. Leveraging these credentials, ShinyHunters accessed numerous connected SaaS applications such as Salesforce, Microsoft 365, and Slack, harvesting sensitive corporate data that was later used for extortion demands. High-profile organizations like SoundCloud, Betterment, and Crunchbase reported breaches and data losses as a result. This incident underscores a significant evolution in social engineering tactics, with attackers combining real-time phishing kits and vishing to bypass MFA and access a wide swath of corporate resources. As threat actors increasingly exploit identity-driven weaknesses and leverage SSO misconfigurations, organizations face greater risks of multi-system compromise and regulatory fallout.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Russian Organizations Hit by Advanced Multi-Stage Phishing with Amnesia RAT and Ransomware
Impact· high

Russian Organizations Hit by Advanced Multi-Stage Phishing with Amnesia RAT and Ransomware

In January 2026, a sophisticated multi-stage phishing campaign targeted Russian organizations, leveraging social engineering emails that contained tampered business documents. These lures delivered a remote access trojan (Amnesia RAT) alongside ransomware, allowing attackers to establish stealthy persistence and ultimately encrypt sensitive data for extortion. The threat actors employed layered infection chains, executed lateral movement within infected environments, and exfiltrated critical information before deploying ransomware. The attack resulted in operational disruptions and financial risk for affected businesses. This incident reflects an escalating trend of multi-vector threats where initial phishing access rapidly pivots to advanced malware implants and ransomware. Security leaders must recognize the evolving sophistication and automation in phishing and malware delivery, and reinforce layered defenses, monitoring, and incident response to counter multi-stage cyber attacks.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Konni Deploys AI-Built Malware Against Blockchain Engineers in 2026 Cyber Campaign
Impact· low

Konni Deploys AI-Built Malware Against Blockchain Engineers in 2026 Cyber Campaign

In January 2026, the North Korean-linked Konni APT (also known as Opal Sleet or TA406) launched a targeted cyber campaign against blockchain developers and engineers in the Asia-Pacific region, deploying bespoke PowerShell malware suspected of being generated using AI tools. Attackers lured victims with Discord-hosted ZIP files containing malicious shortcut links that, when launched, initiated a multi-stage infection chain. This included staged extraction of obfuscated PowerShell backdoors, privilege detection, scheduled task creation for persistence, and hourly beaconing to a remote command-and-control server. The malware focused on extracting sensitive development environment credentials, API keys, and potentially cryptocurrency wallet access, posing significant risks to both individuals and organizations handling blockchain assets. This incident exemplifies a sharp escalation in attacker sophistication, particularly the operational use of AI-powered malware, accelerating the pace at which advanced persistent threats can scale, adapt, and evade detection. As malicious actors increasingly leverage generative AI to develop modular, well-commented, and evasive code, organizations in crypto and other high-value sectors face a heightened need for adaptive security controls and rapid incident detection to keep defenses aligned with evolving attack techniques.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
CISA Urgently Flags Critical VMware vCenter Vulnerability (CVE-2024-37079) Amid Active Exploitation
Impact· low

CISA Urgently Flags Critical VMware vCenter Vulnerability (CVE-2024-37079) Amid Active Exploitation

In June 2024, a critical heap overflow vulnerability (CVE-2024-37079) affecting Broadcom VMware vCenter Server was identified and patched, but active exploitation was confirmed shortly thereafter. On January 10, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities (KEV) catalog after evidence surfaced of attackers leveraging the bug to execute unauthorized code remotely. Malicious actors could use this exploit to gain privileged access, conduct lateral movement, and potentially exfiltrate sensitive data or disrupt operations in environments utilizing unpatched vCenter servers. The incident underscores the continued targeting of core virtualization infrastructure by sophisticated threat actors and ransomware groups. With threat actors rapidly exploiting newly disclosed vulnerabilities, unpatched critical systems are at heightened risk, prompting urgency for patch management and layered security controls across enterprise environments.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Cisco Zero-Day Flaw Sparks Mass Exploitation of Unified Communications Platforms
Impact· low

Cisco Zero-Day Flaw Sparks Mass Exploitation of Unified Communications Platforms

In early June 2026, Cisco disclosed a critical zero-day vulnerability (CVE-2026-20045) impacting its Unified Communications (UC) suite, which quickly became the target of mass automated exploitation. Threat actors leveraged the flaw to gain remote code execution, potentially allowing them to fully compromise UC servers and pivot into broader enterprise networks. The scale of the vulnerability—affecting millions of devices worldwide—prompted urgent alerts from security agencies and rapid patching actions by global organizations. Successful intrusions could enable attackers to intercept sensitive communications, exfiltrate data, and disrupt business operations. This incident is especially notable as zero-day attacks against high-availability collaboration infrastructure have surged, reflecting a broader trend in targeting business-critical communication platforms. The Cisco exploitation underscores the speed at which adversaries now weaponize new flaws, and the risks posed to organizations lacking robust patch and segmentation defenses.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports