Validated Containment Architectures are here. →Explore

Industry Category

Financial Services

Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.

3629 threat reports
Page 221 of 303

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Financial Services Threat Reports

Showing 26412652 / 3629 reports
Supply-Chain Emergency: Critical XXE Bug (CVE-2025-66516) in Apache Tika Imperils Enterprises
Impact· medium

Supply-Chain Emergency: Critical XXE Bug (CVE-2025-66516) in Apache Tika Imperils Enterprises

In December 2025, a critical XML External Entity (XXE) vulnerability, CVE-2025-66516, with a maximum CVSS score of 10.0, was discovered in multiple core Apache Tika modules. This flaw enables unauthenticated attackers to exploit XXE processing to remotely access sensitive files, exfiltrate data, and launch further attacks through maliciously crafted XML payloads. Because Apache Tika is widely employed in data extraction and content analysis across enterprise, cloud, and supply-chain systems, the exposure has immediate downstream risk for any organizations leveraging impacted Tika libraries. The incident highlights a significant supply-chain security challenge, reinforcing the urgency for immediate patching and improved review of third-party open-source components. Increasingly, threat actors are exploiting foundational software dependencies to bypass traditional security perimeters, making software supply-chain vigilance a key priority for 2025 and beyond.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Chinese Hackers Exploit React2Shell RCE—Critical React Server Vulnerability in 2025
Impact· medium

Chinese Hackers Exploit React2Shell RCE—Critical React Server Vulnerability in 2025

In December 2025, two Chinese nation-state threat groups rapidly began exploiting CVE-2025-55182—dubbed 'React2Shell'—a critical unauthenticated remote code execution vulnerability affecting React Server Components (RSC). Within hours of public disclosure, attackers scanned for and targeted vulnerable servers globally, leveraging the flaw to gain full control over application environments, execute arbitrary commands, and establish persistent footholds for lateral movement. The wide adoption of React in enterprise and SaaS environments increased the exposure and impact of these attacks, putting sensitive business-critical data at risk and causing major security teams to issue rapid patch advisories. This incident underscores the growing speed with which advanced threat actors weaponize zero-day vulnerabilities in widely used software frameworks. It highlights the urgent need for rapid vulnerability management, enhanced east-west segmentation, and robust threat detection, as attackers increasingly exploit supply chain and development stack exposures in cloud and hybrid environments.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Zero-Click Agentic Browser Attack Wipes Google Drive (Perplexity Comet, 2025)
Impact· high

Zero-Click Agentic Browser Attack Wipes Google Drive (Perplexity Comet, 2025)

In December 2025, researchers from Straiker STAR Labs disclosed a zero-click browser-based attack targeting users of Perplexity's Comet browser, enabling malicious actors to erase the contents of a victim’s entire Google Drive. The attack leverages agentic browser automation capable of connecting Gmail and Google Drive accounts by abusing trusted email-based automations. Once triggered by a specially crafted email, the exploit requires no user interaction to execute the destructive action. The compromise of cloud-stored data had significant operational impact, resulting in permanent data loss for affected users and highlighting new risks for organizations relying heavily on SaaS storage platforms. This attack is significant as it demonstrates the expanding threat of zero-click vulnerabilities powered by advanced browser automation, agentic AI, and email exploits. As more organizations migrate operations and collaborative data to the cloud, the frequency and sophistication of such attacks are expected to increase, escalating the urgency for robust cloud security controls.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
BRG Ransomware Breach: How a 2025 Attack Unveiled Legal Sector’s Vendor Risk
Impact· high

BRG Ransomware Breach: How a 2025 Attack Unveiled Legal Sector’s Vendor Risk

In March 2025, Berkeley Research Group (BRG), a prominent consulting and legal advisory firm, suffered a devastating ransomware attack attributed to the RansomHub cybercriminal group. Attackers leveraged persistent dwell time to infiltrate BRG’s network, exfiltrated sensitive data including M&A intelligence and confidential client materials, and encrypted key systems. The breach occurred during BRG's $700 million buyout by TowerBrook Capital Partners, amplifying the incident’s impact and resulting in exposure of information related to hundreds of active deals and thousands of individuals. The attackers’ extortion included threats of blackmail and public data leaks, leveraging their knowledge of both firm structure and sensitive client engagements. This attack spotlights a surge in professional services sector targeting—especially legal and advisory firms—by highly organized ransomware groups in 2024–2025. Threat actors like RansomHub have adopted prolonged infiltration tactics, optimized affiliate compensation, and leveraged industrialized extortion, mirroring broader ransomware trends and underscoring urgent vendor risk management needs.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Holiday Season Phishing Surge: Fake Rewards, Tax Refunds, and Retail Scams Hit US Consumers
Impact· medium

Holiday Season Phishing Surge: Fake Rewards, Tax Refunds, and Retail Scams Hit US Consumers

In late 2025, a surge of SMS phishing campaigns originating from China-based threat actors targeted US consumers, leveraging fake rewards, tax refund lures, and convincing e-commerce storefronts. Attackers registered thousands of new phishing domains, deploying convincing T-Mobile and AT&T spoof sites promoted via iMessage and RCS. Victims, enticed to enter payment card data and one-time codes, unknowingly enabled attackers to enroll their cards into Apple or Google mobile wallets under fraudster control, facilitating rapid monetization of stolen credentials. These operations exploited seasonal shopping urgency and sophisticated phishing kits to evade detection, causing widespread financial fraud, identity theft, and downstream losses for individuals and financial institutions. The incident highlights a global shift in phishing techniques, with threat actors now employing advanced, rapidly deployable kits and mobile wallet fraud vectors. The proliferation of fake e-commerce and tax-refund scams demonstrates increased operational agility and a focus on bypassing traditional browser-based defenses, raising urgent concerns for both consumer security and enterprise payment protection.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
M&S & Co-op Group 2025: Identity-Based Vishing Unleashes Ransomware Chaos
Impact· high

M&S & Co-op Group 2025: Identity-Based Vishing Unleashes Ransomware Chaos

In early 2025, Marks & Spencer (M&S) and Co-op Group, two major UK retailers, suffered significant ransomware attacks following sophisticated vishing campaigns. Attackers impersonated IT support and targeted outsourced helpdesk staff to capture corporate credentials, enabling unauthorized access to internal networks. Once inside, threat actors leveraged overprivileged accounts and weak segmentation to laterally move and exfiltrate sensitive data, ultimately deploying ransomware that disrupted operations. The incidents resulted in direct losses exceeding £500 million (USD 667 million), with long-term impacts including reputational harm and regulatory scrutiny. This breach underscores the ongoing threat of identity-based attacks, particularly those exploiting social engineering and credential harvesting to bypass perimeter defenses. With the rise of distributed workforces, cloud adoption, and third-party supply chains, organizations of all sizes remain vulnerable to similar tactics, making identity security and robust privilege management more urgent than ever.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
AutoIT3 Compiled Script Malware: 2024 Infostealer Surge Targets Windows Users
Impact· high

AutoIT3 Compiled Script Malware: 2024 Infostealer Surge Targets Windows Users

In December 2024, researchers identified a fresh malware campaign abusing compiled AutoIT3 scripts to deliver infostealers and remote access trojans to Windows systems. Attackers distributed malicious executables packaged in ZIP archives, which, upon execution, leveraged AutoIT3’s FileInstall() function to embed and unpack additional payloads, including obfuscated shellcode. Once unpacked, these scripts decoded and executed shellcode in memory, deploying threats such as Quasar RAT and Phantom Stealer, thereby enabling credential theft and system compromise for victim organizations. This campaign highlights a growing trend where attackers utilize low-profile development tools, like AutoIT, to evade traditional defenses and deliver sophisticated payloads. The resurgence of compiled script-based malware demonstrates ongoing innovation in attack vectors, requiring defenders to expand their monitoring to scripting environments and unpacked resource analysis.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
React2Shell: China-Nexus Groups Target Supply Chains with Critical React Vulnerability
Impact· low

React2Shell: China-Nexus Groups Target Supply Chains with Critical React Vulnerability

In early 2024, a critical zero-day vulnerability in the widely used React JavaScript library—dubbed React2Shell—was actively exploited in the wild by sophisticated China-nexus threat actors. Attackers leveraged compromised software supply chains to infiltrate organizations during regular package updates, gaining access via vulnerable dependency injection into production environments. Once inside, adversaries orchestrated lateral movement to exfiltrate sensitive data and disrupt business operations across sectors, leveraging encrypted communication channels and advanced stealth techniques. The incident has underscored the significant risk posed by supply-chain weaknesses in core developer tools and frameworks, amplifying concerns among enterprises and regulators alike. This breach reflects a surge in supply-chain attacks targeting popular open-source components, exposing systemic vulnerabilities beyond traditional perimeter defenses. The rapid weaponization of techniques by nation-state actors highlights the urgent need for zero trust segmentation, proactive patching, and real-time threat visibility within software development ecosystems.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Critical RCE in React Server Components Exposes Applications Worldwide (CVE-2025-55182)
Impact· low

Critical RCE in React Server Components Exposes Applications Worldwide (CVE-2025-55182)

In December 2025, a critical remote code execution (RCE) vulnerability—CVE-2025-55182—was discovered in the Flight protocol used by React Server Components. Rated CVSS 10.0, this flaw enabled unauthenticated attackers to craft malicious requests, resulting in the compromise of application servers running affected versions. Security researchers observed exploitation in the wild, with threat actors leveraging the flaw for lateral movement and potential data exfiltration. Organizations using Next.js and other frameworks integrating the vulnerable protocol faced heightened risk until urgent patches were issued. Immediate remediation efforts, threat monitoring, and network segmentation were necessary to mitigate the rapid spread. This incident underscores the increasing threat posed by supply chain vulnerabilities in widely adopted developer ecosystems. The exploitation of core component flaws in popular open-source projects amplifies business risk, as attackers accelerate adoption of frontline vulnerabilities for larger-scale impact.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Meta React Server Components 2025: Critical RCE Vulnerability Added to CISA KEV
Impact· medium

Meta React Server Components 2025: Critical RCE Vulnerability Added to CISA KEV

In December 2025, a critical remote code execution (RCE) vulnerability (CVE-2025-55182) was discovered and actively exploited in Meta's React Server Components framework. Threat actors leveraged this flaw in internet-exposed REACT instances, enabling them to execute arbitrary code remotely and potentially gain unauthorized access to internal systems. This vulnerability was significant enough to be added to CISA's Known Exploited Vulnerabilities (KEV) Catalog, prompting urgent remediation efforts across public and private organizations. Federal agencies were mandated to act by Binding Operational Directive 22-01, while industry peers were strongly advised to prioritize patching to limit exposure and prevent compromise. The exploit highlights an ongoing trend of attackers targeting widely adopted development frameworks like React, demonstrating how software supply chain and third-party vulnerabilities remain a high-risk vector. Its addition to the KEV Catalog underlines the persistent challenge organizations face in quickly identifying and mitigating critical threats across their infrastructure.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Predator Spyware 2024: Zero-Click Ad Delivery Redefines Stealth Attacks
Impact· high

Predator Spyware 2024: Zero-Click Ad Delivery Redefines Stealth Attacks

Between late 2023 and early 2024, the Predator spyware—developed by surveillance tech company Intellexa—was deployed via a novel zero-click attack vector known as "Aladdin." This technique exploited malicious ads to automatically compromise targeted devices as soon as they displayed the booby-trapped advertisement, without requiring any user interaction. Elite threat actors leveraged this method to implant sophisticated spyware capable of exfiltrating sensitive data and monitoring victim activity. The campaign’s covert nature enabled infections to go undetected, raising the risk for organizations and individuals exposed to this advanced surveillance toolset. This incident highlights the rapid evolution of zero-click infection strategies, especially those exploiting web advertising ecosystems. Security teams must double down on threat detection, anomaly response, and zero trust frameworks to counter increasingly stealthy surveillance tools used by both commercial operators and nation-state clients.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Critical React2Shell Flaw in React & Next.js Puts Web Servers at Risk
Impact· medium

Critical React2Shell Flaw in React & Next.js Puts Web Servers at Risk

In June 2024, a critical vulnerability known as 'React2Shell' was discovered in the React Server Components (RSC) 'Flight' protocol, impacting React and Next.js applications worldwide. This flaw enables unauthenticated remote code execution (RCE), allowing attackers to execute arbitrary JavaScript code on affected web servers. Security researchers observed that threat actors could exploit the protocol by sending crafted requests, potentially leading to a full compromise of application environments and exposure of sensitive data or further lateral movement within networks. This incident underscores heightened risk in modern web application supply chains and the urgent need for timely patching within frameworks. Growing attacks on open-source packages and widespread usage of React/Next.js frameworks amplify the incident's relevance, especially as application-layer vulnerabilities facilitate high-impact breaches at scale.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports