Validated Containment Architectures are here. →Explore

Industry Category

Financial Services

Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.

3629 threat reports
Page 222 of 303

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Financial Services Threat Reports

Showing 26532664 / 3629 reports
ArrayOS AG VPN Vulnerability Exploited: Threat Actors Plant Webshells via Command Injection (2024)
Impact· medium

ArrayOS AG VPN Vulnerability Exploited: Threat Actors Plant Webshells via Command Injection (2024)

In early June 2024, threat actors began actively exploiting a command injection vulnerability in Array Networks AG Series VPN devices, targeting organizations and critical infrastructure globally. Attackers leveraged the flaw to plant malicious webshells and create rogue administrative users, gaining persistent access to internal networks. The observed attacks allowed adversaries to bypass normal authentication and move laterally, posing significant operational risks by exposing sensitive internal systems and enabling further exploitation. The breach heightened concerns about the security of perimeter VPN appliances and the need for urgent patching. This incident is especially significant as attackers rapidly weaponize new vulnerabilities in edge infrastructure, reflecting a persistent trend of chaining VPN flaws to compromise enterprise environments. Heightened regulatory scrutiny and rising sophistication in attacks on remote access solutions underscore the urgent need for enhanced security controls and vigilant vulnerability management.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
CISA Warns of Chinese 'BrickStorm' Malware on VMware Servers: What Enterprises Must Know
Impact· low

CISA Warns of Chinese 'BrickStorm' Malware on VMware Servers: What Enterprises Must Know

In mid-2024, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that Chinese state-sponsored hackers deployed the 'BrickStorm' malware to backdoor vulnerable VMware vSphere servers across multiple U.S. critical infrastructure sectors. Attackers exploited unpatched or insecurely configured vSphere environments to gain initial access, install persistent web shells, and enable lateral movement within networks. The campaign featured advanced evasion tactics, strong operational security, and targeted high-value assets, risking confidential data exposure, business disruption, and regulatory non-compliance for affected organizations. This attack exemplifies a rising trend of sophisticated supply-chain and infrastructure attacks leveraging known vulnerabilities in virtualized server environments. With ongoing exploitation by nation-state actors and renewed regulatory focus on asset protection, organizations must reevaluate their segmentation, patching, and east-west visibility controls to mitigate similar threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
2025’s Multi-Vector Supply Chain Attacks: How AI and Automation Redefined Web Security
Impact· medium

2025’s Multi-Vector Supply Chain Attacks: How AI and Automation Redefined Web Security

In 2025, a coordinated wave of sophisticated attacks exploited web supply chain vulnerabilities, impacting over 180,000 websites globally. Threat actors leveraged multi-vector tactics, combining AI-driven injection methods, automated credential stuffing, and lateral movement across cloud and hybrid environments. The adversaries compromised legitimate third-party libraries and embedded malicious code into trusted web assets, bypassing traditional security controls and causing data breaches, unauthorized financial transfers, and reputation damage for thousands of organizations. Rapid east-west propagation enabled attackers to escalate privileges and exfiltrate sensitive customer data before detection. This incident signals a shift in the threat landscape, with attackers increasingly using AI and automation to exploit supply chain trust, targeting hybrid and multi-cloud infrastructures. Organizations face unprecedented pressure to modernize web security, prioritizing zero trust, real-time threat monitoring, and proactive segmentation to defend against rapidly evolving, multi-pronged attack campaigns.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Cloudflare Defeats Record 29.7 Tbps DDoS Attack Attributable to AISURU Botnet
Impact· high

Cloudflare Defeats Record 29.7 Tbps DDoS Attack Attributable to AISURU Botnet

In December 2025, Cloudflare successfully detected and mitigated the largest recorded distributed denial-of-service (DDoS) attack, peaking at 29.7 terabits per second. The attack was orchestrated by the AISURU botnet, leveraging up to four million infected hosts to launch a hyper-volumetric assault. The malicious traffic targeted Cloudflare’s infrastructure, testing the limits of web security and putting critical online services at risk of disruption during the 69-second onslaught. This incident illustrates the increasing scale and sophistication of botnet-driven DDoS attacks, forcing organizations to reassess their mitigation strategies. The AISURU attack underscores a troubling trend in the growth of for-hire botnets and record-breaking DDoS volumes seen in 2025. These evolving threats continue to challenge traditional perimeter defenses, making advanced detection, automated response, and robust network segmentation more critical than ever.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
GoldFactory Trojan Infects 11,000+ Mobile Users in Southeast Asia through Fake Banking Apps
Impact· medium

GoldFactory Trojan Infects 11,000+ Mobile Users in Southeast Asia through Fake Banking Apps

Between October and December 2024, a financially motivated threat group known as GoldFactory orchestrated an extensive campaign targeting mobile users across Indonesia, Thailand, and Vietnam. By impersonating trusted government services, the attackers distributed modified Android banking apps laced with malware, resulting in over 11,000 infections. Once installed, these malicious applications harvested sensitive financial data and enabled unauthorized transactions, posing significant financial risks to individual users and undermining trust in mobile banking channels. The campaign used phishing techniques and social engineering, making detection challenging for average users. This incident illustrates the growing trend of cybercriminals leveraging mobile channels and government impersonation to amplify reach and lower the barrier for monetization in emerging markets. It also highlights the urgent need for stronger mobile security controls, user education, and regulatory vigilance to mitigate evolving threats targeting digital financial services.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
How the yETH DeFi Platform Lost $9 Million in a Flash Loan Exploit (2025)
Impact· high

How the yETH DeFi Platform Lost $9 Million in a Flash Loan Exploit (2025)

In December 2025, an unknown threat actor successfully exploited a critical vulnerability in the yETH DeFi platform's smart contract infrastructure, using advanced flash loan manipulation tactics to drain approximately $9 million in funds. The attack was executed within minutes, bypassing protocol controls and effectively emptying several liquidity pools. Investigators reveal that the breach exploited flawed logic in the contract that allowed multiple reentrancies and circumvented rate checks, leading to rapid unauthorized fund transfers. Remediation steps included pausing affected smart contracts and collaborating with exchanges to freeze stolen assets. This incident highlights the rapidly evolving threat landscape targeting decentralized finance (DeFi) ecosystems, where complex protocols and smart contract bugs can be weaponized for mass financial theft. Continued increases in such exploits have intensified regulatory and investor scrutiny while prompting the DeFi sector to emphasize real-time security visibility, automated incident response, and proactive contract auditing.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
Silver Fox Mimics Russian Tactics: Fake Teams Installer Pushes ValleyRAT in 2025 China Cyber Attack
Impact· low

Silver Fox Mimics Russian Tactics: Fake Teams Installer Pushes ValleyRAT in 2025 China Cyber Attack

In December 2025, the threat actor known as Silver Fox executed a targeted cyber campaign in China, distributing the ValleyRAT remote access trojan through a fake Microsoft Teams installer. By leveraging SEO-poisoned websites, attackers lured victims searching for legitimate collaboration apps into downloading malicious files disguised as authentic installers. Once executed, the malware provided the attackers with covert access and enabled data theft, surveillance, and potential lateral movement within targeted organizations. The campaign mimicked Russian threat actor behaviors as a false flag, complicating attribution and response. This incident highlights the increasing sophistication and frequency of social engineering attacks using trusted business tools as lures. The rise of targeted SEO poisoning, deceptive software installers, and identity obfuscation poses heightened risks for organizations handling sensitive data or operating in sensitive regions.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Sunbird DCIM Vulnerabilities Expose Critical Infrastructure: 2025 Authentication Bypass & Credential Risks
Impact· medium

Sunbird DCIM Vulnerabilities Expose Critical Infrastructure: 2025 Authentication Bypass & Credential Risks

In December 2025, security vulnerabilities were disclosed in Sunbird DCIM's dcTrack and Power IQ products, affecting all versions up to v9.2.0. Two significant flaws—an Authentication Bypass Using an Alternate Path or Channel (CVE-2025-66238) and the Use of Hard-coded Credentials (CVE-2025-66237)—could allow attackers to gain unauthorized access or escalate privileges within critical infrastructure environments. Threat actors abusing these vulnerabilities could redirect network traffic, access restricted services, or take control of host machines, exposing organizations to severe operational and reputational risks. This incident highlights the ongoing challenges organizations face in securing infrastructure management tools. Authentication and credential weaknesses remain a leading vector for cyberattacks amid increasing regulatory oversight and the proliferation of critical systems connected globally. Prompt patching and improved credential handling are now essential across industries facing similar risks.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Arizona AG Files 2024 Suit Against Temu Over User Data Harvesting
Impact· medium

Arizona AG Files 2024 Suit Against Temu Over User Data Harvesting

In May 2024, the Arizona Attorney General filed a lawsuit against Temu, a Chinese online retailer, over allegations that its mobile app covertly accesses and collects sensitive user data from U.S. consumers without their consent. According to the suit, Temu’s app harvested extensive information—including location data, contacts, and device details—beyond what was necessary for shopping functionality by exploiting excessive permissions and transmitting this data to servers in China. The unauthorized data harvesting raised concerns about deceptive business practices, potential privacy violations, and the exposure of personal information to foreign entities with unclear data handling standards. This incident is particularly important as governments and regulators escalate actions against technology firms accused of aggressive or opaque data-collection practices. With privacy regulations and user scrutiny on the rise, the Temu case highlights the urgent need for robust compliance and modern security controls to guard against stealthy apps harvesting sensitive information at scale.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Millions Exposed: ShadyPanda’s 2024 Browser Supply Chain Attack
Impact· high

Millions Exposed: ShadyPanda’s 2024 Browser Supply Chain Attack

In early 2024, the ShadyPanda cyber-threat group, linked to China, orchestrated a large-scale malware campaign by exploiting browser extensions on the Google Chrome and Microsoft Edge marketplaces. The attackers embedded malicious code into seemingly innocuous browser add-ons, silently weaponizing millions of user browsers worldwide. Once installed, these extensions enabled covert surveillance, data exfiltration, and potentially even lateral movement within corporate environments, posing severe risks to both individual privacy and enterprise security. The incident highlights the vulnerabilities in browser supply chains, with organizations scrambling to assess exposure and patch endpoints. This breach underscores a rising trend of sophisticated supply chain and browser-based attacks, where adversaries blend into daily workflows to evade detection. Security leaders must quickly reassess extension controls, threat detection strategies, and regulatory compliance amid growing regulatory scrutiny and persistent attacker innovation.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
How MuddyWater Used a Snake Game to Breach Israeli Networks in 2024
Impact· medium

How MuddyWater Used a Snake Game to Breach Israeli Networks in 2024

In early 2024, Iranian state-sponsored APT MuddyWater launched a series of cyberattacks against Israeli organizations using a novel evasion method involving a modified version of the classic Snake mobile game. Attackers embedded malicious code within the game to establish a covert communication channel and facilitate lateral movement within compromised networks. Initial access was likely achieved through phishing emails, followed by deployment of specially crafted files to disguise data exfiltration activities. The campaign resulted in unauthorized access to sensitive data and disruption of critical business operations for targeted Israeli entities. This incident highlights a growing trend of threat actors leveraging benign-looking applications and creative techniques to bypass traditional security controls. The use of retro games as a decoy demonstrates that sophisticated attackers are continually adapting, raising the bar for detection and forensic analysis across industries.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
How a 2025 SSH Trojan Attack Leveraged a Government IP and Masquerading Tactics
Impact· low

How a 2025 SSH Trojan Attack Leveraged a Government IP and Masquerading Tactics

In November 2025, a sophisticated cyberattack was observed when an adversary used SSH brute-force tactics to infiltrate a honeypot system, exploiting default 'root' credentials. Once inside, the attacker uploaded a malicious ELF binary, masquerading as the legitimate OpenSSH daemon ('sshd'), designed for persistence and stealth. The operation originated from a government-owned IP address, but evidence suggests the IP was likely compromised and misused, underscoring the complexity of attributing attacks. No commands were executed post-login, highlighting advanced attacker tradecraft focused on evasion and long-term foothold. This incident exemplifies modern threats leveraging credential reuse, sophisticated masquerading, and the abuse of trusted system binaries. Such attacks signal the growing use of covert techniques, presenting heightened risks to organizations and reinforcing the need for proactive defense, improved authentication practices, and advanced monitoring.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports