Validated Containment Architectures are here. →Explore

Industry Category

Financial Services

Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.

3629 threat reports
Page 230 of 303

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Financial Services Threat Reports

Showing 27492760 / 3629 reports
ClickFix 2024: New Attack Exploits Fake Windows Update Screens to Spread Malware
Impact· medium

ClickFix 2024: New Attack Exploits Fake Windows Update Screens to Spread Malware

In mid-2024, cybersecurity researchers identified a new ClickFix attack campaign where threat actors leveraged social engineering to trick users with a realistic, full-screen Windows Update animation within their browsers. Malicious code was cleverly hidden inside images on these spoofed update screens, evading many conventional security controls. Victims were lured to these pages via phishing links, leading to inadvertent malware installation, allowing attackers to potentially exfiltrate credentials, establish persistent remote access, or deploy additional payloads. Businesses across various industries may face operational risks such as lateral movement, data exfiltration, or ransomware threats as a result. This incident is particularly relevant as adversaries continue to refine social engineering and live-off-the-land tactics. The increasing sophistication of browser-based deception demonstrates the ongoing evolution of phishing and malware delivery methods, requiring organizations to continuously adapt their awareness training and layered defenses.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
SitusAMC Breach Exposes Sensitive Data in Real-Estate Finance Supply Chain
Impact· high

SitusAMC Breach Exposes Sensitive Data in Real-Estate Finance Supply Chain

In June 2024, SitusAMC, a leading provider of real-estate finance back-end services, identified unauthorized access to systems containing client data. Attackers exploited a vulnerability in the company’s network infrastructure, resulting in the exposure of sensitive information related to financial institutions and their customers. SitusAMC promptly launched an investigation and notified impacted clients after confirming that personal and business data—including names, contact details, financial records, and transaction information—had been compromised. The breach triggered operational reviews and regulatory notification obligations, highlighting the company’s broad reach in the U.S. finance sector. This incident spotlights a worrisome trend of threat actors targeting managed services and supply chains in critical industries. With rising attacks focusing on lateral movement and data exfiltration, organizations face growing pressure from regulators and industry groups to prioritize segmentation, monitoring, and encryption across their digital estates.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
2025 Black Friday Cybercrime Surge: How E-Commerce, Banking & Gaming Users Were Targeted
Impact· medium

2025 Black Friday Cybercrime Surge: How E-Commerce, Banking & Gaming Users Were Targeted

During the 2025 Black Friday sales period, a massive wave of phishing, financial malware, and scam campaigns targeted global consumers across e-commerce, online banking, payment systems, and gaming platforms. Threat actors leveraged sophisticated phishing pages mimicking major retailers like Amazon, Alibaba, and Walmart, and deployed banking Trojans such as Maverick and Efimer via email and messaging apps. Over 6.4 million e-commerce phishing attempts and 1.09 million banking Trojan attacks were detected, with cybercriminals intensively exploiting shopping and gaming hype to harvest credentials, payment data, and digital assets. This incident highlights an ongoing shift as cyber attackers increasingly time their campaigns around large global retail events, exploiting predictable user behavior and surges in online activity. Threats have diversified across platforms, with a notable rise in attacks on gaming services and dramatic increases in malicious activity leveraging Discord and Steam, signaling a pressing need for adaptive, multi-layered cyber defenses.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Fortinet & Chrome 2025: Anatomy of a Multi-Vector SaaS and 0-Day Breach
Impact· medium

Fortinet & Chrome 2025: Anatomy of a Multi-Vector SaaS and 0-Day Breach

In November 2025, a coordinated wave of cyberattacks exploited zero-day vulnerabilities targeting Fortinet security appliances and Google Chrome, while also abusing software supply chains and SaaS platforms. Attackers employed advanced techniques including lateral movement within trusted environments, the deployment of custom malware like BadIIS, and supply-chain infiltration, allowing them to bypass perimeter defenses and remain undetected across enterprise networks. Major cloud and SaaS providers such as Microsoft, Salesforce, and Google rapidly initiated emergency incident response, mitigating exploit attempts, DDoS attacks, and malicious update channels affecting a wide range of organizations. This incident marks a sharp escalation in multi-vector threats—combining zero-day exploitation, supply-chain compromise, and SaaS risk. The campaign aligns with the latest tactics of threat actors leveraging trusted software channels and abusing cloud-native tools, underscoring rising regulatory scrutiny and the urgent need for robust zero trust security measures across multi-cloud and SaaS environments.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
ShadowPad Malware Leverages New WSUS Flaw for Full-System Compromise (2025)
Impact· low

ShadowPad Malware Leverages New WSUS Flaw for Full-System Compromise (2025)

In November 2025, attackers leveraged a recently patched WSUS vulnerability (CVE-2025-59287) to compromise Windows Servers and distribute ShadowPad malware. According to the AhnLab Security Intelligence Center, the threat actors exploited misconfigurations in Windows Server Update Services to gain initial access, then deployed the open-source PowerCat tool to establish remote control and facilitate lateral movement. This campaign targeted enterprises relying on WSUS for patch management, allowing attackers to achieve persistent, full-system access and exfiltrate sensitive operational data. This incident underscores the growing threat of sophisticated supply chain attacks that exploit ubiquitous IT infrastructure and patched vulnerabilities. It highlights the urgent need for continuous visibility, proactive patch management, and comprehensive zero trust strategies across data centers and cloud environments.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
Fluent Bit 2025: Supply Chain Vulnerabilities Endanger Cloud Infrastructures
Impact· medium

Fluent Bit 2025: Supply Chain Vulnerabilities Endanger Cloud Infrastructures

In October 2025, researchers unveiled a set of five critical vulnerabilities in Fluent Bit, a widely-adopted open-source cloud telemetry agent. These vulnerabilities allowed threat actors to bypass authentication and carry out path traversal attacks, achieving remote code execution and potential full infrastructure compromise. Exploiting these flaws, attackers could gain lateral movement inside cloud environments, disrupt operations via denial-of-service, and manipulate data tags, threatening confidentiality and availability across cloud deployments. The compromise highlights significant risks inherent in modern cloud supply chains, as compromised upstream dependencies can quickly propagate and affect numerous downstream organizations. This incident is particularly significant as supply-chain vulnerabilities targeting cloud-native tools are rising sharply, mirroring an industry-wide shift toward “living off the land” attacks. As organizations adopt more open-source agents and components, attackers increasingly exploit integration points, elevating the risk profile for even mature cloud infrastructures.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Sha1-Hulud Strikes npm: Credential Theft Campaign Hits Over 25,000 Open-Source Repositories
Impact· medium

Sha1-Hulud Strikes npm: Credential Theft Campaign Hits Over 25,000 Open-Source Repositories

In November 2025, security researchers uncovered a widespread supply chain attack dubbed the "Sha1-Hulud" wave targeting the npm registry. Threat actors compromised over 25,000 repositories by trojanizing hundreds of widely used npm packages, injecting malicious code into the preinstall scripts. This code siphoned developer credentials and environmental secrets during package installations, potentially giving attackers unauthorized access to private projects and infrastructure. The campaign relied on malicious npm uploads, affecting downstream open-source users and organizations across the software supply chain. This incident highlights the persistent risk of supply chain attacks via popular package ecosystems, underscoring the need for robust code vetting, audit logging, and least privilege principles. With growing reliance on open-source software, attackers continue to exploit trusted platforms to achieve broad compromise.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Inside the STORM-2603 & JustAskJacky Multi-Vector macOS Stealer Campaign
Impact· medium

Inside the STORM-2603 & JustAskJacky Multi-Vector macOS Stealer Campaign

In November 2025, a sophisticated multi-vector cyber campaign targeted macOS users, leveraging a cluster of new information stealers and advanced lateral movement techniques. Threat actors, prominently STORM-2603 and JustAskJacky, exploited vulnerabilities in east-west traffic controls and manipulated encrypted traffic in hybrid cloud environments to evade detection. Utilizing covert remote-access tools and exploiting hybrid connectivity pathways, the attackers exfiltrated sensitive business and personal data—including credentials and intellectual property—before security teams were alerted. The coordinated attack spanned several organizations, resulting in notable data leaks and operational disruption. This incident highlights the growing trend of high-performance, cross-platform info-stealing malware and the convergence of cloud, on-prem, and user device threats. Security leaders should note the increased adoption of identity-based policy enforcement, robust segmentation, and enhanced anomaly detection to counter similar campaigns now escalating in prevalence.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Rondo Botnet Exploits Pentaho URL Mapping Flaws: Lessons from the 2022 Breach
Impact· low

Rondo Botnet Exploits Pentaho URL Mapping Flaws: Lessons from the 2022 Breach

In late 2022, the Hitachi Vantara Pentaho Business Analytics Server was targeted by attackers exploiting CVE-2022-43939 and CVE-2022-43769, leveraging flaws in URL mapping and URL-based access control. Threat actors, including the 'Rondo' botnet group, exploited a template injection vulnerability that allowed unauthenticated command execution by bypassing authentication controls via specific URL paths. This enabled attackers to remotely execute arbitrary code, potentially gaining control over affected systems, exfiltrate data, and laterally move within enterprise networks. The automation and scale of these attacks highlighted application misconfigurations, lapses in secure access control design, and the ongoing risk of vulnerable web application endpoints. This incident underscores a broader trend of threat actors exploiting subtle misconfigurations in URL handling and web server rules. Organizations are now under increased regulatory and operational pressure to audit legacy web applications and APIs, implement zero trust segmentation, and rigorously validate access control rules as attackers aggressively pursue these weaknesses.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
Salesloft Drift SaaS Breach: How Excessive Trust Unlocked CRM Data
Impact· medium

Salesloft Drift SaaS Breach: How Excessive Trust Unlocked CRM Data

In early 2024, the Salesloft Drift SaaS integration breach unfolded when attackers exploited security weaknesses in the Drift chatbot’s OAuth implementation. Malicious actors obtained chatbot OAuth tokens—intended for secure system integrations—and leveraged these for legitimate API calls against customer CRM environments, such as Salesforce. Because the tokens remained valid and were often granted excessive standing privileges, attackers could exfiltrate sensitive business records, contact information, support data, and even embedded credentials across over 700 organizations, all without immediate detection. This breach underscored a powerful new threat vector involving identity and permissions sprawl in SaaS and AI-driven environments. As organizations increasingly rely on deeply integrated third-party systems with broad and persistent access, similar attacks targeting privileged automation and identity-based authorizations are expected to surge without robust governance and continuous monitoring.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Iberia Data Breach (2024): Supply Chain Compromise Exposes Airline Customer Data
Impact· high

Iberia Data Breach (2024): Supply Chain Compromise Exposes Airline Customer Data

In June 2024, Spanish airline Iberia disclosed a significant data breach originating from the compromise of an external supplier. Attackers leveraged a third-party network to steal approximately 77 GB of sensitive customer data, including contact information, travel details, and partial payment card data. The breach was first publicized on underground forums, with threat actors claiming possession of the data days before Iberia notified its customers. The incident underscores how supply chain vulnerabilities can directly jeopardize core business operations and customer trust, disrupting service continuity and triggering regulatory scrutiny for the airline industry. This breach illustrates the ongoing escalation of supply chain attacks, where organizations are exposed through weak vendor controls. With similar tactics increasingly exploited against critical infrastructure, maintaining robust controls over partners is now essential in light of growing attacker sophistication and tightening data protection requirements.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
CISA Issues Urgent Alert: Oracle Identity Manager Zero-Day (CVE-2025-61757) Exploited in Active Attacks
Impact· low

CISA Issues Urgent Alert: Oracle Identity Manager Zero-Day (CVE-2025-61757) Exploited in Active Attacks

In June 2025, CISA issued an emergency warning following the discovery of active exploitation against Oracle Identity Manager (OIM), targeting a critical remote code execution vulnerability tracked as CVE-2025-61757. Attackers leveraged this flaw, possibly as a zero-day, to gain unauthorized access to governmental and enterprise identity infrastructures. Evidence shows threat actors performed arbitrary code execution on affected systems, enabling privilege escalation and potential lateral movement within targeted networks. This breach presents serious risks to the integrity and availability of authentication systems, exposing sensitive data and potentially undermining access controls across impacted organizations. The incident stands out due to a surge in direct attacks targeting identity infrastructure and core authentication providers. The increasing reliance on identity management platforms makes these systems high-value targets, highlighting a broader trend towards exploiting supply chain and zero-day vulnerabilities with immediate, widespread consequences.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports