✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
ClickFix 2024: New Attack Exploits Fake Windows Update Screens to Spread Malware
In mid-2024, cybersecurity researchers identified a new ClickFix attack campaign where threat actors leveraged social engineering to trick users with a realistic, full-screen Windows Update animation within their browsers. Malicious code was cleverly hidden inside images on these spoofed update screens, evading many conventional security controls. Victims were lured to these pages via phishing links, leading to inadvertent malware installation, allowing attackers to potentially exfiltrate credentials, establish persistent remote access, or deploy additional payloads. Businesses across various industries may face operational risks such as lateral movement, data exfiltration, or ransomware threats as a result. This incident is particularly relevant as adversaries continue to refine social engineering and live-off-the-land tactics. The increasing sophistication of browser-based deception demonstrates the ongoing evolution of phishing and malware delivery methods, requiring organizations to continuously adapt their awareness training and layered defenses.
6 months ago
Kill Chain
SitusAMC Breach Exposes Sensitive Data in Real-Estate Finance Supply Chain
In June 2024, SitusAMC, a leading provider of real-estate finance back-end services, identified unauthorized access to systems containing client data. Attackers exploited a vulnerability in the company’s network infrastructure, resulting in the exposure of sensitive information related to financial institutions and their customers. SitusAMC promptly launched an investigation and notified impacted clients after confirming that personal and business data—including names, contact details, financial records, and transaction information—had been compromised. The breach triggered operational reviews and regulatory notification obligations, highlighting the company’s broad reach in the U.S. finance sector. This incident spotlights a worrisome trend of threat actors targeting managed services and supply chains in critical industries. With rising attacks focusing on lateral movement and data exfiltration, organizations face growing pressure from regulators and industry groups to prioritize segmentation, monitoring, and encryption across their digital estates.
6 months ago
Kill Chain
2025 Black Friday Cybercrime Surge: How E-Commerce, Banking & Gaming Users Were Targeted
During the 2025 Black Friday sales period, a massive wave of phishing, financial malware, and scam campaigns targeted global consumers across e-commerce, online banking, payment systems, and gaming platforms. Threat actors leveraged sophisticated phishing pages mimicking major retailers like Amazon, Alibaba, and Walmart, and deployed banking Trojans such as Maverick and Efimer via email and messaging apps. Over 6.4 million e-commerce phishing attempts and 1.09 million banking Trojan attacks were detected, with cybercriminals intensively exploiting shopping and gaming hype to harvest credentials, payment data, and digital assets. This incident highlights an ongoing shift as cyber attackers increasingly time their campaigns around large global retail events, exploiting predictable user behavior and surges in online activity. Threats have diversified across platforms, with a notable rise in attacks on gaming services and dramatic increases in malicious activity leveraging Discord and Steam, signaling a pressing need for adaptive, multi-layered cyber defenses.
6 months ago
Kill Chain
Fortinet & Chrome 2025: Anatomy of a Multi-Vector SaaS and 0-Day Breach
In November 2025, a coordinated wave of cyberattacks exploited zero-day vulnerabilities targeting Fortinet security appliances and Google Chrome, while also abusing software supply chains and SaaS platforms. Attackers employed advanced techniques including lateral movement within trusted environments, the deployment of custom malware like BadIIS, and supply-chain infiltration, allowing them to bypass perimeter defenses and remain undetected across enterprise networks. Major cloud and SaaS providers such as Microsoft, Salesforce, and Google rapidly initiated emergency incident response, mitigating exploit attempts, DDoS attacks, and malicious update channels affecting a wide range of organizations. This incident marks a sharp escalation in multi-vector threats—combining zero-day exploitation, supply-chain compromise, and SaaS risk. The campaign aligns with the latest tactics of threat actors leveraging trusted software channels and abusing cloud-native tools, underscoring rising regulatory scrutiny and the urgent need for robust zero trust security measures across multi-cloud and SaaS environments.
6 months ago
Kill Chain
ShadowPad Malware Leverages New WSUS Flaw for Full-System Compromise (2025)
In November 2025, attackers leveraged a recently patched WSUS vulnerability (CVE-2025-59287) to compromise Windows Servers and distribute ShadowPad malware. According to the AhnLab Security Intelligence Center, the threat actors exploited misconfigurations in Windows Server Update Services to gain initial access, then deployed the open-source PowerCat tool to establish remote control and facilitate lateral movement. This campaign targeted enterprises relying on WSUS for patch management, allowing attackers to achieve persistent, full-system access and exfiltrate sensitive operational data. This incident underscores the growing threat of sophisticated supply chain attacks that exploit ubiquitous IT infrastructure and patched vulnerabilities. It highlights the urgent need for continuous visibility, proactive patch management, and comprehensive zero trust strategies across data centers and cloud environments.
6 months ago
Kill Chain
Fluent Bit 2025: Supply Chain Vulnerabilities Endanger Cloud Infrastructures
In October 2025, researchers unveiled a set of five critical vulnerabilities in Fluent Bit, a widely-adopted open-source cloud telemetry agent. These vulnerabilities allowed threat actors to bypass authentication and carry out path traversal attacks, achieving remote code execution and potential full infrastructure compromise. Exploiting these flaws, attackers could gain lateral movement inside cloud environments, disrupt operations via denial-of-service, and manipulate data tags, threatening confidentiality and availability across cloud deployments. The compromise highlights significant risks inherent in modern cloud supply chains, as compromised upstream dependencies can quickly propagate and affect numerous downstream organizations. This incident is particularly significant as supply-chain vulnerabilities targeting cloud-native tools are rising sharply, mirroring an industry-wide shift toward “living off the land” attacks. As organizations adopt more open-source agents and components, attackers increasingly exploit integration points, elevating the risk profile for even mature cloud infrastructures.
6 months ago
Kill Chain
Sha1-Hulud Strikes npm: Credential Theft Campaign Hits Over 25,000 Open-Source Repositories
In November 2025, security researchers uncovered a widespread supply chain attack dubbed the "Sha1-Hulud" wave targeting the npm registry. Threat actors compromised over 25,000 repositories by trojanizing hundreds of widely used npm packages, injecting malicious code into the preinstall scripts. This code siphoned developer credentials and environmental secrets during package installations, potentially giving attackers unauthorized access to private projects and infrastructure. The campaign relied on malicious npm uploads, affecting downstream open-source users and organizations across the software supply chain. This incident highlights the persistent risk of supply chain attacks via popular package ecosystems, underscoring the need for robust code vetting, audit logging, and least privilege principles. With growing reliance on open-source software, attackers continue to exploit trusted platforms to achieve broad compromise.
6 months ago
Kill Chain
Inside the STORM-2603 & JustAskJacky Multi-Vector macOS Stealer Campaign
In November 2025, a sophisticated multi-vector cyber campaign targeted macOS users, leveraging a cluster of new information stealers and advanced lateral movement techniques. Threat actors, prominently STORM-2603 and JustAskJacky, exploited vulnerabilities in east-west traffic controls and manipulated encrypted traffic in hybrid cloud environments to evade detection. Utilizing covert remote-access tools and exploiting hybrid connectivity pathways, the attackers exfiltrated sensitive business and personal data—including credentials and intellectual property—before security teams were alerted. The coordinated attack spanned several organizations, resulting in notable data leaks and operational disruption. This incident highlights the growing trend of high-performance, cross-platform info-stealing malware and the convergence of cloud, on-prem, and user device threats. Security leaders should note the increased adoption of identity-based policy enforcement, robust segmentation, and enhanced anomaly detection to counter similar campaigns now escalating in prevalence.
6 months ago
Kill Chain
Rondo Botnet Exploits Pentaho URL Mapping Flaws: Lessons from the 2022 Breach
In late 2022, the Hitachi Vantara Pentaho Business Analytics Server was targeted by attackers exploiting CVE-2022-43939 and CVE-2022-43769, leveraging flaws in URL mapping and URL-based access control. Threat actors, including the 'Rondo' botnet group, exploited a template injection vulnerability that allowed unauthenticated command execution by bypassing authentication controls via specific URL paths. This enabled attackers to remotely execute arbitrary code, potentially gaining control over affected systems, exfiltrate data, and laterally move within enterprise networks. The automation and scale of these attacks highlighted application misconfigurations, lapses in secure access control design, and the ongoing risk of vulnerable web application endpoints. This incident underscores a broader trend of threat actors exploiting subtle misconfigurations in URL handling and web server rules. Organizations are now under increased regulatory and operational pressure to audit legacy web applications and APIs, implement zero trust segmentation, and rigorously validate access control rules as attackers aggressively pursue these weaknesses.
6 months ago
Kill Chain
Salesloft Drift SaaS Breach: How Excessive Trust Unlocked CRM Data
In early 2024, the Salesloft Drift SaaS integration breach unfolded when attackers exploited security weaknesses in the Drift chatbot’s OAuth implementation. Malicious actors obtained chatbot OAuth tokens—intended for secure system integrations—and leveraged these for legitimate API calls against customer CRM environments, such as Salesforce. Because the tokens remained valid and were often granted excessive standing privileges, attackers could exfiltrate sensitive business records, contact information, support data, and even embedded credentials across over 700 organizations, all without immediate detection. This breach underscored a powerful new threat vector involving identity and permissions sprawl in SaaS and AI-driven environments. As organizations increasingly rely on deeply integrated third-party systems with broad and persistent access, similar attacks targeting privileged automation and identity-based authorizations are expected to surge without robust governance and continuous monitoring.
6 months ago
Kill Chain
Iberia Data Breach (2024): Supply Chain Compromise Exposes Airline Customer Data
In June 2024, Spanish airline Iberia disclosed a significant data breach originating from the compromise of an external supplier. Attackers leveraged a third-party network to steal approximately 77 GB of sensitive customer data, including contact information, travel details, and partial payment card data. The breach was first publicized on underground forums, with threat actors claiming possession of the data days before Iberia notified its customers. The incident underscores how supply chain vulnerabilities can directly jeopardize core business operations and customer trust, disrupting service continuity and triggering regulatory scrutiny for the airline industry. This breach illustrates the ongoing escalation of supply chain attacks, where organizations are exposed through weak vendor controls. With similar tactics increasingly exploited against critical infrastructure, maintaining robust controls over partners is now essential in light of growing attacker sophistication and tightening data protection requirements.
6 months ago
Kill Chain
CISA Issues Urgent Alert: Oracle Identity Manager Zero-Day (CVE-2025-61757) Exploited in Active Attacks
In June 2025, CISA issued an emergency warning following the discovery of active exploitation against Oracle Identity Manager (OIM), targeting a critical remote code execution vulnerability tracked as CVE-2025-61757. Attackers leveraged this flaw, possibly as a zero-day, to gain unauthorized access to governmental and enterprise identity infrastructures. Evidence shows threat actors performed arbitrary code execution on affected systems, enabling privilege escalation and potential lateral movement within targeted networks. This breach presents serious risks to the integrity and availability of authentication systems, exposing sensitive data and potentially undermining access controls across impacted organizations. The incident stands out due to a surge in direct attacks targeting identity infrastructure and core authentication providers. The increasing reliance on identity management platforms makes these systems high-value targets, highlighting a broader trend towards exploiting supply chain and zero-day vulnerabilities with immediate, widespread consequences.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports