Validated Containment Architectures are here. →Explore

Industry Category

Financial Services

Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.

3643 threat reports
Page 237 of 304

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Financial Services Threat Reports

Showing 28332844 / 3643 reports
CISA Flags New Chromium Browser Exploit: CVE-2025-13223 in Active Use
Impact· medium

CISA Flags New Chromium Browser Exploit: CVE-2025-13223 in Active Use

On November 19, 2025, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-13223—an actively exploited type confusion vulnerability in the Google Chromium V8 JavaScript engine—to its Known Exploited Vulnerabilities (KEV) Catalog. This flaw allows remote attackers to execute arbitrary code via a crafted web page, exploiting weaknesses in Chromium-based browsers used by federal and commercial entities. Threat actors have been leveraging this vulnerability to deliver malware and potentially gain unauthorized access to systems, heightening risk across government and enterprise environments. This incident is highly relevant as attackers continue to target zero-day and rapidly weaponized browser flaws, reflecting a broader trend of exploiting client-side vulnerabilities to bypass traditional network defenses. Regulatory and industry pressure for rapid patch management and strong endpoint protection is intensifying as attackers' tactics evolve.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Cloud Firewall Flaws Lead to Widespread IoT Takeovers in 2024
Impact· low

Cloud Firewall Flaws Lead to Widespread IoT Takeovers in 2024

In early 2024, security researchers uncovered a critical cloud misconfiguration enabling silent takeover of internet-connected IoT devices by exploiting gaps in firewall and router management interfaces. Attackers, leveraging lax default policies and insufficient segmentation in multi-cloud environments, gained unauthorized access to endpoints despite security software being in place. The exploit did not require the devices to be directly connected to the public internet—instead, it relied on weaknesses within cloud firewall interfaces and poor east-west traffic controls, allowing attackers to pivot laterally and compromise large numbers of devices with little to no detection. The resulting impact includes device disruption, risk of data exfiltration, and potential staging for larger attacks. This incident comes amid a surge in attacks against IoT and operational technology, with adversaries increasingly targeting missteps in cloud security architectures rather than application-level flaws. The trend underscores the urgency for organizations to implement multi-layered segmentation, robust policy enforcement, and continuous cloud configuration monitoring to defend against rapidly-evolving lateral movement tactics.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Cloudflare's 2024 Outage: How a Simple Misconfiguration Led to Global Disruption
Impact· high

Cloudflare's 2024 Outage: How a Simple Misconfiguration Led to Global Disruption

In June 2024, Cloudflare, a leading cloud services provider, experienced a major global outage initially suspected to be the result of a distributed denial-of-service (DDoS) attack. Further investigation revealed that the real cause was an internal configuration error: a routine permissions update inadvertently triggered a critical software failure within network infrastructure, disrupting access to innumerable customer websites and business services for several hours worldwide. The incident underscored the fragile interplay between automated change management and resiliency of cloud-based operations. This outage is especially timely as organizations accelerate cloud adoption and automation, increasing their susceptibility to operational lapses and accidental misconfigurations. Regulatory bodies and industry frameworks are now sharpening requirements for cloud governance, real-time visibility, and robust change controls to mitigate such risks.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(high)
Read Report
Anatomy of an Akira Ransomware Attack: 42 Days Hidden After a Fake CAPTCHA
Impact· high

Anatomy of an Akira Ransomware Attack: 42 Days Hidden After a Fake CAPTCHA

In early 2024, a sophisticated cyberattack attributed to the Akira ransomware group exploited a fake CAPTCHA page to infiltrate an organization's environment. Attackers used this social engineering technique as an entry point, deploying malware that enabled persistent access and undetected movement across internal systems for 42 days. During this period, lateral movement and privilege escalation allowed the attackers to exfiltrate data and ultimately deploy ransomware, encrypting vital business assets and causing significant operational disruption. The incident illustrates how modern ransomware actors leverage stealth, deception, and extended dwell times to maximize their impact. This case underscores an escalating trend of increasingly complex and targeted ransomware attacks that blend technical exploitation with effective social engineering. Organizations are being challenged to enhance east-west traffic security, real-time threat detection, and zero trust segmentation to counter these evolving threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Unicode: The Hidden Security Threat Fueling 2024's Obfuscated Code Attacks
Impact· low

Unicode: The Hidden Security Threat Fueling 2024's Obfuscated Code Attacks

In late 2024, security researchers highlighted a series of application security vulnerabilities caused by improper handling of the Unicode character set, impacting numerous platforms and development environments. Attackers exploited Unicode features such as confusable characters, variant selectors, and bidirectional text markers, enabling impersonation, injection, and severe obfuscation of code in public repositories. Notably, a self-propagating worm known as "Glass Worm" leveraged invisible Unicode code points to disguise malicious code in Visual Studio Code extensions, bypassing manual code review and automated security checks. These techniques led to increased risk of code injection, credential spoofing, and long-term compromise of software supply chains. Unicode-driven attack techniques continue to gain prominence due to their effectiveness at evading human and automated detection. The recent spike in attacks demonstrates a broader trend towards supply chain risk and advanced code obfuscation, demanding urgent attention to Unicode normalization, secure coding practices, and robust detection mechanisms in compliance-driven industries.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
Malicious NPM Packages Exploit Adspect in 2024 Supply Chain Breach
Impact· low

Malicious NPM Packages Exploit Adspect in 2024 Supply Chain Breach

In June 2024, security researchers uncovered a supply chain attack involving seven malicious packages on the NPM registry that abused the Adspect cloud-based service. Attackers used these packages to redirect users through Adspect, circumventing many security sandboxes and researcher analysis tools. This sophisticated evasion allowed threat actors to selectively route potential victims to malicious payloads while deflecting scrutiny from security firms. The malicious packages were rapidly removed from NPM, but not before posing a significant risk to open-source software supply chains. This incident highlights the increasing exploitation of trusted third-party platforms and infrastructure in software supply chain attacks. With adversaries leveraging evasive redirects and advanced obfuscation tactics, organizations face a growing need for robust dependency management, automated threat detection, and enhanced monitoring of public code repositories.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
CISA 2025 Issues Guidance to Mitigate Bulletproof Hosting Provider Risks
Impact· medium

CISA 2025 Issues Guidance to Mitigate Bulletproof Hosting Provider Risks

In November 2025, the Cybersecurity and Infrastructure Security Agency (CISA), together with the NSA, FBI, Department of Defense Cyber Crime Center, and international partners, released comprehensive guidance to combat risks posed by Bulletproof Hosting Providers (BPHs). BPHs are infrastructure providers that knowingly lease servers and networking resources to cybercriminals, enabling ransomware, phishing, malware distribution, and denial-of-service attacks at scale. The guidance urges Internet Service Providers and network operators to apply blocklists, traffic analysis, intelligence sharing, and stronger vetting to prevent malicious actors from exploiting BPH resources, aiming to bolster the digital resilience of critical infrastructure sectors globally. The ongoing proliferation of cyberattacks leveraging BPH infrastructure underscores the urgency of these recommendations. With threat actors increasingly turning to anonymized, resilient hosting to evade law enforcement and detection, proactive mitigation by ISPs is crucial to limiting damage and strengthening industry-wide cybersecurity defense.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Fortinet FortiWeb Zero-Day Abuse: 2024 Attack Highlights Security Device Risks
Impact· low

Fortinet FortiWeb Zero-Day Abuse: 2024 Attack Highlights Security Device Risks

In June 2024, Fortinet disclosed a critical zero-day vulnerability in its FortiWeb web application firewall that was being actively exploited in the wild. Threat actors leveraged the unknown flaw to gain unauthorized access to targeted organizations, bypassing authentication and potentially altering application configurations or exfiltrating sensitive data. Fortinet responded promptly by releasing security patches and urging customers to update affected devices, while security researchers warned this campaign was already impacting several organizations before public disclosure. This incident is part of a growing trend of sophisticated attacks targeting network and security appliances through undisclosed vulnerabilities. Organizations face heightened risk as attackers weaponize zero-days more quickly, making swift patch management and layered controls essential to defending digital infrastructure.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Google Chrome 2024 Zero-Day Exploited in the Wild: What You Need to Know
Impact· low

Google Chrome 2024 Zero-Day Exploited in the Wild: What You Need to Know

In June 2024, Google disclosed and patched a critical zero-day vulnerability in the Chrome web browser (CVE-2024-5274) that had actively been exploited in the wild. Attackers leveraged a type confusion flaw in Chrome’s V8 JavaScript engine to execute arbitrary code on victim devices, enabling full compromise of targeted systems. Google's rapid response—releasing an emergency security update—helped mitigate exploitation risks. The vulnerability represented the seventh zero-day affecting Chrome this year, underscoring persistent targeting of popular browsers for initial access into corporate and consumer environments. This incident illustrates the sustained threat posed by browser zero-days and the increasing velocity with which attackers are weaponizing new flaws. As web browsers remain a ubiquitous endpoint attack vector, organizations must ensure rapid patch cycles and layered security controls to limit exposure.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Tycoon 2FA: How Phishing-as-a-Service Broke Legacy MFA at Scale in 2024
Impact· low

Tycoon 2FA: How Phishing-as-a-Service Broke Legacy MFA at Scale in 2024

In 2024, cybercriminals leveraged the Tycoon Phishing-as-a-Service (PaaS) platform to orchestrate over 64,000 successful real-time attacks bypassing legacy multi-factor authentication (MFA) with relay-based phishing toolkits. Tycoon allowed even low-skilled attackers to automate the interception and relay of users’ MFA tokens, defeating common one-time passcodes and push-based authentication. This Phishing-as-a-Service campaign targeted a wide array of industries and organizations, exposing user credentials and compromising sensitive systems at scale. The incident underscores the urgent collapse of legacy MFA methods under modern, scalable phishing threats. The widespread exposure from Tycoon demonstrates how phishing-resistant authentication (such as FIDO2 hardware tokens and biometrics) are now critical. Regulatory agencies and security experts have since elevated calls for organizations to rapidly phase out vulnerable MFA in favor of hardware-backed solutions, as attackers weaponize automated, scalable PaaS infrastructure.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Pajemploi Data Breach Exposes 1.2 Million French Citizens: What Went Wrong?
Impact· high

Pajemploi Data Breach Exposes 1.2 Million French Citizens: What Went Wrong?

In June 2024, French public agency Pajemploi, responsible for social security management for parents and home childcare providers, suffered a large-scale data breach. Attackers exploited a flaw in the agency's online system that enabled them to access personal data belonging to approximately 1.2 million individuals, including names, addresses, social security numbers, bank details, and tax identification data. The breach was discovered after abnormal activity was detected, and Pajemploi acted swiftly to close the vulnerability, notify affected users, and inform regulatory authorities, including France's data privacy regulator CNIL. The incident temporarily restricted access to certain online services for impacted users. This breach highlights the ongoing targeting of government and public-sector databases holding sensitive citizen data. With regulatory requirements such as GDPR placing heavy penalties on agencies that fail proper controls, the Pajemploi incident underscores the urgency of robust data protection, zero trust segmentation, and advanced anomaly detection across Europe’s digital public services.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
Google Chrome’s 2025 V8 Zero-Day: What Organizations Must Do After the Latest Exploit
Impact· low

Google Chrome’s 2025 V8 Zero-Day: What Organizations Must Do After the Latest Exploit

In June 2025, Google disclosed an actively exploited zero-day vulnerability (CVE-2025-13223) in the V8 JavaScript and WebAssembly engine powering Chrome. Attackers leveraged this type confusion flaw to execute arbitrary code or trigger program crashes, enabling them to compromise vulnerable browsers. Google promptly released patches to address the flaw after receiving reports of in-the-wild exploitation. At-risk users included anyone running unpatched Chrome versions across platforms, with attackers potentially able to hijack sessions, install malware, or steal sensitive data simply by enticing users to visit a malicious web page. This incident highlights the persistent risks posed by emerging browser vulnerabilities, as both sophisticated threat actors and opportunistic cybercriminals increasingly exploit zero-day flaws for rapid compromise. Security teams face mounting urgency to prioritize browser patching cycles to counter fast-moving, exploitation-ready threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports