Validated Containment Architectures are here. →Explore

Industry Category

Financial Services

Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.

3643 threat reports
Page 238 of 304

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Financial Services Threat Reports

Showing 28452856 / 3643 reports
Microsoft Thwarts Record-Breaking 15.72 Tbps DDoS Attack Orchestrated by AISURU Botnet
Impact· high

Microsoft Thwarts Record-Breaking 15.72 Tbps DDoS Attack Orchestrated by AISURU Botnet

In November 2025, Microsoft successfully detected and mitigated an unprecedented Distributed Denial-of-Service (DDoS) attack that peaked at 15.72 Tbps, targeting a cloud endpoint in Australia. The attack, orchestrated by the AISURU botnet leveraging TurboMirai-class malware, generated nearly 3.64 billion packets per second. Advanced protections within Microsoft's Azure platform automatically neutralized the threat before it could affect customer availability or data. Microsoft attributed the attack to highly automated botnets leveraging compromised IoT devices and observed a rapid, multi-vector assault designed to test cloud resilience and incident response. This record-breaking event highlights the escalating scale and sophistication of DDoS activity targeting foundational cloud infrastructure. As attackers exploit larger IoT botnets and novel malware strains, defenders face mounting pressure to evolve detection and mitigation at cloud-scale. Organizations must increasingly invest in robust DDoS protection and continuously monitor for emerging threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
ShadowRay 2.0: How Ray Cluster Flaws Fueled a Cryptomining Botnet
Impact· high

ShadowRay 2.0: How Ray Cluster Flaws Fueled a Cryptomining Botnet

In June 2024, cybersecurity researchers identified a coordinated global attack campaign dubbed ShadowRay 2.0 targeting exposed Ray clusters—open-source distributed computing environments widely used in AI and machine learning workloads. Attackers exploited an unpatched remote code execution vulnerability in Ray's dashboard service, gaining unauthorized access to cloud and on-premises clusters. Once inside, adversaries deployed self-spreading cryptomining malware, turning infected clusters into part of a large-scale botnet that harnessed high-performance compute resources for illicit cryptocurrency mining, causing potential performance degradation, elevated cloud bills, and risk of further lateral movement. This campaign demonstrates the growing threat surface posed by AI and data infrastructure, as adversaries increasingly automate the exploitation of software supply chain and configuration weaknesses. The incident highlights the urgency of securing east-west traffic, enforcing least privilege, and maintaining continuous vulnerability management in distributed and cloud-native environments.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
npm Supply-Chain Threat: Seven Malicious Packages Cloak Crypto Scams in 2025
Impact· high

npm Supply-Chain Threat: Seven Malicious Packages Cloak Crypto Scams in 2025

In late 2025, cybersecurity researchers uncovered a supply-chain attack involving seven malicious npm packages uploaded by the threat actor 'dino_reborn.' These packages leveraged Adspect cloaking technology to detect if visitors were victims or security researchers. Unsuspecting users were redirected to fraudulent cryptocurrency-themed websites, exposing them to potential scams or malware. The packages were published between September and November 2025 and remained available until detection, highlighting the challenges in securing open-source ecosystems. This incident is part of a growing trend involving supply-chain attacks targeting widely used software repositories. As more attackers adopt advanced evasion measures like traffic cloaking and nuanced social engineering, the risk and complexity of defending modern development pipelines are rapidly increasing.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Researchers Reveal Tuoni C2’s Role in 2025 Real-Estate Cyber Attack
Impact· medium

Researchers Reveal Tuoni C2’s Role in 2025 Real-Estate Cyber Attack

In early November 2025, a prominent U.S.-based real-estate company was targeted in a sophisticated cyber attack utilizing the Tuoni command-and-control (C2) framework, a new red-teaming tool known for implementing stealthy, in-memory payload delivery. The attackers exploited Tuoni C2’s advanced capabilities to infiltrate the network while evading traditional security controls, demonstrating lateral movement and attempting data collection within internal segments. Although swift detection halted major exfiltration, the intrusion highlighted gaps in east-west traffic visibility and segmentation, causing temporary disruption to key business systems and prompting an urgent review of internal controls. This attack underscores the growing trend of adversaries adopting novel, freely available C2 tools to bypass existing enterprise defenses. It reflects broader industry concern as C2 frameworks like Tuoni fuel increased attack sophistication, especially in sectors handling large volumes of sensitive data such as real estate and finance.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Sneaky 2FA Kit Innovates with BitB Pop-up Phishing: MFA Bypass at Scale
Impact· low

Sneaky 2FA Kit Innovates with BitB Pop-up Phishing: MFA Bypass at Scale

In November 2025, security researchers reported on the evolving Sneaky 2FA Phishing-as-a-Service (PhaaS) kit, which now features sophisticated Browser-in-the-Browser (BitB) pop-ups that convincingly mimic legitimate browser address bars. These enhancements enable threat actors, including low-skilled attackers, to deploy highly realistic phishing attacks at scale and bypass multi-factor authentication (MFA) protections. Victims, typically employees of enterprises and large organizations, are tricked into entering credentials and 2FA codes into deceptive portals, facilitating account compromise and potential unauthorized access to sensitive business assets. This incident highlights a troubling trend of phishing toolkits increasing in sophistication, making advanced attacks accessible to broader criminal audiences. Organizations are now facing growing regulatory and operational pressure to update authentication, identity protection, and detection controls amid a wave of phishing leveraging MFA bypass and deceptive visual TTPs.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
CISA Flags Critical Fortinet FortiWeb Vulnerability: CVE-2025-58034 Joins KEV Catalog
Impact· low

CISA Flags Critical Fortinet FortiWeb Vulnerability: CVE-2025-58034 Joins KEV Catalog

In November 2025, CISA added CVE-2025-58034, a Fortinet FortiWeb OS Command Code Injection vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog following evidence of in-the-wild exploitation against internet-exposed FortiWeb appliances. Threat actors leveraged this critical flaw to execute arbitrary system commands remotely, enabling them to gain unauthorized access, pivot laterally, or deploy additional malware. The urgency was amplified by ongoing exploitation and a recently published Fortinet security advisory, prompting CISA to recommend an accelerated one-week remediation deadline for federal and enterprise environments. This incident exemplifies the continued targeting of web application infrastructure by attackers exploiting unpatched devices. The rapid exploitation timeline, coupled with directives like BOD 23-02, highlights the increasing regulatory focus and operational risk posed by known—but unremediated—vulnerabilities in public-facing systems.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Malicious npm Packages Leverage Adspect Cloaking to Fuel Crypto Supply Chain Scam (2024)
Impact· medium

Malicious npm Packages Leverage Adspect Cloaking to Fuel Crypto Supply Chain Scam (2024)

In early 2024, a sophisticated supply chain attack was uncovered involving a wave of malicious npm packages that abused Adspect cloaking techniques to avoid detection. Attackers published seemingly benign JavaScript libraries to the official npm registry. Once installed, these packages deployed malware via fake cryptocurrency-related sites, using cloaking to distinguish between legitimate victims and security researchers. The campaign allowed threat actors to evade automated scans, maximize the longevity of their malicious payloads, and target developers and end users with credential theft and crypto scams. This incident highlights the evolving threat landscape around open-source software supply chains. The use of advanced traffic cloaking and victim filtering marks a new escalation in attacker TTPs, forcing organizations to revisit how they vet third-party dependencies and monitor developer ecosystems for hidden threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
KongTuke 2025: Real-World Insights from a Fake CAPTCHA Malware Campaign
Impact· low

KongTuke 2025: Real-World Insights from a Fake CAPTCHA Malware Campaign

In November 2025, the KongTuke threat actor (also referenced as LandUpdate808 or TAG-124) orchestrated a malware campaign leveraging sophisticated Traffic Distribution System (TDS) techniques. The attackers compromised legitimate websites by injecting malicious scripts that displayed fake CAPTCHA pages designed to lure victims into executing clipboard-injected PowerShell commands. Once executed, these commands downloaded a ZIP archive containing a Windows-compatible Python environment and a malicious Python script, which established persistence via scheduled tasks and generated encrypted HTTPS traffic to external infrastructure. The infection sequence was confirmed within Active Directory environments, highlighting the attacker's ability to evade detection and automate persistence. This incident underscores an increasing trend in malware distribution leveraging trusted websites as initial access vectors, blending social engineering with technical innovation. Organizations should take note of the evolving sophistication in initial lure tactics and persistence mechanisms, as such approaches complicate traditional detection methods and pose substantial risk to enterprise endpoints.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
Fortinet’s Silent Patch Leaves FortiWeb Customers Exposed to Critical Exploit in 2024
Impact· low

Fortinet’s Silent Patch Leaves FortiWeb Customers Exposed to Critical Exploit in 2024

In October 2024, Fortinet faced significant criticism after a critical vulnerability (CVE-2025-64446) in its FortiWeb application firewall was exploited by attackers before the flaw was publicly disclosed or a CVE was assigned. Although a patch was silently released on October 28, public notification and technical details were delayed for over two weeks, leaving customers unaware of the immediate risk posed by the vulnerability. During this window, attackers leveraged a path-traversal bug to gain administrative command execution and persistent access, potentially compromising affected infrastructures and evading detection until after widespread exploitation was underway. This incident highlights the increasing risk that delayed vulnerability disclosures pose to organizations, as attackers can weaponize defects before defenders are informed. The event has intensified calls for timely vendor transparency and reinforced scrutiny from regulators as the cyber threat landscape evolves toward faster exploitation cycles and greater demands for coordinated defensive action.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
Microsoft Azure Faces Unprecedented 15 Tbps DDoS Attack Driven by Aisuru Botnet
Impact· high

Microsoft Azure Faces Unprecedented 15 Tbps DDoS Attack Driven by Aisuru Botnet

In June 2024, Microsoft revealed that its Azure cloud network was targeted by the Aisuru botnet in a record-breaking Distributed Denial-of-Service (DDoS) attack that peaked at 15.72 terabits per second. The attack leveraged over 500,000 globally distributed IP addresses to inundate Azure’s infrastructure, demonstrating sophisticated command and control and massive botnet scale. Microsoft successfully mitigated the assault, which represented the largest DDoS attack it had ever recorded, but the event highlighted the evolving threat landscape and ongoing attacker focus on major cloud service providers. The incident is highly relevant today as DDoS tactics grow in scale and complexity, frequently outpacing conventional network defenses. The use of enormous botnets like Aisuru and automated attack infrastructure underscores the urgent need for advanced mitigation, segmentation, and resilient cloud architectures across all industries.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Eurofiber France Data Breach 2024: Ticket System Compromise Exposes Customer Records
Impact· high

Eurofiber France Data Breach 2024: Ticket System Compromise Exposes Customer Records

In June 2024, Eurofiber France disclosed a significant data breach after its ticket management system was compromised by threat actors who exploited a vulnerability. The attackers gained unauthorized access to the ticketing platform, proceeding to exfiltrate customer data before attempting to sell it on an underground forum. The breach exposed personal and business information, prompting notification to affected clients and regulatory authorities, and forced Eurofiber to review and enhance its internal security measures. This incident highlights the persistent targeting of essential infrastructure vendors via vulnerable business applications, such as ticketing systems. It reflects the growing risks of data exfiltration and underground marketplaces, prompting renewed scrutiny on third-party software security and compliance requirements.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
Princeton University Data Breach Exposes Alumni and Donor Information
Impact· high

Princeton University Data Breach Exposes Alumni and Donor Information

On November 10, 2023, Princeton University experienced a significant data breach when unauthorized actors gained access to a university database containing sensitive information on alumni, donors, students, and faculty. The intrusion exposed personal details such as names, contact information, and donation records, with initial reports indicating the compromise originated from the university’s advancement and fundraising systems. Princeton moved quickly to secure impacted systems, notify affected individuals, and engage cybersecurity experts and law enforcement. The exposure raises concerns regarding the safeguarding of high-value personal and financial data held by educational institutions. This incident underscores the persistent threat higher education institutions face from cyberattacks targeting personal and philanthropic data. The Princeton breach highlights a surge in attacks exploiting third-party platforms and unencrypted internal data flows, aligning with broader trends toward increased ransomware and data extortion pressures observed throughout 2023.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports