Validated Containment Architectures are here. →Explore

Industry Category

Financial Services

Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.

3650 threat reports
Page 244 of 305

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Financial Services Threat Reports

Showing 29172928 / 3650 reports
SmartApeSG Leverages ClickFix Fake CAPTCHA Pages to Spread NetSupport RAT (2024)
Impact· medium

SmartApeSG Leverages ClickFix Fake CAPTCHA Pages to Spread NetSupport RAT (2024)

In November 2024, the SmartApeSG campaign shifted tactics by leveraging ClickFix-style fake CAPTCHA pages to deliver the NetSupport RAT, a powerful remote access trojan. Threat actors compromised websites by injecting malicious scripts that, under specific conditions, displayed convincing 'verify you are human' prompts. Unsuspecting users, influenced by the fraudulent CAPTCHA, executed clipboard-injected commands that downloaded and ran NetSupport RAT on their Windows systems, establishing persistent access via Start Menu shortcuts. The campaign was notable for its adaptation and the regular rotation of malicious infrastructure. This incident highlights a rising trend of social engineering combined with hands-on-keyboard malware delivery. The use of fake CAPTCHA solutions is proliferating, making traditional email-filter and endpoint controls less effective. Organizations should be aware of evolving attack chains and regularly review user education programs to counter these sophisticated lures.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Breakdown: 2024 FormBook Infostealer Delivered via Multi-Stage Script Obfuscation
Impact· high

Breakdown: 2024 FormBook Infostealer Delivered via Multi-Stage Script Obfuscation

In November 2024, a sophisticated email campaign delivered the FormBook infostealer via a series of obfuscated scripts. Attackers distributed malicious ZIP email attachments containing an obfuscated VBS file, which initiated multiple layers of PowerShell-based deobfuscation and payload retrieval. The staged infection successfully bypassed standard detection tools by employing complex anti-analysis techniques, eventually injecting FormBook into a legitimate process and establishing command and control through a remote server. Impacts included potential credential theft, session hijacking, and risk of lateral movement within affected organizations. This incident highlights the increasing use of multi-stage script-based delivery vectors and advanced obfuscation in commodity malware campaigns. Detection challenges are heightened as attackers combine legacy script formats and cloud hosting services to evade conventional endpoint security controls and deliver persistent infostealing payloads.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Google Takes Legal Aim at Lighthouse Smishing Syndicate in 2024
Impact· high

Google Takes Legal Aim at Lighthouse Smishing Syndicate in 2024

In June 2024, Google initiated a civil lawsuit targeting the perpetrators of the 'Lighthouse' phishing-as-a-service operation, believed to be managed by individuals based in China. These actors used large-scale SMS phishing (smishing) campaigns, often spoofing Google and other trusted brands, to lure victims into divulging personal and financial information by clicking fraudulent links. Over a short period, the attackers deployed hundreds of thousands of fake sites and reportedly victimized more than one million people worldwide, resulting in significant financial losses and the compromise of millions of payment cards—primarily in the United States. The group’s abuse of Google’s trademarks also led the company to seek legal and technical disruption measures, including the removal of malicious domains. This case illustrates the growing impact and reach of phishing-as-a-service kits, which democratize sophisticated techniques for broader criminal use. The prevalence of smishing, coupled with international threat actor networks, reinforces the need for proactive legal and technical responses, as well as multi-stakeholder legislative and public awareness initiatives.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Amazon Detects APT Group Exploiting Cisco & Citrix Zero-Days in 2024
Impact· medium

Amazon Detects APT Group Exploiting Cisco & Citrix Zero-Days in 2024

In summer 2024, Amazon’s threat intelligence team identified that an advanced persistent threat (APT) group exploited zero-day vulnerabilities in Cisco Identity Services Engine (CVE-2025-20337) and Citrix NetScaler (CVE-2025-5777), months before official patches were released. The attackers leveraged custom malware with advanced evasion capabilities, demonstrating a deep understanding of enterprise Java and network edge products. Exploitation was detected as early as May, prior to vendor disclosure, allowing the threat actor prolonged access to target environments for likely espionage purposes. Massive exploitation attempts followed public disclosure, impacting thousands of organizations globally. This incident underscores the increased speed and sophistication with which threat groups are identifying and weaponizing zero-day vulnerabilities in critical network and identity infrastructure. The trend poses escalating risks for organizations relying on edge devices, making timely patching and layered defenses more crucial than ever.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Operation Endgame 2024: Global Law Enforcement Strikes Down Major Malware Networks
Impact· medium

Operation Endgame 2024: Global Law Enforcement Strikes Down Major Malware Networks

In November 2024, a coalition of law enforcement agencies from 11 countries coordinated Operation Endgame, a major crackdown disrupting some of the most prolific malware networks globally. The operation targeted Rhadamanthys infostealer, VenomRAT remote access trojan, and the Elysium botnet—malware that collectively infected hundreds of thousands of computers and enabled the theft of millions of credentials. Authorities arrested the principal VenomRAT suspect in Greece, searched 11 sites across Europe, and dismantled more than 1,000 criminal servers and 20 illicit domains. With assistance from 30-plus cybersecurity companies, the operation also notified thousands of victims and exposed users of these illicit services, mitigating ongoing criminal campaigns. Operation Endgame underscores the rapidly evolving, cross-border nature of malware infrastructure and the growing need for coordinated responses by both public and private sectors. As attackers innovate and leverage distributed networks to evade law enforcement, regular collaborative enforcement actions and heightened detection capability are now critical to cybersecurity defenses worldwide.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Rhadamanthys Infostealer Brought Down: Lessons from a Major Malware Disruption
Impact· high

Rhadamanthys Infostealer Brought Down: Lessons from a Major Malware Disruption

In June 2024, law enforcement and security vendors successfully disrupted the Rhadamanthys infostealer operation, a prominent 'malware-as-a-service' offering used by cybercriminals to harvest sensitive data from infected devices. The takedown resulted in many malware operators reporting loss of access to their command-and-control servers, crippling active campaigns and rendering stolen data inaccessible. This disruption impacted both the malware's customers and the broader illicit ecosystem that depended on Rhadamanthys for credential theft, data exfiltration, and distribution of stolen information for financial gain. The incident highlights growing law enforcement coordination targeting infostealer infrastructure and criminal-as-a-service marketplaces. As infostealers proliferate with new evasion methods, their disruption remains a critical priority for organizations and defenders seeking to reduce exposure to credential theft and secondary breaches.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Citrix & Cisco Face 2025 Zero-Day Onslaught: Custom Malware Targets Network Cores
Impact· low

Citrix & Cisco Face 2025 Zero-Day Onslaught: Custom Malware Targets Network Cores

In early 2025, a sophisticated threat actor leveraged zero-day vulnerabilities—CVE-2025-5777 ('Citrix Bleed 2') in NetScaler ADC/Gateway and CVE-2025-20337 in Cisco Identity Services Engine (ISE)—to gain initial access into targeted enterprise environments. Exploiting these flaws before vendor patches were available, attackers deployed custom malware to establish persistent command-and-control and facilitate lateral movement, affecting sensitive east-west and outbound network traffic. The advanced nature of this attack enabled the evasion of traditional security controls, resulting in unauthorized access to confidential data and business operations disruptions. This breach highlights a critical evolution in adversary tradecraft: coordinated and simultaneous exploitation of zero-day flaws in widely deployed network infrastructure. With threat actors increasingly chaining vulnerabilities to maximize impact, proactive threat detection and effective segmentation are more essential than ever for organizations seeking resilience against such rapid exploitation campaigns.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
DanaBot Returns: Windows Banking Trojan Resurges After Global Takedown
Impact· medium

DanaBot Returns: Windows Banking Trojan Resurges After Global Takedown

In early 2024, the notorious DanaBot banking Trojan resurfaced after a six-month hiatus following major international law enforcement crackdowns under Operation Endgame in May 2023. This new version targets Windows systems through phishing campaigns, using malicious email attachments to gain initial access. Once deployed, DanaBot leverages modular capabilities for credential theft, lateral movement, and potential data exfiltration, threatening organizations and individuals with financial losses and malware proliferation. The resurgence highlights the continuously evolving tactics of threat actors in the financial malware ecosystem despite decisive takedown efforts. DanaBot's return signals the persistent threat posed by adaptive malware campaigns, with attackers quickly retooling to evade detection and capitalize on lapses in endpoint security. This incident stresses the importance of modern inbound threat detection measures and rapid response to evolving banking malware tactics.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Google Sues to Dismantle Chinese 'Lighthouse' Phishing Platform Orchestrating US Toll Scams
Impact· medium

Google Sues to Dismantle Chinese 'Lighthouse' Phishing Platform Orchestrating US Toll Scams

In June 2024, Google filed a lawsuit to dismantle the 'Lighthouse' phishing-as-a-service (PhaaS) platform operated out of China. Lighthouse enabled global cybercriminals to launch large-scale SMS phishing campaigns, targeting U.S. residents by impersonating the U.S. Postal Service and E-ZPass toll systems. Attackers used automated infrastructure to send convincing text messages, directing victims to fraudulent sites designed to steal credit card and personal information. The campaign resulted in substantial financial losses for consumers and posed major operational risks to U.S. businesses and government agencies. This incident underscores the growing sophistication and accessibility of phishing-as-a-service offerings. With such turnkey solutions readily available on the dark web, attackers are able to scale campaigns with minimal technical skill, escalating both the frequency and severity of credential theft and fraud worldwide.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Amazon Discovers Zero-Day Exploits Targeting Cisco and Citrix Appliances
Impact· low

Amazon Discovers Zero-Day Exploits Targeting Cisco and Citrix Appliances

In October 2025, Amazon's threat intelligence division uncovered an advanced cyberattack that targeted undisclosed zero-day vulnerabilities in Cisco Identity Services Engine (ISE) and Citrix NetScaler ADC appliances. The attackers leveraged these flaws to gain privileged access within victim environments, deploying tailor-made malware to compromise critical identity and network infrastructure. By exploiting trusted network appliances, the threat actor bypassed conventional perimeter security, enabled persistent lateral movement, and threatened both operational continuity and data confidentiality for affected organizations. This incident underscores a growing shift in attacker tactics, with a strategic focus on exploiting zero-days in widely deployed network infrastructure. It highlights rising concerns about supply chain risks, the increasing sophistication of threat actors, and an urgent need for proactive detection and patch management across enterprise environments.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Critical Infrastructure Active Directory Breach Highlights the Need for Zero Trust Controls
Impact· medium

Critical Infrastructure Active Directory Breach Highlights the Need for Zero Trust Controls

In October 2025, a coordinated threat campaign targeted the Active Directory environment of a major North American critical infrastructure provider. Attackers exploited vulnerabilities in legacy on-premises and misconfigured cloud authentication bridges to gain initial access, leveraging unencrypted internal traffic and credential harvesting tools. By establishing persistence inside hybrid systems, they used lateral movement techniques to escalate privileges, eventually exfiltrating sensitive operational and personal data. The attack briefly disrupted authentication services, causing operational outages and impacting supply chain partners reliant on secure access. Regulators and cyber response teams were engaged, intensifying scrutiny of infrastructure identity security. This incident underscores how attackers increasingly target hybrid and cloud-integrated identity platforms like Active Directory, exploiting gaps in east-west traffic security and multifactor enforcement. As ransomware and nation-state campaigns leverage similar methods, the urgency for zero trust segmentation, encrypted traffic, and strong policy enforcement within hybrid infrastructure has never been greater.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Inside Google’s 2025 Crackdown on the Lighthouse Phishing Platform
Impact· low

Inside Google’s 2025 Crackdown on the Lighthouse Phishing Platform

In November 2025, Google filed a landmark lawsuit in the U.S. District Court for the Southern District of New York, targeting a group of China-based threat actors operating the Lighthouse Phishing-as-a-Service (PhaaS) platform. Lighthouse enabled massive SMS phishing attacks, leveraging trusted brands such as E-ZPass and USPS to lure victims. The operation compromised more than 1 million users across 120 countries by automating credential theft at scale, enabling untraceable criminal campaigns, and facilitating both lateral movement and data exfiltration. The attackers' infrastructure capitalized on encrypted traffic obfuscation and rapid brand impersonation techniques. This lawsuit marks a significant escalation in technology companies' pursuit of legal remedies against sophisticated cybercriminal ecosystems. It underscores the rising threat of PhaaS platforms enabling non-technical actors, the rapid proliferation of phishing kits, and the urgent need for zero trust and multi-layered defenses in digital infrastructure.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports