Validated Containment Architectures are here. →Explore

Industry Category

Financial Services

Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.

3650 threat reports
Page 247 of 305

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Financial Services Threat Reports

Showing 29532964 / 3650 reports
GlassWorm: Malicious VS Code Extensions Trigger a New Wave of Supply-Chain Attacks
Impact· medium

GlassWorm: Malicious VS Code Extensions Trigger a New Wave of Supply-Chain Attacks

In late 2025, cybersecurity researchers discovered the 'GlassWorm' malware campaign actively targeting the Visual Studio Code (VS Code) ecosystem via three malicious extensions available on the official marketplace. With over 7,400 combined downloads, these extensions enabled threat actors to inject malware directly into developers' environments, facilitating credential theft, remote access, and potential downstream supply-chain attacks. Attackers leveraged trusted community tools as the entry vector, bypassing traditional perimeter defenses to gain a foothold in development workflows and potentially propagate malware throughout interconnected repositories. This incident underscores the rising prevalence of supply-chain attacks in the software development ecosystem and the unique risks posed by compromised IDE extensions. The popularity of VS Code amplifies the potential blast radius, highlighting an urgent need for improved extension vetting, granular access controls, and continuous threat monitoring within CI/CD pipelines.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
CISA Orders Emergency Patching After Samsung Zero-Day Exploited in LandFall Spyware Attacks
Impact· low

CISA Orders Emergency Patching After Samsung Zero-Day Exploited in LandFall Spyware Attacks

In June 2024, U.S. federal agencies were ordered by CISA to urgently patch a critical Samsung zero-day vulnerability (CVE-2023-21492) after evidence emerged of its exploitation in targeted attacks delivering LandFall spyware. The attackers leveraged the flaw, which enabled privilege escalation, to compromise Samsung Android devices of high-value targets via WhatsApp. Once exploited, the vulnerability allowed unauthorized actors to bypass security controls, deploy surveillance tools, and covertly exfiltrate sensitive communications and data from affected devices, potentially impacting agency operations and confidentiality. This incident highlights a growing trend of mobile zero-day exploitation linked to sophisticated surveillance operations targeting both governmental and private sector entities. The rapid response from CISA underlines the rising regulatory and operational urgency as attackers increasingly exploit unpatched endpoints and messaging platforms in tailored cyber-espionage campaigns.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
ClickFix Phishing Hits Hospitality: Hotel Credentials Compromised via PureRAT
Impact· medium

ClickFix Phishing Hits Hospitality: Hotel Credentials Compromised via PureRAT

In late 2025, the hospitality sector was targeted by a sophisticated, large-scale phishing campaign involving ClickFix-style lures that tricked hotel managers into revealing their credentials. Attackers leveraged compromised email accounts to distribute malicious links to numerous hotel establishments, leading victims to phishing sites that mimicked familiar workflow tools. Credential theft enabled deployment of PureRAT malware, which provided remote access to internal hotel systems and enabled lateral movement, resulting in compromised operations and data exposure for multiple organizations. This incident demonstrates the increasing use of advanced social engineering in credential-focused attacks against the hospitality industry. With phishing campaigns growing more convincing and commodity RATs like PureRAT widely available, organizations in high-turnover sectors face mounting risk from credential-based breaches and follow-on malware infections.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Quantum Route Redirect PhaaS: The 2024 Microsoft 365 Phishing Surge
Impact· low

Quantum Route Redirect PhaaS: The 2024 Microsoft 365 Phishing Surge

In 2024, cybersecurity researchers discovered that a Phishing-as-a-Service (PhaaS) platform named Quantum Route Redirect orchestrated a large-scale credential theft campaign targeting Microsoft 365 users globally. The threat actors leveraged a distributed network of roughly 1,000 malicious domains to automate phishing attacks and evade detection. Victims were lured through convincing emails, redirecting them seamlessly through multiple stages to capture login credentials. The campaign exploited the trust in corporate SaaS platforms, enabling attackers to compromise user identities, access sensitive business data, and potentially facilitate subsequent attacks across affected organizations. The incident highlighted widespread operational and reputational risks for enterprises relying on cloud collaboration platforms. This incident underscores the growing threat posed by PhaaS platforms, which are lowering the entry barrier for cybercriminals to launch sophisticated, scalable phishing campaigns. As email and identity-based attacks surge, organizations face urgent pressure to reinforce cloud security, strengthen user awareness, and adopt zero-trust frameworks to defend against evolving social engineering tactics.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(low)
Read Report
AI-Powered Malware & Hyper-V Exploits: The 2025 Multi-Vector Attack Recap
Impact· medium

AI-Powered Malware & Hyper-V Exploits: The 2025 Multi-Vector Attack Recap

In early November 2025, a series of sophisticated cyberattacks targeted enterprise and consumer systems worldwide, exploiting vulnerabilities in Hyper-V virtual machines, RDP protocols, and leveraging malicious AI bots. Attackers deployed stealthy malware within virtualized environments to evade detection, while advanced spyware campaigns targeted Android devices using side-channel techniques to capture sensitive AI chat data. Additionally, high-profile service disruptions, including a mass WhatsApp account lockdown, affected millions of users and raised concerns about systemic vulnerabilities and cross-platform exploitation. The threat actors behind these incidents demonstrated new levels of coordination and adaptability, with alliances between major cybercrime groups amplifying the scope and impact of the campaigns. This incident underscores an accelerating trend toward multi-vector, AI-enabled cybercrime and highlights the convergence of ransomware, lateral movement, and novel attack methods across cloud and hybrid infrastructures. Security leaders should anticipate further escalation in both the sophistication and frequency of such attacks through 2025, heightening urgency for layered defenses and zero trust strategies.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Triofox Flaw Exploited: How CVE-2025-12480 Enabled Remote Access Tool Attacks
Impact· medium

Triofox Flaw Exploited: How CVE-2025-12480 Enabled Remote Access Tool Attacks

In June 2025, cybersecurity researchers at Google's Mandiant Threat Defense uncovered active exploitation of a critical authentication bypass vulnerability (CVE-2025-12480, CVSS 9.1) affecting Gladinet's Triofox file-sharing and remote access platform. Attackers leveraged this n-day vulnerability—now patched—to gain unauthorized access to Triofox administrative configuration panels. With authentication circumvented, they uploaded and executed malicious payloads, specifically deploying remote access tools via the platform’s integrated antivirus feature. This enabled adversaries to establish persistent footholds, move laterally, and potentially exfiltrate sensitive corporate data and credentials. The incident underscores the ongoing urgency of patch management and monitoring, as threat actors continue to weaponize critical vulnerabilities within widely used collaboration and remote access tools. Industry experts warn of increasing attacks exploiting n-day vulnerabilities before patch adoption, reflecting a broader trend toward highly targeted lateral movement and remote tool deployment campaigns.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
CISA Flags Samsung Mobile Devices for Critical Exploited Vulnerability (CVE-2025-21042)
Impact· medium

CISA Flags Samsung Mobile Devices for Critical Exploited Vulnerability (CVE-2025-21042)

In November 2025, CISA added CVE-2025-21042, an out-of-bounds write vulnerability affecting Samsung Mobile Devices, to its Known Exploited Vulnerabilities (KEV) Catalog following active exploitation in the wild. Threat actors have leveraged this flaw to gain unauthorized control over affected devices, potentially allowing them to execute arbitrary code, escalate privileges, and compromise sensitive user data. The vulnerability poses significant risks to both federal agencies and commercial enterprises, prompting CISA to mandate remediation by federal civilian agencies under Binding Operational Directive (BOD) 22-01. Failure to remediate exposes organizations to data breaches and operational disruption. This incident highlights a broader wave of targeted exploits against widely used mobile platforms, illustrating attackers’ ongoing shift toward mobile devices as primary entry vectors. With regulatory attention intensifying, the urgency for rapid vulnerability management and proactive defense measures is escalated for all sectors.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
ClickFix Hospitality Breach: Infostealer Attack Impacts Hotels and Their Customers
Impact· medium

ClickFix Hospitality Breach: Infostealer Attack Impacts Hotels and Their Customers

In early 2024, a cybercrime campaign known as "ClickFix" targeted hospitality providers globally using infostealer and remote access trojan (RAT) malware. Threat actors gained initial access via spear phishing and malicious links, compromising hotel systems to harvest sensitive booking data and customer contact information. Attackers leveraged this stolen data to conduct highly convincing secondary phishing attacks directed at hotel customers via both email and WhatsApp channels, exposing guests to social engineering, fraud, and further credential theft. This cascading impact emphasized the attacker's focus on exploiting trusted relationships across business and customer environments. The incident is notable for its dual-target strategy, harnessing a single breach to fuel broader downstream attacks and demonstrating attackers' sophisticated use of layered social engineering. As infostealer activity surges across the hospitality and service sectors, defenders must adapt to increasingly persistent, multi-stage campaigns that pose risks for both enterprise operations and their customers.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
TEE.fail: 2025 Hardware Attack Cracks Latest Secure Enclaves
Impact· medium

TEE.fail: 2025 Hardware Attack Cracks Latest Secure Enclaves

In November 2025, researchers disclosed a critical hardware attack known as TEE.fail, which compromised secure enclaves (trusted execution environments or TEEs) across Intel, AMD, and ARM chips. By placing a small hardware device between a DDR5 memory chip and the motherboard, and leveraging kernel-level privileges, attackers were able to bypass the most advanced TEE protections including Confidential Compute, SEV-SNP, and TDX/SDX. Once exploited, these secure enclaves could no longer be trusted to protect sensitive data in-use, raising major concerns for cloud providers, enterprises, and users reliant on confidential computing. The attack’s low cost, simplicity, and applicability to modern hardware make it a significant development, reflecting growing sophistication in hardware-level threats. Regulatory scrutiny and industry attention have intensified as organizations reevaluate their trust assumptions and risk models for sensitive workloads.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
runC Vulnerabilities Threaten Container Security: Docker and Kubernetes Breach 2024
Impact· low

runC Vulnerabilities Threaten Container Security: Docker and Kubernetes Breach 2024

In June 2024, critical vulnerabilities (CVE-2024-21626, CVE-2024-21627, and CVE-2024-21628) were disclosed in the runC container runtime, which underpins Docker, Kubernetes, and many modern container platforms. These flaws could be exploited by attackers to break out of a container, bypassing isolation controls and gaining unauthorized access to the underlying host system. A successful exploit would allow lateral movement and potentially compromise entire cloud or on-premises environments. Prompt patching and risk assessment are essential, as proof-of-concept exploits have already been published in the wild. This incident underscores the increasing sophistication and focus of attackers on supply chain and containerization technologies, as organizations accelerate cloud and DevOps adoption. As regulatory expectations around zero trust and runtime controls intensify, keeping pace with container threat vectors is now mission-critical for enterprise security teams.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
GlassWorm Supply Chain Attack: Malicious VSCode Extensions Threaten Open Source Ecosystem
Impact· low

GlassWorm Supply Chain Attack: Malicious VSCode Extensions Threaten Open Source Ecosystem

In June 2024, the GlassWorm malware resurfaced in a significant supply chain attack on the OpenVSX and Visual Studio Code (VSCode) extension marketplaces. Threat actors uploaded three malicious extensions, which were collectively downloaded over 10,000 times before detection and removal. These extensions were designed to compromise developer environments by deploying malware capable of exfiltrating credentials and enabling persistent access. The attack leveraged trusted open-source ecosystems, making it difficult for end users and organizations to detect the compromise until indicators of compromise (IoCs) were published, potentially exposing sensitive data and intellectual property. This event underscores a broader rise in supply chain attacks targeting developer tools and open-source package ecosystems. The campaign highlights the urgent need for rigorous code vetting, extension auditing, and enhanced supply chain security controls as attackers increasingly exploit automated trust in widely used development platforms.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Microsoft's 'Whisper Leak' Side-Channel Attack Bypasses Encryption for AI Traffic
Impact· medium

Microsoft's 'Whisper Leak' Side-Channel Attack Bypasses Encryption for AI Traffic

In late 2025, Microsoft researchers uncovered the 'Whisper Leak' side-channel attack, a novel method allowing passive adversaries to deduce the topics of conversations with streaming AI language models despite the use of encrypted, high-performance network protocols. Attackers exploited traffic analysis techniques, observing packet timing and size patterns, to infer sensitive discussion details traversing enterprise VPNs and encrypted links. Although private circuit encryption such as MACsec and IPsec was in place, the attack effectively bypassed traditional data-in-transit security controls, raising concerns for sectors leveraging AI in sensitive communications. This incident is significant as it highlights an emerging risk where encrypted cloud AI traffic can be compromised via sophisticated traffic analysis, just as generative AI adoption is surging across regulated industries. It illustrates evolving attacker sophistication beyond classical exploits, prompting urgent review of AI data security and zero trust segmentation strategies.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports