Validated Containment Architectures are here. →Explore

Industry Category

Financial Services

Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.

3650 threat reports
Page 254 of 305

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Financial Services Threat Reports

Showing 30373048 / 3650 reports
Fake Solidity VSCode Extension Backdoors Developers in 2024 Supply Chain Attack
Impact· medium

Fake Solidity VSCode Extension Backdoors Developers in 2024 Supply Chain Attack

In early 2024, a malicious Visual Studio Code extension impersonating the popular Solidity plugin was discovered on the Open VSX Registry, a prominent open-source extension marketplace. The extension secretly installed the SleepyDuck remote access trojan. Threat actors leveraged an Ethereum smart contract to covertly communicate with infected developer environments, establishing a covert command and control channel. Dozens of unsuspecting developers who installed the fake extension were exposed to potential source code theft, workspace compromise, and broader supply chain risk for any software subsequently produced on affected systems. This incident highlights the escalating threat posed by supply chain attacks via open-source repositories and package registries, particularly those targeting development toolchains. Increasingly, attackers are exploiting trust in popular extensions, emphasizing the urgent need for organizations to bolster code integrity controls and enforce zero trust principles for their build environments.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Kimsuky Deploys HttpTroy Backdoor in Sophisticated VPN-Phishing Attack Against South Korea
Impact· low

Kimsuky Deploys HttpTroy Backdoor in Sophisticated VPN-Phishing Attack Against South Korea

In late 2025, the North Korean advanced persistent threat (APT) group Kimsuky launched a targeted cyberattack against an organization in South Korea using a previously undocumented backdoor dubbed 'HttpTroy.' Leveraging a spear-phishing email containing a malicious ZIP file disguised as a VPN invoice, the attackers tricked the recipient into extracting and running a disguised executable. Once executed, HttpTroy enabled encrypted communication with attacker-controlled infrastructure, allowing remote data exfiltration and persistent access. This covert operation underscored the group's ongoing focus on espionage, intelligence collection, and the use of custom malware to evade detection. This incident is significant due to the rise of spear-phishing attacks deploying novel backdoors and the persistence of state-sponsored threats targeting geopolitical rivals. It highlights the necessity for vigilant endpoint monitoring, advanced traffic analysis, and robust segmentation to limit attacker lateral movement and safeguard sensitive communications.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Lazarus Group Orchestrates Major 2025 Web3 Multi-Vector Breach
Impact· medium

Lazarus Group Orchestrates Major 2025 Web3 Multi-Vector Breach

In November 2025, the Lazarus Group executed a sophisticated multi-vector attack campaign targeting several high-profile Web3 and cryptocurrency organizations. Utilizing social engineering and supply-chain attacks, the threat actors exploited newly disclosed vulnerabilities in trusted hardware (including Intel and AMD TEEs) mere hours after public disclosures. Attackers employed encrypted C2 channels, lateral movement tools, and advanced ransomware, allowing them to bypass internal segmentation and traverse east-west across internal networks. The result was significant compromise of sensitive assets, encrypted backups, and leakage of confidential data, leading to operational disruption and reputational harm to victims. This incident is especially noteworthy due to the rapid attacker adaptation to zero-day vulnerabilities, the blending of traditional and cloud-native threat techniques, and Lazarus’s evolution in targeting decentralized platforms. The attack highlights the increasing complexity and urgency of defending distributed infrastructure against agile, persistent threat actors.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
BankBot-YNRK and DeliveryRAT: Sophisticated Android Trojans Targeting Financial Data
Impact· medium

BankBot-YNRK and DeliveryRAT: Sophisticated Android Trojans Targeting Financial Data

In November 2025, cybersecurity researchers discovered the active deployment of two advanced Android trojans, BankBot-YNRK and DeliveryRAT, targeting users across multiple financial and delivery service platforms. The trojans infiltrated devices primarily through deceptive apps and phishing schemes, with BankBot-YNRK leveraging anti-analysis techniques to evade detection by testing for emulated and virtualized environments before unleashing its data theft capabilities. DeliveryRAT, meanwhile, provided attackers with remote access for layered exploitation. Both malware families are capable of harvesting sensitive personal and financial data, making banking credentials and payment details accessible to threat actors, potentially leading to significant financial losses and privacy violations for affected users and organizations. This incident highlights the evolving sophistication of Android-targeted infostealers, which increasingly combine stealth, anti-analysis, and remote access tactics. The attack underscores the urgent need for organizations and end-users to enhance mobile threat defenses and rapidly adapt to emerging malware targeting the growing mobile financial ecosystem.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
2024 Mega Email Stealer Log Breach: Over 2 Billion Accounts Exposed
Impact· high

2024 Mega Email Stealer Log Breach: Over 2 Billion Accounts Exposed

In early June 2024, a large-scale data breach involving the exposure of over 2 billion email addresses was discovered in a massive stealer log dataset. Attackers compiled these emails through widespread info-stealer malware campaigns, collecting credentials and sensitive data from compromised systems and aggregating them into searchable logs accessible on illicit forums. The breach, prepared for public release after extensive validation and costly processing, highlights the sheer scale and complexity of modern info-theft operations. Affected users may face targeted phishing, credential stuffing attacks, and long-term privacy risks due to the availability of this data. This breach exemplifies the accelerating trend of industrialized data theft and commoditization of stolen information, especially as info-stealer malware campaigns proliferate and cybercriminals refine monetization methods. Organizations should be on heightened alert for downstream risks, including targeted attacks leveraging exposed data and regulatory scrutiny of data protection practices.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
SleepyDuck Supply Chain Attack: Malicious VSX Extension Exposes Developers via Ethereum C2
Impact· low

SleepyDuck Supply Chain Attack: Malicious VSX Extension Exposes Developers via Ethereum C2

In late October and early November 2025, cybersecurity researchers uncovered a malicious Visual Studio Code extension, 'juan-bianco.solidity-vlang', uploaded to the Open VSX registry. Originally benign, the extension was updated within days to include a remote access trojan called SleepyDuck, which leveraged Ethereum smart contracts to dynamically maintain connectivity with its command-and-control (C2) servers. By exploiting the trust inherent in open-source software supply chains and masquerading as a development tool, attackers enabled remote access and possible data exfiltration from developer environments, posing significant risks to organizations reliant on open-source packages. This breach highlights the persistent threat of supply chain attacks targeting developer tools and marketplaces, a rapidly growing vector as attackers seek to compromise software upstream. It also demonstrates the adoption of blockchain infrastructure for resilient, hard-to-takedown C2 mechanisms, forcing defenders to adapt to increasingly complex threat ecosystems.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Jabber Zeus Coder 'MrICQ' Arrested: Lessons from a Banking Trojan Empire
Impact· high

Jabber Zeus Coder 'MrICQ' Arrested: Lessons from a Banking Trojan Empire

In October 2025, U.S. authorities took into custody Yuriy Igorevich Rybtsov, known online as "MrICQ," a key developer for the infamous Jabber Zeus cybercrime group. The group, active between 2009 and 2013, leveraged a custom version of the ZeuS banking trojan to compromise small and mid-sized business accounts, bypass multi-factor authentication, and orchestrate elaborate money-laundering schemes across multiple countries. MrICQ's primary role involved monitoring real-time breaches, facilitating payroll fraud via money mules, and supporting the laundering of illicit gains through electronic exchanges. This arrest follows years of cross-border law enforcement collaboration, building upon indictments and intelligence from forensic chat intercepts and international extraditions. This case highlights the evolving tactics of financially motivated threat actors, especially their capacity to defeat strong authentication and automate large-scale financial theft. The longevity and operational sophistication demonstrated by groups like Jabber Zeus underscore persistent vulnerabilities in online banking and underscore the need for adaptive security controls across sectors.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
TruffleNet Attack Highlights Urgent AWS Cloud Credential Risks
Impact· medium

TruffleNet Attack Highlights Urgent AWS Cloud Credential Risks

In early 2024, a sophisticated campaign dubbed 'TruffleNet' leveraged stolen credentials to infiltrate Amazon Web Services (AWS) environments. Attackers, believed to leverage components of TruffleHog, obtained valid credentials via phishing and credential theft, bypassing weak controls to gain access to cloud accounts. Following initial compromise, the threat actors engaged in reconnaissance, lateral movement, and business email compromise (BEC) activities, exploiting privileges to move within the cloud infrastructure and exfiltrate sensitive data. The incident resulted in significant risk of data loss and operational disruption for affected organizations, highlighting the dangers of identity-based attacks in cloud environments. This attack reflects an escalating trend of attackers targeting cloud platforms through abused credentials and automated open-source tooling. Organizations face increased regulatory scrutiny and operational risk, underscoring the critical need for zero trust segmentation, strong identity controls, and real-time monitoring of cloud platforms.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
WSUS CVE-2025-59287: Mass Scanning and Rapid Exploitation Threaten IT Infrastructure
Impact· low

WSUS CVE-2025-59287: Mass Scanning and Rapid Exploitation Threaten IT Infrastructure

In late October and early November 2025, security researchers observed a marked uptick in external scans targeting ports 8530/TCP and 8531/TCP, which are related to Microsoft Windows Server Update Services (WSUS). These scans were linked to the rapid exploitation of CVE-2025-59287, a critical vulnerability allowing remote attackers to execute unauthorized scripts on vulnerable WSUS servers. Threat actors leveraged both encrypted (TLS) and unencrypted channels, beginning with reconnaissance sweeps and quickly escalating to full network compromise of exposed endpoints. Given the public availability of exploit details and the speed of attacks, organizations with exposed WSUS servers have likely suffered unauthorized access or larger breaches. This incident highlights a surge in opportunistic exploitation of newly disclosed vulnerabilities, particularly affecting critical IT infrastructure. The level of automated scanning and rapid weaponization is emblematic of a broader trend: attackers systematically hunting for internet-exposed administration interfaces and supply-chain services, increasing regulatory and operational risks for enterprises.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
University of Pennsylvania Breach Exposes 1.2 Million Donor Records in 2024
Impact· high

University of Pennsylvania Breach Exposes 1.2 Million Donor Records in 2024

In June 2024, a hacker claimed responsibility for breaching the University of Pennsylvania, exposing sensitive information on approximately 1.2 million donors as well as internal documentation. The threat actor infiltrated the university's IT environment, potentially exploiting weaknesses in data encryption and network segmentation. The attack resulted in the unauthorized access and potential leak of donor personal details, which could include names, contact information, and possibly financial data. The incident became publicly known after a 'We got hacked' email was sent from university channels, alerting stakeholders to the scale of the compromise. This incident highlights the increasing prevalence of large-scale data breaches targeting higher education and non-profit institutions. As threat actors employ more advanced techniques to exploit internal network gaps, organizations face mounting regulatory pressure to strengthen defenses and prevent sensitive data exposure.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Open VSX Access Token Leak Triggers 2024 Supply-Chain Security Incident
Impact· medium

Open VSX Access Token Leak Triggers 2024 Supply-Chain Security Incident

In early June 2024, the Open VSX Registry—a key open-source repository for Visual Studio Code extensions—rotated its access tokens after developers inadvertently leaked credentials in public repositories. This exposure enabled unauthorized actors to publish malicious extensions, triggering a supply-chain attack that could have allowed widespread compromise of downstream developers and end users. Upon discovery, Open VSX revoked and replaced the affected tokens, advised pruning of potentially impacted extensions, and began audits to assess the scope of any malicious uploads. While swift action was taken, the incident highlighted ongoing risks associated with leaked credentials in public codebases and the challenges of securing distributed developer ecosystems. This supply-chain breach is highly relevant amid a surge in attacks abusing public software repositories and developer credentials. As threat actors increasingly target development tooling and code packages, organizations face rising pressure to enhance security around code signing, credential management, and extension vetting to reduce systemic software supply-chain risk.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(medium)
Read Report
China-Linked Bronze Butler Exploits Lanscope Zero-Day for Cyber-Espionage in 2024
Impact· medium

China-Linked Bronze Butler Exploits Lanscope Zero-Day for Cyber-Espionage in 2024

In early 2024, China-linked APT group Bronze Butler (also known as Tick) exploited an undisclosed zero-day vulnerability in Motex Lanscope Endpoint Manager to deploy an upgraded version of its Gokcpdoor malware. The attackers leveraged this flaw to gain initial access and establish persistent footholds in targeted organizations, primarily for cyber-espionage purposes. Security researchers confirmed that the intrusion campaigns targeted East Asian entities and potentially exfiltrated sensitive data before the vulnerability was publicly disclosed and patched. The attack underscores the evolving sophistication of state-sponsored actors in weaponizing software supply chain vulnerabilities for stealthy intrusion. This incident exemplifies a broader surge in zero-day exploitation by nation-state actors, as well as a growing focus on endpoint management software as an attack vector. It highlights the urgent need for organizations to patch promptly, monitor lateral network traffic, and implement defense-in-depth strategies that reduce dwell time and lateral movement opportunities.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports