Validated Containment Architectures are here. →Explore

Industry Category

Financial Services

Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.

3650 threat reports
Page 262 of 305

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Financial Services Threat Reports

Showing 31333144 / 3650 reports
SessionReaper in the Wild: How a 2025 Adobe Commerce Flaw Fueled E-Commerce Breaches
Impact· medium

SessionReaper in the Wild: How a 2025 Adobe Commerce Flaw Fueled E-Commerce Breaches

In early 2025, a critical security vulnerability (CVE-2025-54236) was discovered in Adobe Commerce, formerly known as Magento. This flaw, actively exploited in the wild as 'SessionReaper,' enables remote attackers to hijack user sessions on e-commerce sites, bypassing authentication controls. Attackers leveraged this weakness to compromise sensitive customer data, manipulate transactions, and disrupt online sales operations for affected merchants. The exploitation led to significant financial and reputational risks, prompting rapid incident response and emergency patching. This incident highlights the growing trend of sophisticated web application attacks targeting popular e-commerce platforms. As threat actors increasingly weaponize session hijacking techniques and exploit critical flaws pre-patch, organizations must prioritize timely vulnerability management and layered defenses to protect customer trust and regulatory compliance.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
2024 Android Infostealer Attack: How Termux and Telegram Fueled Stealthy Mobile Data Breaches
Impact· medium

2024 Android Infostealer Attack: How Termux and Telegram Fueled Stealthy Mobile Data Breaches

In October 2024, researchers identified a novel Android infostealer undetected by antivirus engines, leveraging Termux—a legitimate terminal emulator app—to collect sensitive data from mobile devices. The attacker deployed a Python-based stealer designed to extract user contacts, SMS, call logs, location data, and app-specific files, including those for Facebook, WhatsApp, and banking. Exfiltration occurred via Telegram API integration, and a persistent backdoor was installed for continued access. The operation showcased clever abuse of legitimate utilities, with initial device compromise mechanics still unclear, though social engineering leading to the installation of Termux is likely. This incident highlights the evolving landscape in which infostealers now aggressively target mobile platforms as device usage and data stored on them surge. With sophisticated yet undetectable malware exploiting legitimate tools and APIs, organizations and users face heightened risks from threats previously confined mostly to Windows environments.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Salt Typhoon’s 2024 Attack: Nation-State Espionage Exploits Forgotten Network Devices
Impact· high

Salt Typhoon’s 2024 Attack: Nation-State Espionage Exploits Forgotten Network Devices

In early 2024, a cyber espionage campaign orchestrated by the China-linked Salt Typhoon group targeted forgotten and unpatched network perimeter devices, such as out-of-support routers, VPNs, and firewalls, across both public and private sector organizations in the U.S. and allied nations. Adversaries leveraged advanced "living off the land" tactics, establishing persistent access by exploiting technical debt and overlooked legacy hardware—bypassing hardened endpoint defenses and moving laterally within affected networks. Operational impacts included exposure of sensitive credentials, long-term surveillance risks, and significant challenges in incident detection and response due to the stealthy nature of the attacks. This incident highlights a surge in sophisticated nation-state threats adapting to improved endpoint security by targeting unmanaged infrastructure. The campaign underscores the urgency for organizations to reassess asset inventories, prioritize decommissioning of end-of-life devices, and deploy proactive detection strategies, as similar tactics are increasingly observed across multiple state-sponsored and ransomware actors.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Atlas & Comet AI Sidebar Spoofing: How Attackers Are Hijacking Trust in Browser AI
Impact· low

Atlas & Comet AI Sidebar Spoofing: How Attackers Are Hijacking Trust in Browser AI

In early June 2024, security researchers identified a novel application security vulnerability affecting OpenAI’s Atlas and Perplexity’s Comet browsers. Attackers leveraged spoofed AI sidebars to present malicious, AI-generated instructions that duped users into actions compromising security, such as running unverified commands or visiting phishing sites. The attack method bypassed traditional endpoint defenses by exploiting inherent trust in AI-powered browser features. Though no widespread exploitation has been confirmed, proof-of-concept demonstrations exposed a significant risk of credential theft, data leakage, or lateral movement within enterprise environments. The rapid adoption of AI assistants made this vector both timely and dangerous. This incident highlights the growing trend of attackers targeting AI-powered productivity tools by manipulating contextual interfaces. Rising adoption of AI chatbots and browser plugins increases the threat surface, demanding urgent reevaluation of security controls and staff awareness. Regulatory scrutiny of AI and application security is expected to accelerate in response.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
CISA Sounds Alarm: Lanscope Endpoint Manager Flaw Actively Exploited
Impact· low

CISA Sounds Alarm: Lanscope Endpoint Manager Flaw Actively Exploited

In June 2024, the Cybersecurity and Infrastructure Security Agency (CISA) warned organizations of active exploitation of a critical vulnerability in Motex’s Lanscope Endpoint Manager software. Threat actors leveraged the flaw (tracked as CVE-2024-27956) to gain unauthorized access and potentially execute remote code on unpatched systems. The attackers could bypass authentication and gain administrative privileges, enabling lateral movement and further compromise of affected network environments. The incident impacted enterprises using Lanscope Endpoint Manager for device monitoring and management, raising concerns over exposure of sensitive data and operational disruption. This incident is notable for its speed of exploitation following public disclosure, illustrating the ongoing trend of threat actors rapidly weaponizing software vulnerabilities in endpoint management tools. The breach underscores the importance of immediate patching and rigorous monitoring as attackers increasingly target IT infrastructure software to establish initial footholds.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
Toys "R" Us Canada Faces Customer Data Leak in 2024 Breach
Impact· high

Toys "R" Us Canada Faces Customer Data Leak in 2024 Breach

In late April 2024, Toys "R" Us Canada disclosed a data breach after threat actors exfiltrated and subsequently leaked customer records from its systems. The breach was confirmed via direct customer notifications, revealing that sensitive customer data—including names and contact details—was stolen and made public on a hacker forum. The company identified the security incident after discovering that attackers had gained unauthorized access and were able to access certain internal systems, leading to the data leak. Following the discovery, Toys "R" Us Canada initiated an investigation and notified the affected individuals, emphasizing that payment information was not compromised. This incident highlights a continued trend of cybercriminals targeting retail and e-commerce sectors for customer data theft and exposure. The breach exemplifies the increasing frequency of attacks leveraging stolen credentials or vulnerable infrastructure, underlining the urgent need for robust data protection and threat monitoring strategies across all consumer-facing organizations.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
CISA Confirms Critical Lanscope Endpoint Manager Vulnerability Under Active Attack
Impact· medium

CISA Confirms Critical Lanscope Endpoint Manager Vulnerability Under Active Attack

In October 2025, a critical vulnerability (CVE-2025-61932, CVSS 9.3) in Motex Lanscope Endpoint Manager was added to CISA’s Known Exploited Vulnerabilities catalog after confirmed active exploitation in the wild. Attackers leveraged the on-premises endpoint management platform’s remote code execution flaw to obtain unauthorized access, enabling lateral movement and potential data exfiltration. Organizations relying on Lanscope Endpoint Manager may face business disruption, data integrity issues, and heightened regulatory scrutiny as a result of this exposure. The recent exploitation of this vulnerability underscores a larger trend of remote code execution exploits targeting widely deployed endpoint management products. With attackers increasingly seeking supply-chain and IT management footholds, regulatory bodies and security leaders are prioritizing rapid patch cycles and robust segmentation to limit risk.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Jingle Thief: How Hackers Exploited Cloud to Steal Millions in Retail Gift Cards (2025)
Impact· medium

Jingle Thief: How Hackers Exploited Cloud to Steal Millions in Retail Gift Cards (2025)

In October 2025, a cybercriminal group known as Jingle Thief orchestrated a sophisticated financial fraud campaign targeting retail and consumer services organizations operating in cloud environments. Leveraging phishing and smishing tactics to obtain employee credentials, the attackers gained access to cloud-based systems responsible for managing digital gift card issuance. Once inside, they exploited weak east-west traffic controls and lack of adequate segmentation to move laterally and automate gift card theft at scale, resulting in losses worth millions of dollars and significant operational disruption to affected businesses. This incident highlights an ongoing escalation in targeted cloud infrastructure attacks, especially towards retail functions involving financial assets like digital gift cards. The use of cloud-native attack vectors and credential phishing underscores the urgency for enhanced zero trust practices, robust detection controls, and strict policy enforcement to protect sensitive assets in distributed environments.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
It Only Takes 250 Documents to Poison Any Large Language Model – Security Implications for 2024
Impact· high

It Only Takes 250 Documents to Poison Any Large Language Model – Security Implications for 2024

In 2024, cybersecurity researchers demonstrated that the integrity of large language models (LLMs) can be severely compromised with as few as 250 poisoned documents strategically inserted into their training data. By covertly introducing manipulated or malicious content into public data sources, attackers can alter a model’s understanding, bias its outputs, or degrade its reliability. This proof-of-concept highlights that ‘data poisoning’ attacks require minimal input yet pose substantial risk for AI reliability, potentially opening the door for misinformation, backdoors, or loss of operational trust across industries leveraging AI. Organizations relying on LLMs for critical tasks face a heightened threat of silent, hard-to-detect breaches affecting their core AI deployments. The urgency around AI/ML supply chain security has intensified, as threat actors and researchers increasingly explore the feasibility of data poisoning. Regulatory frameworks and industry best practices now emphasize the need for data provenance controls and continuous integrity monitoring of training pipelines.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
The 2024 Global Smishing Deluge: China-Based SMS Phishing at Scale
Impact· medium

The 2024 Global Smishing Deluge: China-Based SMS Phishing at Scale

In early 2024, a China-based threat group orchestrated a massive global smishing campaign, flooding mobile devices across multiple continents with fraudulent SMS messages impersonating banks, government agencies, and delivery services. Leveraging a rapidly-evolving attack ecosystem, the actors utilized wide-scale automation and regional tailoring to bypass spam filters and trick users into revealing sensitive credentials or installing malware. The attack’s magnitude caught many organizations off guard, resulting in significant credential theft, unauthorized transactions, and growing operational strain as firms raced to block fast-moving SMS domains and educate affected users. This campaign signals a sharp escalation in the sophistication and reach of smishing attacks, highlighting persistent gaps in mobile security awareness and detection. As similar TTPs gain traction among organized threat groups, critical infrastructure and commercial service providers face increased risks of large-scale credential exposure and downstream fraud.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
F5 2025 Supply-Chain Breach: Nation-State Attackers Target Update Infrastructure
Impact· medium

F5 2025 Supply-Chain Breach: Nation-State Attackers Target Update Infrastructure

In October 2025, F5 Networks—an industry-leading provider of enterprise networking and security appliances—disclosed a sophisticated supply-chain breach attributed to a nation-state threat actor. Attackers maintained long-term, covert access to F5’s internal environment, ultimately compromising systems responsible for building and distributing software updates for its widely deployed BIG-IP products. The breach allowed unauthorized access to proprietary source code, documentation of unpatched vulnerabilities, and a trove of sensitive customer configuration data, significantly enlarging the risks of downstream exploitation for thousands of major enterprises and critical infrastructure providers globally. This incident underscores the growing threat of highly persistent, technically advanced supply-chain attacks targeting the software build and delivery processes of core technology vendors. The breach reflects recent escalation in nation-state tactics and highlights the continued exposure of global businesses to supply-chain and software update system threats.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
F5 Vulnerability Exposes Visibility Gaps in DHS’s CDM Program
Impact· low

F5 Vulnerability Exposes Visibility Gaps in DHS’s CDM Program

In June 2024, a critical vulnerability affecting F5 devices exposed a major blind spot within the Department of Homeland Security's Continuous Diagnostics and Mitigation (CDM) program, which is tasked with overseeing federal cybersecurity assets. The Cybersecurity and Infrastructure Security Agency (CISA) was forced to issue an emergency directive after learning that a nation-state actor had exploited F5 edge devices to gain persistent access across multiple civilian federal agencies. The directive revealed that while thousands of F5 systems were in use, there was significant uncertainty about their location due to gaps in federal asset inventory capabilities, particularly for internet-facing edge devices like F5 BIG-IP load balancers. As a result, agencies had to scramble to manually identify and secure affected systems, highlighting the operational impact of incomplete visibility and asset management. The incident underscores the growing risks associated with network edge devices, which have become prime targets for sophisticated attackers exploiting gaps outside traditional IT inventories. As cloud adoption and edge architectures proliferate, ensuring asset visibility and securing non-traditional endpoints have become urgent priorities for government and private sector organizations alike, as attackers increasingly exploit these visibility gaps.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports