Validated Containment Architectures are here. →Explore

Industry Category

Financial Services

Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.

3665 threat reports
Page 267 of 306

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Financial Services Threat Reports

Showing 31933204 / 3665 reports
Scattered LAPSUS$ Hunters Target Encrypted Traffic in 2024 Hybrid Cloud Breach
Impact· medium

Scattered LAPSUS$ Hunters Target Encrypted Traffic in 2024 Hybrid Cloud Breach

In early 2024, the cybercrime group Scattered LAPSUS$ Hunters was observed launching a series of attacks targeting high-performance encrypted traffic between enterprise environments. Leveraging advanced tactics such as packet sniffing and lateral movement across hybrid and multicloud networks, the group exploited weak internal segmentation and gaps in east-west traffic controls. The attackers circumvented some organizations’ use of line-rate encryption by targeting less-protected internal flows and using sophisticated threat detection evasion techniques. Operational impacts included service disruptions, potential data exfiltration, and compromised cloud environments. This incident underscores the evolution of cybercrime actors as they adopt more advanced methods to breach environments assumed to be protected by conventional encryption or traditional network segmentation. The trend highlights growing risks for enterprises relying on hybrid and multicloud infrastructure, and illustrates the urgent need for zero trust approaches and enhanced east-west traffic security.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Jingle Thief: A 2024 Look at Cloud Gift Card Fraud in Retail
Impact· medium

Jingle Thief: A 2024 Look at Cloud Gift Card Fraud in Retail

In early 2024, security researchers uncovered "Jingle Thief," a sophisticated cybercriminal campaign targeting major retail organizations through coordinated phishing and smishing attacks. The attackers leveraged credential harvesting to gain unauthorized, persistent access to enterprise cloud environments and exploited multicloud weaknesses to orchestrate large-scale, automated gift card fraud. This activity resulted in the theft of significant monetary value from targeted retailers and demonstrated the evolving tactics of financially motivated threat groups seeking to exploit cloud infrastructure and weak east-west security controls. Jingle Thief underscores an alarming trend: attackers increasingly exploit cloud misconfigurations and multifactor authentication gaps to maintain post-compromise access for extended periods. The campaign exemplifies the need for enterprises to adopt Zero Trust strategies and rigorous east-west segmentation as criminals shift focus toward cloud-native targets.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Remote Code Execution Flaw in Abandoned Rust Library Exposes Global Supply Chain
Impact· medium

Remote Code Execution Flaw in Abandoned Rust Library Exposes Global Supply Chain

In August 2024, Edera researchers discovered CVE-2025-62518, a high-severity remote code execution vulnerability in the abandoned async-tar library for the Rust programming language. This logic flaw, named "TARmageddon," was unwittingly propagated to millions of users through downstream forks like tokio-tar and widely used build tools such as uv and testcontainers. The systemic risk arises because the vulnerability was replicated across a deep lineage of forks, making it very difficult to detect and patch comprehensively. Exploitation allows attackers to achieve remote code execution by overwriting files via malicious tar archives—a threat amplified by the lack of direct visibility into indirect dependencies in modern supply chains. The incident is especially impactful as it highlights the persistent risks of open-source abandonware and insufficient maintenance of foundational software libraries. It underscores growing industry focus on supply-chain security, indirect dependency management, and the need for rapid, coordinated vulnerability disclosure and remediation.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Velociraptor Misused: LockBit Ransomware & Storm-2603 Weaponize DFIR Tools in 2025 Attacks
Impact· high

Velociraptor Misused: LockBit Ransomware & Storm-2603 Weaponize DFIR Tools in 2025 Attacks

In October 2025, cybersecurity researchers uncovered that threat actors associated with Storm-2603 (also known as Gold Salem or CL-CRI-1040) leveraged Velociraptor, a legitimate open-source digital forensics and incident response (DFIR) tool, to facilitate a series of LockBit ransomware attacks. Adversaries exploited Velociraptor’s capabilities to gather intelligence and move laterally within target environments, evading detection by blending in with regular security operations. The attacks led to significant data encryption events and operational disruptions, primarily impacting organizations with insufficient internal security segmentation and monitoring. This incident marks a significant evolution in attacker tradecraft, as it demonstrates that widely trusted security tools—often present for defensive use—can be repurposed as offensive weapons. Increased regulatory scrutiny and the recurrent rise of double extortion ransomware attacks highlight the urgent need for organizations to monitor tool usage and improve east-west visibility.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
SonicWall VPN Breach 2025: Over 100 Customer Accounts Compromised via Stolen Credentials
Impact· low

SonicWall VPN Breach 2025: Over 100 Customer Accounts Compromised via Stolen Credentials

In October 2025, a widespread compromise targeted SonicWall SSL VPN devices, enabling attackers to gain unauthorized access to at least 100 customer accounts across various organizations. Security firm Huntress noted that threat actors rapidly authenticated using valid credentials on multiple devices, suggesting credential theft or data leaks rather than brute-force attacks. Attackers leveraged VPN access to infiltrate corporate environments, enabling lateral movement and potentially exfiltrating sensitive data. This campaign demonstrates the heightened risk posed by stolen credentials, especially when VPN infrastructure is directly exposed to the internet. This incident is highly relevant as credential-focused attacks and VPN compromises continue to surge, exploiting weaknesses in remote access systems. The event underscores the urgent need for zero trust strategies and stronger authentication measures to defend against evolved attacker tactics targeting perimeter defenses.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Oracle E-Business Suite Hit by Critical Unauthenticated Data Exposure Vulnerability
Impact· low

Oracle E-Business Suite Hit by Critical Unauthenticated Data Exposure Vulnerability

In October 2025, Oracle disclosed a high-severity vulnerability (CVE-2025-61884) affecting E-Business Suite versions 12.2.3 through 12.2.14. This flaw allows unauthenticated attackers to access sensitive data without login, leveraging a network-exploitable bug rated CVSS 7.5. Organizations running impacted Oracle EBS versions are at risk of data compromise, business disruption, and regulatory exposure if left unpatched. Oracle issued a security alert and urgent patch to address the issue as exploitation attempts in the wild are anticipated. This disclosure underscores the growing trend of unauthenticated, remote data access flaws targeting ERP platforms. Critical business applications present attractive targets for threat actors, especially as organizations expand interconnectivity. Prompt detection and segmentation of east-west traffic remain essential as ERP vulnerabilities increasingly underpin large-scale, compliance-relevant breaches.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
ChaosBot Unleashed: Rust-Based Malware Breach Leverages Discord and Stolen Credentials
Impact· medium

ChaosBot Unleashed: Rust-Based Malware Breach Leverages Discord and Stolen Credentials

In October 2025, security researchers identified a targeted cyberattack involving a new Rust-based backdoor known as ChaosBot. The threat actors initially leveraged compromised credentials associated with both a Cisco VPN account and an over-privileged Active Directory service account, enabling them to gain stealthy remote access to victims’ environments. Once inside, ChaosBot connected to adversary-controlled Discord channels for command-and-control and allowed attackers to perform reconnaissance, execute arbitrary commands, and potentially move laterally through affected networks. The incident underscores attackers' increasing reliance on credential abuse, novel malware written in memory-safe languages, and abuse of popular cloud-based collaboration tools for C2, ultimately increasing the risk of data exfiltration and operational disruption for enterprises reliant on hybrid identity and VPN solutions. This incident exemplifies the growing threat of multi-vector identity compromise combined with cloud and modern malware tradecraft. Its emergence highlights the urgent need for organizations to adopt zero trust access controls, enforce strict privilege management, and monitor for suspicious activity across both cloud and on-premises assets.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Astaroth Banking Trojan Leverages GitHub to Evade Takedowns in 2025
Impact· medium

Astaroth Banking Trojan Leverages GitHub to Evade Takedowns in 2025

In October 2025, cybersecurity researchers uncovered a sophisticated campaign distributing the Astaroth banking trojan, which leveraged GitHub repositories as its primary command-and-control infrastructure. By shifting away from traditional, easily dismantled C2 servers, attackers used public code-hosting platforms to deploy configuration files and payloads. Targeted endpoints were infected through phishing campaigns, after which Astaroth would harvest credentials and financial data undetected. The integration with GitHub provided attackers increased operational resilience, making takedown efforts by defenders and law enforcement more challenging. Financial institutions and users experienced notable disruptions and heightened risk of unauthorized account activity due to these stealthy techniques. This incident highlights a growing trend of threat actors abusing legitimate platforms for illicit operations, undermining trust in cloud services. Organizations must reassess controls and detection strategies as adversaries increasingly exploit mainstream tools and shift to fileless, cloud-hosted malware models.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Microsoft Shuts Down IE Mode After Zero-Day Exploit Exposes Legacy Risks
Impact· low

Microsoft Shuts Down IE Mode After Zero-Day Exploit Exposes Legacy Risks

In August 2025, Microsoft responded to credible reports that unknown threat actors exploited Internet Explorer (IE) mode in the Edge browser. Attackers used a combination of unpatched (zero-day) JavaScript vulnerabilities and basic social engineering to compromise legacy IE mode, which allowed unauthorized access to Windows devices. The exploitation leveraged backward compatibility for legacy web apps, serving as an entry point for attackers to install persistent backdoors and potentially exfiltrate sensitive data. Microsoft swiftly revamped and locked down IE mode to prevent further abuse, minimizing ongoing risk and alerting organizations reliant on legacy web technologies. This incident underscores the persistent risks of maintaining backward compatibility for legacy browser features. As attackers increasingly target older components embedded within modern platforms, organizations face new urgency to accelerate deprecation plans and strengthen zero trust security controls.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
RondoDox Botnet 2025: Mass Exploitation Sheds Light on Multi-Vendor Security Gaps
Impact· high

RondoDox Botnet 2025: Mass Exploitation Sheds Light on Multi-Vendor Security Gaps

In October 2025, security researchers uncovered a major campaign involving the RondoDox botnet, which rapidly weaponized over 50 vulnerabilities across more than 30 device vendors. The attack leveraged an "exploit shotgun" approach, targeting a vast range of internet-facing infrastructure including routers, DVRs, NVRs, CCTV systems, and web servers. Threat actors behind RondoDox employed automated scanning and exploitation, compromising vulnerable devices at scale for botnet expansion, distributed denial-of-service (DDoS) attacks, and potential further malicious activity. The operational impact included service degradation, widespread risk of breach propagation, and the exposure of inadequately secured assets across diverse environments. This incident highlights a surging trend in large-scale, opportunistic exploitation—where attackers rapidly integrate newly disclosed vulnerabilities into botnet tools. The scale and automation reflect the growing sophistication of threat actors, amplifying risks for businesses lagging in patch management and segmentation. Regulatory scrutiny is intensifying as such campaigns threaten critical infrastructure and data security.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
2025 Mega-Breach: WhatsApp Worm & Oracle 0-Day Power Ransomware Cartel Campaign
Impact· medium

2025 Mega-Breach: WhatsApp Worm & Oracle 0-Day Power Ransomware Cartel Campaign

In October 2025, a sophisticated international cybercriminal cartel launched a coordinated multi-vector campaign targeting organizations worldwide. The attackers leveraged a newly discovered zero-day vulnerability in Oracle middleware, chaining it with several critical CVEs and a rapidly spreading WhatsApp worm. Lateral movement was facilitated via unprotected east-west traffic and credential theft, allowing rapid compromise of hybrid cloud environments and on-premises resources. The impact included ransomware deployment, data exfiltration, and significant operational disruptions across sectors such as finance, healthcare, and technology. This incident highlights the unsettling trend of threat actors collaboratively exploiting multiple weaknesses—including unpatched systems, misconfigurations, and trusted collaboration tools—to bypass traditional defenses. The convergence of wormable malware, supply chain vulnerabilities, and ransomware-as-a-service underscores the necessity for adaptive security and real-time threat detection.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
TA585’s MonsterV2: Unveiling 2025’s Next-Gen Phishing Infostealer Threat
Impact· medium

TA585’s MonsterV2: Unveiling 2025’s Next-Gen Phishing Infostealer Threat

In October 2025, cybersecurity researchers uncovered new activities by the previously undocumented threat actor TA585, which was observed conducting sophisticated phishing attacks to deliver the MonsterV2 infostealer malware. The group leveraged advanced tactics, including web injections and traffic filtering, to evade detection and ensure payload delivery. Once deployed, MonsterV2 enabled TA585 to harvest sensitive information and credentials, posing significant risks to organizational data integrity and confidentiality. The attack chains exploited weaknesses in email security and endpoint controls, demonstrating a concerning evolution in social engineering and malware delivery. This incident highlights the growing prevalence of stealthy infostealer campaigns targeting enterprises across multiple sectors. It underscores the urgent need for organizations to reevaluate network segmentation, multi-cloud visibility, and anomaly detection strategies to counter increasingly capable threat actors and align with evolving compliance standards.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports