Validated Containment Architectures are here. →Explore

Industry Category

Financial Services

Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.

3666 threat reports
Page 271 of 306

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Financial Services Threat Reports

Showing 32413252 / 3666 reports
Malicious OAuth Apps in Microsoft 365: A 2025 Cloud Identity Wake-Up Call
Impact· medium

Malicious OAuth Apps in Microsoft 365: A 2025 Cloud Identity Wake-Up Call

In October 2025, security researchers discovered widespread abuse of OAuth applications within Microsoft 365 environments, exposing tenants to covert identity compromise. Threat actors leveraged both legitimate and custom-built ("traitorware" and "stealthware") OAuth apps to establish persistent, unauthorized access by obtaining illicit consent to sensitive permissions, often evading detection for years. The incident, analyzed across 8,000+ organizations, revealed that nearly 10% had malicious or risky apps, often due to default configurations allowing broad consent and weak app governance, resulting in increased risk of credential theft, data exposure, and lateral movement. This incident underscores the growing threat of cloud identity attacks exploiting trusted cloud-native mechanisms like OAuth. As organizations accelerate Microsoft 365 adoption and attackers pivot to persistent, stealthy access models, regular auditing of app permissions and stronger identity threat detection become urgent priorities for reducing cloud risk.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Microsoft Windows Smart Card Authentication Breakdowns After 2025 Security Update
Impact· low

Microsoft Windows Smart Card Authentication Breakdowns After 2025 Security Update

In October 2025, Microsoft released security updates to address a cryptographic vulnerability (CVE-2024-30098) in Windows platforms, triggering widespread smart card authentication failures. The update, which altered default behavior from using CSP to KSP for RSA-based smart card certificates, disrupted authentication services across Windows 10, Windows 11, and Windows Server systems. Affected organizations reported issues such as failed logins, inability to sign documents, and critical service interruptions in workflows dependent on certificate-based authentication. The root cause was traced to a registry change designed to mitigate a feature bypass risk, inadvertently impacting legacy compatibility and 32-bit applications. This incident highlights how routine security hardening can introduce substantial operational risk, particularly for enterprises relying on legacy authentication methods. As businesses continue their path to zero trust and increase dependency on certificate-based systems, compatibility breakdowns following security improvements are becoming more prominent, amplifying pressures for comprehensive testing and rapid response strategies.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
GlassWorm Supply Chain Malware: VS Code & OpenVSX Infected in 2025
Impact· medium

GlassWorm Supply Chain Malware: VS Code & OpenVSX Infected in 2025

In October 2025, a highly sophisticated supply chain attack involving the GlassWorm malware targeted developers via the OpenVSX and Microsoft Visual Studio Code (VS Code) extension marketplaces. Malicious actors inserted invisible Unicode characters into multiple popular extensions, enabling self-spreading malware to infect users without detection during automatic updates. GlassWorm stole credentials for developer services and cryptocurrency wallets, established remote access, and transformed compromised workstations into nodes within a broader criminal infrastructure. The malware leveraged blockchain (Solana) transactions, Google Calendar events, and distributed Peer-to-Peer protocols for resilient command-and-control, impacting at least 35,800 installations and keeping several malicious extensions available before remediation. This incident highlights the growing threat of self-propagating malware in software supply chains, especially via extension ecosystems critical to development workflows. Its combination of advanced evasion tactics, automated propagation, and leveraging of decentralized infrastructure sets a new precedent, signaling broader risks for organizations relying on trusted code repositories and accelerating regulatory and industry scrutiny on supply chain security.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
CVE-2025-33073: Windows SMB Zero-Day Highlights Risks of Privilege Escalation and Patch Gaps
Impact· low

CVE-2025-33073: Windows SMB Zero-Day Highlights Risks of Privilege Escalation and Patch Gaps

In October 2025, threat actors began actively exploiting a high-severity privilege escalation vulnerability (CVE-2025-33073) in Windows SMB services, affecting Windows 10, Windows 11 (up to 24H2), and all supported Windows Server releases. The flaw, caused by improper access control in SMB, allows attackers to gain SYSTEM-level privileges by tricking victims into connecting to a malicious SMB server via a crafted script or application. With proof-of-concept details publicly available before Microsoft’s June 2025 patch, threat actors rapidly weaponized the exploit, prompting emergency guidance from CISA for federal agencies and warnings for all organizations to remediate immediately. This incident highlights renewed attacker focus on privilege escalation vectors and supply chain weaknesses in ubiquitous network protocols. The rapid exploitation window, following public disclosure but prior to broad patch deployment, underlines the need for continuous vulnerability management, robust segmentation, and vigilant detection of lateral movement.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
Over 75,000 WatchGuard Firebox VPN Devices Vulnerable to Critical RCE Flaw
Impact· low

Over 75,000 WatchGuard Firebox VPN Devices Vulnerable to Critical RCE Flaw

In October 2025, a critical remote code execution (RCE) vulnerability, CVE-2025-9242, was disclosed in WatchGuard Firebox network security appliances. Nearly 76,000 public-facing Firebox devices worldwide are exposed, primarily in the United States and Europe. The flaw resides in the Fireware OS 'iked' process, which handles IKEv2 VPN negotiations. Attackers can exploit the vulnerability without authentication by sending specially crafted IKEv2 packets, leading to out-of-bounds memory writes and potentially full device compromise. WatchGuard has issued patches, but thousands remain unprotected, as many affected devices run versions that are end-of-life or unpatched. This incident underscores a continuing trend of attackers targeting network infrastructure with VPN-centric vulnerabilities, particularly impacting organizations reliant on legacy or unpatched systems. The rise of critical edge device exploits heightens urgency for patching and proactive segmentation, especially as regulatory scrutiny around infrastructure security tightens.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
Qantas 2024 Data Breach: Legal Orders Fail, Security Controls Critical
Impact· medium

Qantas 2024 Data Breach: Legal Orders Fail, Security Controls Critical

In early 2024, Qantas Airways experienced a significant data breach when cybercriminals exfiltrated sensitive passenger and employee information. Despite an Australian court issuing an injunction to prevent the distribution of stolen data, the responsible threat actors ignored the legal order and leaked the compromised datasets on the dark web. The breach was confirmed by multiple data breach notification services. Attackers leveraged unencrypted traffic vulnerabilities and lateral movement inside Qantas systems, bypassing internal controls and highlighting deficiencies in east-west traffic security and zero trust segmentation. Business operations faced regulatory pressure, reputational damage, and potential compliance issues. This incident underscores the difficulties organizations face in containing modern breaches, especially as legal measures alone cannot halt the distribution or misuse of exposed data. The continued release and trade of stolen datasets emphasize the importance of proactive technical controls and the need for robust, automated detection and data governance in line with evolving compliance standards.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Linux Fileless Malware in 2024: Syscall(memfd_create) Unlocks New Attack Vectors
Impact· high

Linux Fileless Malware in 2024: Syscall(memfd_create) Unlocks New Attack Vectors

In October 2024, security researchers discovered a new Linux-targeting fileless malware that exploits Python and the direct use of syscalls—specifically 'memfd_create'—to execute payloads entirely in memory, bypassing traditional disk-based detection. The attack begins with a Python dropper embedding a base64-encoded ELF binary, which is loaded directly into memory using syscall(319), then executes file encryption using a simple 1-byte XOR key. While the second stage payload is rudimentary and appears to be a proof-of-concept, the methodology demonstrates how easily threat actors can evade filesystem-based controls and endpoint security tools on Linux systems. The incident underscores an increasing trend in fileless malware and direct syscall manipulation, especially on Linux servers and cloud workloads. These advanced tactics make traditional detection and prevention approaches less effective, urging organizations to adopt stronger memory and process monitoring, inline threat detection, and zero-trust segmentation to mitigate similar threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(high)
Read Report
Agentic AI's OODA Loop Vulnerability: Prompt Injection & Architecture Risks in 2025
Impact· high

Agentic AI's OODA Loop Vulnerability: Prompt Injection & Architecture Risks in 2025

In October 2025, a major vulnerability was revealed in agentic AI systems’ OODA (Observe, Orient, Decide, Act) decision loops, where adversaries exploited prompt injection, training data poisoning, and tool protocol confusion to compromise autonomous AI agents. Attackers planted triggers and malicious instructions in web-accessible content and tool descriptions, which were ingested by AI models, bypassing privilege separation and contaminating operational state and chat history. The incident resulted in persistent data leaks, unintentional tool actions, and the propagation of backdoors and compromised context across organizations deploying AI-driven automation and analytics. This exposure underscores a critical and growing risk: as organizations adopt increasingly autonomous AI, vulnerabilities related to data integrity, input trust, and OODA loop manipulation have escalated. Recent trends show surges in prompt injection exploits, AI-powered toolchain attacks, and regulatory focus on AI integrity controls, highlighting an urgent need for architectural reforms and robust zero trust measures.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Fake Homebrew and LogMeIn Sites Spread Infostealer Malware via Google Ads in 2025
Impact· medium

Fake Homebrew and LogMeIn Sites Spread Infostealer Malware via Google Ads in 2025

In October 2025, a sophisticated malvertising campaign exploited Google Ads to distribute infostealing malware via fake Homebrew, LogMeIn, and TradingView websites targeting macOS users and developers. The threat actors registered over 85 convincing domains and lured victims to enter terminal commands that downloaded malware such as AMOS (Atomic macOS Stealer) and Odyssey Stealer. Once executed, these payloads bypassed security controls, harvested browser credentials, cryptocurrency wallets, and sensitive files, and forwarded the stolen data to threat actor-controlled servers. This campaign underscores the effectiveness of ClickFix social engineering techniques and highlights the risks of trust in search advertising. The incident is particularly relevant as infostealer malware continues to evolve with new tactics, including sophisticated social engineering, supply chain targeting, and persistent access capabilities. Organizations face increasing pressure to defend against rapidly shifting malware delivery channels and enforce user education to reduce the likelihood of compromise.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Europol Takedown of SIMCARTEL: SIM Box Fraud Network Disrupted
Impact· high

Europol Takedown of SIMCARTEL: SIM Box Fraud Network Disrupted

In October 2024, Europol led a coordinated international operation to dismantle a sophisticated cybercrime syndicate known as "SIMCARTEL". This network, spanning Austria, Estonia, and Latvia, leveraged over 1,200 SIM box devices and 40,000 active SIM cards to conduct large-scale phishing, credential theft, and financial fraud across more than 3,200 recorded cases. Authorities linked the group to $5.8 million in financial losses, the creation of 49 million fraudulent accounts, and infrastructure facilitating criminal services in over 80 countries. The takedown resulted in seven arrests, seizure of servers, SIMs, websites, luxury vehicles, and the freezing of suspect assets. This incident highlights the growing global threat posed by SIM farms and SIM box networks, which enable scammers to evade detection, commit diverse types of fraud, and undermine trust in online communications. The rapid adoption of similar tactics worldwide puts financial institutions, telecoms, and consumers increasingly at risk.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Sotheby’s 2025 Data Breach: Employee Financial Data Compromised
Impact· high

Sotheby’s 2025 Data Breach: Employee Financial Data Compromised

In July 2025, Sotheby's, the renowned international auction house, identified a significant cybersecurity breach in which an unknown threat actor exfiltrated sensitive employee information, including full names, Social Security numbers, and financial account details. The breach was discovered on July 24, 2025, and an internal investigation with data protection experts and law enforcement extended over two months to confirm the nature and scope of compromised data. Sotheby’s responded by notifying impacted employees and offering a year of free identity protection and credit monitoring services. No ransomware group claimed responsibility, and the number of affected individuals remains undisclosed. This incident underscores ongoing risks facing financial and high-value service sectors, especially from sophisticated attacks targeting personnel data for monetization and fraud. Organizations with sensitive employee or client financial data must act promptly as regulatory scrutiny tightens and attacks on high-net-worth entities continue to escalate.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
F5 Supply Chain Breach 2025: China-Linked Attack Exposes Global BIG-IP Risk
Impact· low

F5 Supply Chain Breach 2025: China-Linked Attack Exposes Global BIG-IP Risk

In October 2025, F5 Networks disclosed a major cybersecurity incident involving a China-linked nation-state group (UNC5291) that gained unauthorized access to its infrastructure. Attackers reportedly maintained covert access for at least a year, stealing F5 BIG-IP source code and information on as-yet-undisclosed vulnerabilities. While F5 stated there’s no evidence of active exploitation of these flaws, the breach affects more than 266,000 exposed BIG-IP instances worldwide. The attackers leveraged advanced persistence techniques and deployed specialized malware, raising serious concerns about global supply chain integrity. This breach highlights the persistent targeting of critical infrastructure vendors by highly resourced nation-state actors. Government agencies and enterprises face heightened urgency as regulatory bodies issue emergency directives to patch devices, with compliance and operational risks elevated by the scale and sophistication of the attack.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports