✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
Officials Dismantle Major Southeast Asia Cybercrime Network in $15B Bitcoin Seizure
In early 2024, federal authorities from the U.S. and U.K. conducted a large-scale operation against Southeast Asia cybercrime networks, seizing 127,271 Bitcoins worth approximately $15 billion from Chen Zhi, the alleged head of the Prince Group based in Cambodia. The Prince Group, operating since 2015, is accused of running transnational scam compounds utilizing human trafficking and forced labor to enact wide-reaching financial fraud across over 30 countries, including the U.S. where a Brooklyn network victimized more than 250 individuals. The operation resulted in sanctions on 146 people and organizations, the severing of Huione Group from the U.S. financial system, and the dismantling of 117 illicit Prince Group-affiliated businesses. This record-breaking crackdown underscores the severity and international scale of cyber-enabled financial fraud, money laundering, and the role of organized crime groups leveraging technology across borders. The incident highlights growing regulatory and enforcement focus, as well as the evolving threat posed by sophisticated scam and laundering operations exploiting multi-region financial networks.
6 months ago
Kill Chain
Microsoft Patch Tuesday: October 2025 Brings Critical Zero-Day Exploits
In October 2025, Microsoft disclosed and patched 175 vulnerabilities affecting its major products, marking the year's largest vulnerability release from the company. Notably, two zero-day vulnerabilities (CVE-2025-24990 in the Agere Windows Modem Driver and CVE-2025-59230 in Windows Remote Access Connection Manager) were discovered to be actively exploited in the wild. Attackers leveraging these flaws could elevate privileges, potentially gaining administrative or system-level access across all supported Windows versions. Microsoft acted promptly, removing the vulnerable modem driver and providing fixes for the Remote Access Connection Manager, with the U.S. Cybersecurity and Infrastructure Security Agency adding both zero-days to its known exploited catalog. This incident underscores the persistent threat posed by zero-day exploits and highlights the increasing rate at which attackers are targeting system-level services and third-party drivers. The surge of high-severity vulnerabilities, along with rapid exploitation, demonstrates the need for organizations to strengthen vulnerability and privilege management programs to respond to modern attack trends.
6 months ago
Kill Chain
F5 2024 Breach: Nation-State Attack Highlights Supply Chain Risks
In June 2024, F5—a leading provider of application security and delivery products—disclosed a sophisticated cyberattack attributed to a nation-state actor. The breach was first discovered on August 9, 2023, and involved unauthorized, prolonged access to F5’s BIG-IP product development environment and its internal engineering knowledge platform. Although the attackers exfiltrated files containing segments of BIG-IP source code and limited customer configuration details, external forensic reviews confirmed no tampering with F5’s supply chain processes or build systems. No customer-facing platforms, including NGINX and Distributed Cloud Services, were affected, and the company found no evidence of critical vulnerabilities or malicious code insertion. This incident is particularly important due to increasing nation-state supply chain attacks targeting core infrastructure vendors. It highlights growing risks to software development environments and the potential cascade effects on enterprise and government clients dependent on widely used technologies.
6 months ago
Kill Chain
Framework’s 2025 Secure Boot Bypass: How Signed UEFI Debug Tools Created a Supply-Chain Crisis
In October 2025, firmware security researchers revealed a supply-chain vulnerability affecting nearly 200,000 Framework Linux laptops, caused by the inclusion of signed UEFI shells with the powerful 'mm' (memory modify) command. This legitimate but dangerous command, intended for hardware debugging, could be used by attackers with local or physical access to bypass Secure Boot by overwriting memory critical to the boot process—disabling signature verification and enabling the loading of bootkits like BlackLotus or HybridPetya. The issue was not the result of an external compromise but a manufacturing oversight, impacting several Framework 13 and Framework 16 models, with firmware updates and mitigation guidance swiftly issued. This vulnerability highlights a growing risk in hardware supply-chain security, where trusted vendor-signed components can inadvertently enable sophisticated attacks that persist even after OS reinstalls. As attackers increasingly target firmware and boot processes, the incident underscores the urgency for robust device-level and manufacturing-time security controls.
6 months ago
Kill Chain
Oracle EBS Zero-Day: How ShinyHunters and Clop Launched 2025's Most Notorious Data Extortion Attacks
In October 2025, Oracle silently released out-of-band patches for a critical zero-day vulnerability (CVE-2025-61884) in its E-Business Suite, following active exploitation by the ShinyHunters extortion group. The flaw allowed attackers to perform unauthenticated Server-Side Request Forgery (SSRF) and potentially remote code execution, leading to unauthorized access and data theft from affected servers. Clop ransomware actors also launched parallel extortion campaigns targeting Oracle EBS customers, leveraging separate yet related zero-day vulnerabilities to steal sensitive corporate data and demand ransom payments. Multiple exploits and proofs-of-concept were shared publicly, increasing organizational risk and pressure for rapid patching. This incident underscores the growing sophistication and collaboration among ransomware and extortion groups exploiting enterprise zero-day vulnerabilities for data theft and financial gain. The release and weaponization of public exploits highlight a rising trend of supply chain risk and the urgent need for continuous vulnerability management, proactive patching strategies, and advanced east-west traffic controls.
6 months ago
Kill Chain
US Seizes $15B in Crypto from Global 'Pig Butchering' Syndicate
In October 2025, the U.S. Department of Justice seized $15 billion in bitcoin from the leader of the Prince Group, a transnational criminal organization responsible for orchestrating large-scale cryptocurrency investment scams, widely known as 'pig butchering.' Operating from Cambodia since 2015, Prince Group exploited social media, dating apps, and messaging platforms to lure victims into fraudulent investment schemes, funneling billions via complex laundering tactics and a vast network of shell companies in over 30 countries. The syndicate trafficked and forced thousands into labor-intensive scam compounds, evading law enforcement and leveraging bribery, automated call centers, and violence. The stolen funds were laundered and spent on luxury assets and high-value goods. The Prince Group incident underscores the escalating threat of organized cyber-enabled financial fraud, particularly those leveraging cryptocurrency to obfuscate illicit gains. Despite large-scale law enforcement crackdowns, similar tactics—ranging from romance baiting to advanced obfuscation—have proliferated globally, highlighting persistent regulatory and security challenges for fintech and law enforcement agencies.
6 months ago
Kill Chain
Microsoft October 2025 Patch Tuesday: Six Zero-Days and 172 Vulnerabilities Addressed
In October 2025, Microsoft released security patches addressing 172 vulnerabilities across its product suite, including six actively-exploited zero-day flaws. These vulnerabilities exposed users to potential remote code execution, privilege escalation, and data leakage risks. The zero-days were exploited prior to patch release, affecting Windows, Office, and other core services. Security researchers and threat intelligence teams observed active exploitation in the wild, prompting urgent patching and incident response from enterprises globally. Microsoft’s rapid disclosure and remediation response helped to mitigate further threat actor activity and contain the immediate risk. The significance of this Patch Tuesday lies not only in the sheer number of vulnerabilities and zero-days but also in the increasing prevalence of opportunistic and targeted attacks against widely-used software. Organizations are under heightened pressure to maintain timely patch cycles, given growing regulatory scrutiny and sophisticated attacker TTPs.
6 months ago
Kill Chain
Pixnapping: The 2025 Android Vulnerability Stealing MFA Codes Pixel by Pixel
In October 2025, researchers unveiled a new Android vulnerability called 'Pixnapping,' enabling malicious applications with zero special permissions to exfiltrate sensitive screen data—such as multi-factor authentication (MFA) codes, chat messages, and emails—pixel by pixel via a GPU-based side-channel attack. The attack exploits the way Android's SurfaceFlinger composes app windows and leverages a graphics compression side-channel (GPU.zip) to reconstruct sensitive on-screen information. Pixnapping affects modern and fully patched Android 13–16 devices from Google and Samsung, and researchers demonstrated that 2FA codes could be exfiltrated in under 30 seconds, while more extensive data (such as chat logs) could be compromised within hours. Although Google attempted a patch in September, an effective fix is only expected in the December 2025 Android update, with GPU vendors yet to announce mitigation plans. This incident underscores a growing trend in side-channel and screen-based attacks, reflecting how even trusted software stacks and hardware abstraction layers can be used to bypass isolation. The Pixnapping method exposes the gaps in mobile OS zero-trust models—and with rising adoption of MFA and privacy-driven apps, the risk to enterprises and consumers is heightened.
6 months ago
Kill Chain
Malicious VSCode Extensions: TigerJack’s 2025 Supply Chain Attack on OpenVSX
In October 2025, the threat actor known as TigerJack resurfaced with a sophisticated supply chain attack targeting developer environments by publishing malicious Visual Studio Code (VSCode) extensions to both the official marketplace and the OpenVSX registry. Despite removal from the VSCode marketplace after 17,000 downloads, the extensions remained accessible on OpenVSX and continued to proliferate through renamed and republished versions. These extensions exfiltrated source code, ran unauthorized cryptocurrency miners, and enabled arbitrary remote code execution, greatly increasing the risk to individual developers and organizations relying on open-source tools. This incident highlights a rising trend of supply chain attacks targeting developer tools and open-source ecosystems, where trust in community-maintained registries is frequently exploited. With minimal oversight and delayed response from registry maintainers, businesses face a persistent risk of compromise through their software development pipelines.
6 months ago
Kill Chain
Windows 10 End-of-Support: Patch Tuesday Signals Urgent Lifecycle Risk in 2025
In October 2025, Microsoft released KB5066791, the final mandatory Patch Tuesday update for Windows 10 as the operating system officially reached end-of-support status. This update addressed six zero-day vulnerabilities and 172 additional flaws. With free support and security updates discontinued, only customers enrolled in extended security updates (ESUs) are eligible for further patches. The shift leaves millions of endpoints—including in enterprise and consumer environments—potentially vulnerable to emerging threats targeting unpatched or unsupported Windows 10 systems as threat actors historically target end-of-life platforms for exploitation. The update also modified components like the Azure validation chain and removed outdated drivers, signaling a definitive end to mainstream security support. This event is particularly significant due to the accelerated exploitation trends observed following previous Microsoft OS end-of-life events. Attackers rapidly pivot to leverage newly found or previously unreported vulnerabilities, resulting in heightened lateral movement and potential compliance risks. Organizations must act swiftly to upgrade, implement segmentation, and enhance detection capabilities to avoid becoming easy targets.
6 months ago
Kill Chain
How Hacktivists Used Hashtags and DDoS to Disrupt in 2025
In early 2025, a surge in global hacktivist operations was observed, coordinated primarily via Telegram and X (formerly Twitter), with attackers leveraging hashtags to claim credit, issue threats, and organize campaigns. Over 120 hacktivist groups, originating in the MENA region but targeting organizations worldwide—including government, finance, and critical infrastructure—conducted highly visible DDoS attacks. These operations favored impact and propaganda over technical sophistication, resulting in significant service disruptions and reputational challenges for numerous victims, with attack announcements and proof frequently disseminated in near real-time. The campaign reflects a broader shift toward open, social-media-driven hacktivist tactics that often transcend regional geopolitics. As DDoS tools become more accessible and social platforms amplify coordination, all organizations—regardless of direct involvement in conflicts—face increased risk from ideologically motivated cyberattacks.
6 months ago
Kill Chain
Windows 11 Recall: New AI Feature Raises Alarming Data Security Concerns
In May 2025, security researchers highlighted significant privacy and security concerns in the Windows 11 Recall feature, an AI-powered function that automatically captures and stores screenshots and context of user activity. Although designed to enhance productivity by allowing seamless search and recall, the feature stores sensitive information—including potential credentials, private messages, and payment data—without robust controls or proven encryption. The built-in privacy filtering was found to be unreliable, enabling attackers or malware to leverage Recall’s artifacts to reconstruct user activity or exfiltrate high-value data. Because the Recall database is accessible without administrative privilege, organizations relying on default configurations could unintentionally expose critical information or face regulatory risks. This incident underscores the urgent need for organizations to review new operating system features before broad deployment, especially as attackers increasingly target post-compromise artifacts and AI-powered data collectors. High-profile attention to Recall has driven further debate on privacy standards and compliance, with heightened scrutiny from both regulators and security leaders.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports