Validated Containment Architectures are here. →Explore

Industry Category

Financial Services

Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.

3675 threat reports
Page 276 of 307

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Financial Services Threat Reports

Showing 33013312 / 3675 reports
SolarWinds & MOVEit: The Wake-Up Call for Modern Supply Chain Cybersecurity
Impact· high

SolarWinds & MOVEit: The Wake-Up Call for Modern Supply Chain Cybersecurity

In recent years, a wave of major supply chain cyberattacks—most notably the SolarWinds compromise in 2020 and the MOVEit Transfer breach in 2023—have demonstrated how adversaries exploit trusted vendors to bypass defenses at scale. In the SolarWinds incident, attackers injected malicious code into the Orion software updates, leading to undetected access across 18,000 organizations, including government agencies and Fortune 500 companies. Just three years later, a zero-day vulnerability in MOVEit’s file transfer software enabled ransomware group Clop to exfiltrate and manipulate sensitive data from more than 2,000 global organizations, impacting over 62 million individuals. These incidents not only inflicted operational and reputational damage but also instigated regulatory and legal scrutiny, highlighting that even the most secure organizations remain vulnerable through third-party dependencies. Supply chain attacks now pose an elevated risk as threat actors increasingly target software providers, managed service firms, and widely used platforms to maximize reach and disruption. Rising regulatory expectations on supply chain oversight, combined with new TTPs like supply chain ransomware and identity abuse, solidify supply chain risk as a top boardroom and CISO concern.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Fortra GoAnywhere MFT Breach: How CVE-2025-10035 Enabled a Major Ransomware Attack
Impact· high

Fortra GoAnywhere MFT Breach: How CVE-2025-10035 Enabled a Major Ransomware Attack

In September 2025, Fortra disclosed that its GoAnywhere Managed File Transfer (MFT) platform suffered from a critical vulnerability (CVE-2025-10035) that was actively exploited by threat actors. Attackers leveraged this flaw—reportedly requiring a private cryptographic key, the origins of which are still unclear—to gain unauthorized access, moving laterally within cloud-based environments and exfiltrating data. Notably, Microsoft attributed ransomware intrusions and multi-stage attacks to a criminal group tracked as Storm-1175, leading to business disruptions and heightened risk for GoAnywhere users. Fortra responded by patching its services, investigating suspicious activity, and notifying affected customers, though questions remain regarding the root cause and extent of private key compromise. This incident highlights the growing risk of supply chain and third-party software vulnerabilities being exploited in ransomware campaigns. The exploitation of cryptography-dependent mechanisms signals an evolving sophistication among threat actors, pressing organizations to reconsider approaches to privileged cryptographic assets and drive urgency in patch management.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Harvard University Hit by Clop Ransomware Through Oracle Zero-Day Exploit in 2025
Impact· high

Harvard University Hit by Clop Ransomware Through Oracle Zero-Day Exploit in 2025

In October 2025, Harvard University disclosed an ongoing investigation into a cybersecurity breach linked to the exploitation of a zero-day vulnerability (CVE-2025-61882) in Oracle's E-Business Suite servers. The Clop ransomware gang claimed responsibility after adding Harvard to its data leak site, stating sensitive administrative data was stolen and threatening public release if ransom demands were not met. The attack was part of a broader campaign targeting Oracle E-Business Suite customers globally, exploiting the flaw for extortion and data theft. Harvard applied the vendor’s emergency patch upon notification and reported the breach as limited to a small administrative unit, with no signs of further compromise. This incident underscores the continuous risk universities and other organizations face from sophisticated ransomware groups leveraging zero-day exploits to bypass conventional defenses. The rapid exploitation of newly discovered vulnerabilities and subsequent data thefts reflect an ongoing shift towards extortion-focused campaigns targeting high-profile institutions and critical business systems.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
Oracle E-Business Suite 2025 Flaw Sparks Urgent Clop Ransomware Concerns
Impact· high

Oracle E-Business Suite 2025 Flaw Sparks Urgent Clop Ransomware Concerns

In October 2025, Oracle issued an emergency patch addressing CVE-2025-61884, a critical information disclosure vulnerability in its E-Business Suite (EBS) affecting versions 12.2.3 through 12.2.14. The flaw, present in the Runtime UI component, allowed unauthenticated attackers to remotely access sensitive business data, bypassing standard authentication mechanisms. The incident followed the discovery that threat actors—most notably the Clop ransomware group—had recently targeted Oracle EBS zero-days in extortion schemes against executives, leveraging vulnerabilities to facilitate large-scale data theft. Although Oracle has not confirmed active exploitation of CVE-2025-61884, the urgency of the patch highlights heightened threat actor interest and continued risk for organizations with unpatched, internet-facing EBS deployments. This incident underscores an alarming trend: criminal groups exploiting zero-day and recently patched vulnerabilities in widely used business applications for extortion and data theft. The rapid evolution of attacker tactics, combined with the continued exposure of critical SaaS and ERP platforms, raises the stakes for organizations to accelerate patching cycles and strengthen segmentation and threat detection strategies.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
SonicWall VPN Breach 2025: Credential Theft Sparks Widespread Compromise
Impact· medium

SonicWall VPN Breach 2025: Credential Theft Sparks Widespread Compromise

In October 2025, a widespread cyberattack compromised more than 100 SonicWall SSLVPN accounts across 16 customer environments through the use of stolen, valid credentials. Researchers at Huntress observed the attackers rapidly authenticating into multiple accounts, with some sessions ending abruptly while others progressed to network reconnaissance and attempts at lateral movement by targeting local Windows accounts. The campaign began around October 4, 2025, with most attack traffic tracing back to a single IP address. Although there is no direct link to a previous breach involving SonicWall firewall configuration files, the incident underscores a substantial exposure risk to sensitive systems, business operations, and potentially regulatory compliance requirements. This incident highlights the evolving threat landscape, where credential compromise—not brute force—enables rapid, large-scale intrusions into VPN infrastructures. The continued prevalence of identity-driven attacks against remote access systems amplifies the urgency for enhanced credential hygiene, multi-factor authentication, and zero-trust access controls in the face of sophisticated adversaries.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Massive Multi-Country Botnet Launches RDP Attacks Against US Organizations
Impact· low

Massive Multi-Country Botnet Launches RDP Attacks Against US Organizations

In October 2025, a massive botnet composed of devices spanning over 100 countries launched coordinated attacks targeting Remote Desktop Protocol (RDP) services in the United States. Security researchers first spotted a spike in unusual RDP traffic originating from Brazil, with further malicious activity quickly spreading globally. Attackers leveraged two primary techniques: RD Web Access timing attacks to infer valid usernames, and RDP web client login enumeration to access accounts through analysis of server response behaviors. The campaign utilized over 100,000 unique IP addresses sharing a similar TCP fingerprint, indicating a highly organized cluster-based operation. The attacks put both government and enterprise systems at risk of brute-force intrusion and potential credential compromise. This incident underlines the persistent and evolving threat posed by botnets against remote access services. With increasing remote work reliance and exposed RDP endpoints, such sophisticated, multi-geography attacks exploit common authentication weaknesses and call for urgent upgrades in defense, including MFA and network segmentation.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
Microsoft 2025: Zero-Day Exploit Prompts Emergency IE Mode Restrictions
Impact· low

Microsoft 2025: Zero-Day Exploit Prompts Emergency IE Mode Restrictions

In October 2025, Microsoft announced urgent restrictions on Internet Explorer (IE) mode within the Edge browser following the discovery of active zero-day exploits targeting the Chakra JavaScript engine. Threat actors leveraged sophisticated social engineering tactics to lure users to spoofed sites, where a previously unknown vulnerability in Chakra enabled remote code execution. Attackers combined this with a privilege escalation flaw to escape the browser sandbox and seize complete device control. Microsoft responded by removing easy methods to activate IE mode in Edge for consumer users, instead requiring manual configuration limited to explicit, approved sites, and urged migration from legacy technologies. This incident underscores the persistent risks associated with maintaining legacy web compatibility features such as IE mode, especially as threat actors increasingly exploit these pathways with sophisticated chains of zero-day vulnerabilities and social engineering. It highlights heightened urgency for organizations to migrate from deprecated software and rigorously manage legacy access points.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
Spain Shuts Down GXC Team: Crime-as-a-Service Powerhouse Busted in 2025
Impact· high

Spain Shuts Down GXC Team: Crime-as-a-Service Powerhouse Busted in 2025

In May 2025, Spanish authorities dismantled the "GXC Team" cybercrime syndicate, arresting its alleged leader, a 25-year-old Brazilian known as "GoogleXcoder." Operating as a Crime-as-a-Service (CaaS) provider, the group developed and sold AI-powered phishing kits, multiple Android malware strains, and social engineering voice-scam tools, primarily via Telegram and Russian-speaking hacker forums. Their phishing operations targeted financial, transport, and e-commerce institutions in Spain, Slovakia, the UK, the US, and Brazil, facilitating large-scale credential theft through more than 250 spoofed sites. Law enforcement recovered stolen cryptocurrency, seized electronic evidence, and shut down illicit channels. The investigation, enabled by forensic analysis of devices and crypto transactions, remains ongoing, with further arrests anticipated. This incident highlights the rise of CaaS platforms using automation, AI, and malware-as-a-service approaches to accelerate phishing and fraud at scale. The GXC Team case underscores the evolving sophistication and reach of these criminal ventures, which now target numerous sectors globally and leverage encrypted communications to obfuscate operations.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Fake Inflation Refund Phishing Texts Target New Yorkers in 2025 Smishing Attack
Impact· high

Fake Inflation Refund Phishing Texts Target New Yorkers in 2025 Smishing Attack

In October 2025, a coordinated smishing campaign targeted New York State residents with fraudulent text messages purporting to be from the Department of Taxation and Finance. The attackers claimed recipients were eligible for an 'Inflation Refund' and directed them to a phishing site impersonating an official state portal, where victims were prompted to submit sensitive personal data—name, address, email, phone number, and Social Security Number—under the guise of processing their refund. This malicious operation seeks to steal identities and facilitate extensive financial fraud. Government officials swiftly issued warnings, clarifying that legitimate refunds required no action from residents and urging vigilance. This incident is a stark reminder of the increasing sophistication of SMS phishing (smishing) attacks, which blend timely government programs with social engineering techniques. The campaign highlights the persistent risk posed by identity-centric attacks, especially as digital fraudsters exploit widespread economic uncertainty and official-sounding initiatives.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Qantas 2025 Data Breach: Scattered LAPSUS$ Defies Legal Barriers
Impact· high

Qantas 2025 Data Breach: Scattered LAPSUS$ Defies Legal Barriers

In October 2025, Australian airline Qantas suffered a major data breach when threat actor group Scattered LAPSUS$ released sensitive customer and employee data following an extortion attempt. Despite Qantas obtaining a legal injunction aimed at stopping the dissemination of the information, the attackers proceeded to publish the stolen data, rendering legal intervention ineffective. The incident exposed personal records and travel information, spotlighting ongoing organizational vulnerabilities to data extortion and public leaks driven by sophisticated attackers exploiting access. The breach prompted widespread media coverage and concern over enforcement power in digital incidents. This attack underscores the growing trend of double extortion tactics, where attackers threaten to release stolen data for leverage, outpacing regulatory or legal controls. The event exemplifies the surge in ransomware and extortion methods targeting aviation and critical infrastructure, reinforcing the urgent need for proactive, technical mitigations and incident preparedness planning.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Bling Libra’s 2024 Extortion: Lessons from a Modern Ransomware Attack
Impact· high

Bling Libra’s 2024 Extortion: Lessons from a Modern Ransomware Attack

In early 2024, a cybercriminal alliance known as Bling Libra—aligned with the notorious Scattered Spider and Lapsus$—launched coordinated extortion campaigns targeting retail and hospitality organizations worldwide. Using a mixture of credential theft, social engineering, and advanced lateral movement, attackers bypassed security controls to gain privileged access to sensitive systems, disrupted operations, and exfiltrated confidential data. Victims faced steep ransom demands and public threats of data disclosure if payments were not met, resulting in loss of business continuity, reputational harm, and regulatory scrutiny. This incident highlights the mounting prevalence of extortion-based tactics that leverage both data theft and operational disruption. Organizations across multiple industries are now seeing an increase in sophisticated, multi-stage attacks fueled by agile, loosely affiliated threat actor groups determined to exploit gaps in cyber defenses.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Russian ClayRat Android Spyware Masquerades as Popular Apps, Spreads Rapidly in 2024
Impact· medium

Russian ClayRat Android Spyware Masquerades as Popular Apps, Spreads Rapidly in 2024

In mid-2024, security researchers at Zimperium discovered ClayRat, a rapidly evolving Android spyware campaign targeting users in Russia. Disguised as trusted apps like TikTok and YouTube, ClayRat was spread via phishing websites and Telegram channels, infecting over 600 devices in just three months. Once installed, the spyware leverages Android’s SMS handler permissions to bypass typical security prompts, allowing attackers to covertly access messages, call logs, device information, and even remotely control infected phones. The highly orchestrated campaign abused social engineering, web deception, and obfuscation techniques to remain undetected, and can turn each compromised device into a new attack vector. The threat’s evolution signals rising global risks, as the campaign’s tactics can easily adapt to new payloads and regions. With increasing use of mobile malware, organizations globally should reassess mobile security controls and user awareness programs to defend against sophisticated, evasive spyware attacks exploiting trust in well-known apps.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports