✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
Phishing and RMM Tool Abuse Drive Multi-Vector Attacks – September 2025 Wrap-Up
In September 2025, organizations faced a surge of multi-vector cyber campaigns targeting enterprises through sophisticated phishing attacks and compromised WordPress sites. Attackers used phishing emails as entry points, tricking employees into installing remote monitoring and management (RMM) tools such as AnyDesk and Atera, thereby gaining unauthorized access to internal networks. Simultaneously, threat actors leveraged vulnerable or hijacked WordPress websites to distribute malware payloads, facilitating both initial compromise and lateral movement across organizations' internal networks. The impact included credential theft, unauthorized remote control, and data exfiltration, as well as disruption to normal business activities. This incident highlights a rapidly evolving threat landscape where attackers combine social engineering, legitimate RMM tools, and supply-chain exploits to evade traditional security defenses. It underscores increased regulatory attention on monitoring east-west traffic, policy enforcement, and anomaly detection across hybrid cloud environments.
6 months ago
Kill Chain
DraftKings 2025 Credential Stuffing Breach: Lessons in Password Security
In October 2025, DraftKings, a prominent sports betting company, disclosed that less than 30 customer accounts were compromised via credential stuffing attacks. Threat actors utilized previously stolen username and password combinations from breaches of unrelated services, leveraging automated tools to gain unauthorized access to DraftKings user accounts. While the attackers obtained personal data such as names, addresses, dates of birth, contact details, and the last four digits of payment cards, there was no evidence of access to sensitive government-issued IDs or full financial account numbers. DraftKings responded swiftly by notifying affected users, requiring password resets, and recommending the use of multifactor authentication to mitigate further risk. This incident highlights the persistent threat of credential stuffing—an attack vector that exploits widespread password reuse. With large troves of leaked credentials available and automated attack tools on the rise, organizations across industries face increasing regulatory pressure to implement layered authentication and robust account monitoring to defend against identity-driven threats.
6 months ago
Kill Chain
Google Gemini Hit by Unfixed ASCII Smuggling AI Attack in 2025
In October 2025, a newly disclosed ASCII smuggling attack targeting Google’s Gemini AI assistant exposed a significant security vulnerability stemming from the model's processing of hidden Unicode payloads. Security researcher Viktor Markopoulos demonstrated that attackers could leverage invisible Unicode characters in Calendar invites or emails, prompting Gemini to execute unseen instructions and alter its behavior without user awareness. Notably, the exploit could automate data extraction or spoof identities within Google Workspace integrations, increasing risk for both users and enterprises. Despite the demonstrated risks, Google chose not to address the vulnerability, citing its overlap with social engineering tactics. This incident underscores the heightened threat posed by AI/ML attacks against widely integrated platforms. As LLMs increasingly automate workflows and access sensitive data, adversarial prompt manipulation and Unicode character abuse are becoming urgent areas for organizational security reviews and regulatory scrutiny.
6 months ago
Kill Chain
Salesforce 2025 Supply Chain Data Breach: An Executive Overview
In 2025, Salesforce and hundreds of its customers were targeted in two coordinated data theft campaigns by the threat group "Scattered Lapsus$ Hunters," leveraging both social engineering and stolen OAuth tokens. Attackers tricked employees into connecting malicious OAuth applications or exploited compromised Salesloft Drift tokens, gaining unauthorized access to sensitive CRM data, support tickets, credentials, and authentication tokens. The attackers subsequently attempted to extort 39 major organizations, threatening to leak up to 1.5 billion records via a dark web leak site unless sizable ransom demands were met. Salesforce publicly refused to negotiate or pay any ransom, and law enforcement actions appeared to subsequently seize the extortion domain. This incident underscores the growing sophistication of supply-chain attacks using identity-based and OAuth token compromise, highlighting the rising risk to SaaS ecosystems. The event triggered significant concerns across industries that increasingly rely on interconnected third-party platforms and further emphasizes urgent gaps in SaaS security, zero trust application governing, and lateral movement prevention.
6 months ago
Kill Chain
Google Workspace 2025 OAuth Supply Chain Breach: Lessons From the Drift Incident
In August 2025, a supply chain attack targeted Google Workspace via compromised OAuth tokens associated with the Drift email integration, impacting several organizations. Attackers leveraged stolen Drift tokens to gain unauthorized, delegated access to connected Google Workspace mailboxes, bypassing traditional security controls by exploiting trusted third-party app grants. Google rapidly responded on August 9 by revoking the affected tokens and disabling the integration. While only a small number of mailboxes were directly accessed, the incident underscored how attackers increasingly exploit SaaS interconnections rather than direct platform breaches. This incident is particularly relevant today as exploitation of OAuth tokens and third-party integrations continues to climb, representing a paradigm shift in enterprise attack surfaces. It highlights the growing need for comprehensive SaaS integration visibility, rigorous token governance, and real-time behavioral monitoring as attackers increasingly favor these stealthy, scalable techniques.
6 months ago
Kill Chain
Crimson Collective’s 2025 AWS Cloud Data Breach: Tactics, Impacts, and Security Lessons
In October 2025, the Crimson Collective threat group executed a sophisticated attack targeting Amazon Web Services (AWS) cloud instances belonging to multiple organizations, most notably Red Hat. Utilizing exposed AWS credentials discovered via open-source reconnaissance tools, the attackers escalated their privileges by creating new IAM users with administrative rights. They then enumerated and accessed sensitive resources, including databases and storage volumes, exfiltrating approximately 570 GB of data from private GitLab repositories. The Crimson Collective followed up with extortion demands, leveraging AWS's internal and external email services to apply pressure on victims and collaborating with the Scattered Lapsus$ Hunters to intensify threats. This incident underscores an escalating trend of cloud-focused threat actors exploiting credential exposures to breach critical infrastructure, bypass perimeter controls, and apply multifaceted extortion tactics. Organizations face increasing regulatory and business risk as attackers target cloud identity and API misconfigurations, requiring immediate attention to zero trust controls, egress restrictions, and anomaly detection in multi-cloud environments.
6 months ago
Kill Chain
FileFix's 2024 Cache Smuggling Attack: What CISOs Need to Know
In June 2024, a new variant of the FileFix social engineering attack was identified leveraging cache smuggling to bypass endpoint security and deliver a malicious ZIP archive onto victims' systems. Attackers enticed users with phishing emails or deceptive social engineering content, prompting them to click download links. These links abused proxy and cache server behaviors to insert a malware payload into responses that security tools would otherwise block, enabling stealthy malware infection and potential data exfiltration. The attack method proved effective at evading security controls such as endpoint protection, web proxies, and firewalls, increasing the risk to business operations and sensitive data. This incident underscores the sophisticated evolution of social engineering attacks, now boosted by technical exploits like cache smuggling. Attackers are increasingly combining human and infrastructure weaknesses to evade even advanced security defenses, making traditional filtering and sandboxing less reliable. Security operations should urgently revisit email, web proxy, and endpoint controls for these new attack chains.
6 months ago
Kill Chain
2025 Fortra GoAnywhere Breach: Medusa Ransomware Leverages Zero-Day and Key Compromise
In early 2025, Medusa ransomware operators—tracked as Storm-1175—successfully exploited a critical vulnerability (CVE-2025-10035) in the Fortra GoAnywhere Managed File Transfer (MFT) platform. The attack required access to a private key, indicating either an advanced intrusion or insider compromise. Once inside, the threat actors moved laterally to deploy ransomware payloads, seizing sensitive business data and disrupting managed file transfers for impacted organizations. Multiple enterprises suffered data theft, business downtime, and reputational damage as a result. This incident underscores an ongoing trend of targeting supply chain platforms and MFT products with ransomware via sophisticated access methods. As ransomware groups become more resourceful in exploiting zero-days and leveraging stolen keys, organizations must prioritize proactive threat detection, timely patching, and tighter access controls to counter these evolving tactics.
6 months ago
Kill Chain
Clop Ransomware Strikes Oracle: 2024 Zero-Day Breakdown
In early 2024, the Clop ransomware group leveraged a previously unknown zero-day vulnerability in Oracle E-Business Suite to infiltrate the networks of multiple Oracle customers. Exploiting this zero-day, Clop operators gained unauthorized access to critical enterprise systems by bypassing conventional security controls, moving laterally within organization environments, and ultimately deploying ransomware to encrypt sensitive business data. The attack’s vector allowed rapid compromise across industries reliant on Oracle systems, resulting in operational disruptions, potential data exposure, and ransom demands for decryption keys. Security teams across affected organizations were forced into emergency response and containment procedures. This incident highlights a disturbing trend of ransomware gangs exploiting supply-chain vulnerabilities and zero-day flaws in widely used enterprise applications. With attackers aggressively targeting business-critical platforms, the urgency for patch management, network segmentation, and advanced threat monitoring has never been higher, especially as regulatory scrutiny and financial impacts intensify.
6 months ago
Kill Chain
Breaking: 'RediShell' RCE Vulnerability Hits 300,000+ Redis Cloud Servers
In early June 2024, security experts identified a critical remote code execution (RCE) vulnerability, dubbed 'RediShell,' impacting Redis servers worldwide. This 13-year-old flaw (CVSS 10.0) enables unauthenticated attackers to execute arbitrary commands and fully compromise exposed hosts. More than 300,000 unpatched Redis instances were found publicly accessible, largely in cloud and hybrid environments, risking complete data loss, ransomware deployment, or lateral movement within enterprise networks. Attackers rapidly weaponized the exploit to automate mass scans and attacks, prompting emergency advisories and patch releases from Redis maintainers and cloud providers. This incident underscores the ongoing risks posed by old vulnerabilities in widely deployed open-source software. The scale and speed of RediShell exploitation demonstrate attackers’ preference for high-impact, low-effort weaknesses in cloud infrastructure, forcing organizations to prioritize patching, network segmentation, and modern Zero Trust models.
6 months ago
Kill Chain
FreePBX VoIP Vulnerability Exploited: CVE-2025-57819 Enables Code Execution
In August 2025, a critical SQL injection vulnerability (CVE-2025-57819) was disclosed in FreePBX, a popular open-source VoIP telephony platform. The flaw, found in the system's web-based admin interface, allowed unauthenticated attackers to inject malicious SQL queries via a vulnerable 'brand' parameter, enabling arbitrary modification of the backend database. Attackers have already been observed using this vulnerability to gain remote code execution by inserting persistent cron jobs that continuously recreate a web shell on the target server, providing full access for data exfiltration or fraudulent activities. Organizations using unpatched versions may be exposed to call fraud, impersonation, lateral movement, or further compromise of VoIP infrastructure. This breach highlights a persistent trend of attackers exploiting critical web application vulnerabilities shortly after public disclosure, underscoring the importance of proactive patching and real-time threat detection. It also illustrates attackers’ growing focus on embedded and telecom systems as entry points for broader enterprise compromise.
6 months ago
Kill Chain
EU Chat Control Law Threatens Privacy and Encryption in 2024
In 2024, the European Union considered sweeping legislation called Chat Control, aimed at mandating providers of end-to-end encrypted messaging apps to implement client-side scanning of user content for illegal material, notably child sexual abuse material (CSAM). Major privacy advocates and technology leaders, including Signal's CEO, highlighted that such a regulation would undermine privacy by requiring access to sensitive content before encryption. Technical experts warned that creating lawful access inherently weakens the entire encrypted ecosystem, exposing all users—including journalists, activists, and vulnerable groups—to potential surveillance or exploitation, and might force some encrypted messaging services to exit the EU market entirely. This proposed law has sparked an urgent debate on digital privacy, as its adoption could set a global precedent for government-mandated encryption backdoors. The current climate of rising concerns over lawful and extrajudicial surveillance, combined with persistent cyber threats, amplifies the pertinence and risks associated with such regulatory initiatives.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports