Validated Containment Architectures are here. →Explore

Industry Category

Financial Services

Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.

3675 threat reports
Page 280 of 307

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Financial Services Threat Reports

Showing 33493360 / 3675 reports
Oracle Zero-Day Breach: Clop Ransomware Group Orchestrates Global Data Theft in 2024
Impact· high

Oracle Zero-Day Breach: Clop Ransomware Group Orchestrates Global Data Theft in 2024

In mid-2024, the Clop ransomware gang exploited a critical zero-day vulnerability (CVE-2025-61882) in Oracle E-Business Suite, executing a sophisticated chain of exploits for unauthorized, pre-authenticated remote code execution. Attackers infiltrated multiple enterprise and public-sector environments, stealing significant volumes of data before issuing high-dollar extortion demands—some as high as $50 million. The breaches went undetected for weeks, with Oracle disclosing the flaw only after victims began receiving ransom emails and the U.S. CISA catalogued the vulnerability as actively exploited. This incident underscores the rapid weaponization of newly discovered vulnerabilities by well-resourced threat actors. As enterprises increase reliance on complex ERP systems, threats leveraging zero-day exploits and multi-bug chains have become a pressing concern, signaling the need for enhanced threat detection, segmentation, and zero-trust controls.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Clop Ransomware Exploits Oracle EBS Zero-Day for Massive Data Theft in 2025
Impact· high

Clop Ransomware Exploits Oracle EBS Zero-Day for Massive Data Theft in 2025

In October 2025, Oracle urgently patched a critical zero-day vulnerability (CVE-2025-61882) affecting Oracle E-Business Suite (EBS) after widespread exploitation by the Clop ransomware gang. The flaw enabled unauthenticated remote code execution via the Concurrent Processing component’s BI Publisher integration, letting attackers gain unauthorized access and exfiltrate data. Threat actors, including Clop and possibly affiliated groups, used public proof-of-concept exploits—some leaked by other cybercriminals—to breach multiple organizations’ Oracle EBS servers. Victims were extorted via email, with stolen data leveraged for ransom, highlighting material operational and reputational risks. This incident underscores the persistent targeting of enterprise software zero-days by organized ransomware groups. The increased speed of exploit weaponization and the public sharing of exploit code amplify the urgency for organizations to apply patches swiftly, harden business-critical systems, and enhance detection capabilities for lateral movement and data exfiltration.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
XWorm RAT Re-emerges in 2025: Ransomware & Plugins Drive Global Malware Campaigns
Impact· high

XWorm RAT Re-emerges in 2025: Ransomware & Plugins Drive Global Malware Campaigns

In mid-2025, security researchers observed the resurgence of XWorm, a modular remote access trojan (RAT) that now features extensive plugin support and an integrated ransomware module. Originally developed by XCoder and abandoned in 2024, the latest XWorm variants (v6.0–6.5) have been widely adopted by multiple threat actors and distributed via phishing campaigns using malicious scripts and document attachments. Capable of data theft, remote desktop takeover, and file encryption, XWorm leverages over 35 plugins, including modules for browser data harvesting, keystroke logging, shell access, and ransomware deployment. The malware's rapid proliferation has led to thousands of infections globally, with major activity detected in Russia, the US, India, Ukraine, and Turkey. The reappearance of XWorm, now available on dark web forums and grouped with capabilities like AI-themed lures and social engineering, demonstrates an alarming trend: readily available commodity malware is increasingly sophisticated and multifaceted. This case underscores rising risks from plug-and-play cybercrime kits and reinforces the critical need for continuous defense, layered security, and advanced threat monitoring.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Redis 2025 Critical RCE: How CVE-2025-49844 Threatens Cloud Data Security
Impact· medium

Redis 2025 Critical RCE: How CVE-2025-49844 Threatens Cloud Data Security

In October 2025, Redis disclosed a critical remote code execution vulnerability (CVE-2025-49844), stemming from a 13-year-old use-after-free bug in the Lua interpreter, impacting all major Redis releases. Exploitable via authenticated Lua scripts—enabled by default—the flaw allows attackers to escape the script sandbox, execute arbitrary code, establish persistent access via reverse shell, and ultimately gain full control of the host system. Security researchers revealed that over 330,000 Redis instances were exposed online, some requiring no authentication, enabling credential theft, data exfiltration, lateral movement, and malware deployment at scale. This incident highlights persistent risks from legacy code, cloud-exposed databases, and default insecure configurations, accelerating regulatory and industry emphasis on proactive patching, network segmentation, and least privilege controls. The vulnerability’s sheer scope and ease of exploitation underline the urgency for organizations to remediate and harden public-facing infrastructure.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Microsoft 2025: Storm-1175 Exploits GoAnywhere Zero-Day for Devastating Ransomware Attacks
Impact· high

Microsoft 2025: Storm-1175 Exploits GoAnywhere Zero-Day for Devastating Ransomware Attacks

In September 2025, a cybercrime group tracked as Storm-1175 exploited a critical zero-day deserialization vulnerability (CVE-2025-10035) in Fortra's GoAnywhere Managed File Transfer (MFT) solution. The attackers gained initial access by remotely targeting vulnerable MFT instances and leveraged remote monitoring tools (SimpleHelp, MeshAgent) for persistence. Subsequently, they conducted network reconnaissance with Netscan, moved laterally using Microsoft RDP, exfiltrated sensitive data with Rclone, and ultimately deployed Medusa ransomware payloads to encrypt files. This campaign affected multiple organizations, exposing unpatched systems to significant operational risk and data loss. The incident highlights a continued surge in ransomware operations leveraging zero-day vulnerabilities in widely used enterprise software. Attackers are increasingly exploiting supply chain and infrastructure components to maximize impact, driving regulatory scrutiny and accelerating the need for robust patch management and segmentation practices.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
How Kaspersky’s 2025 ML Models Raised the Bar for DLL Hijacking Detection
Impact· medium

How Kaspersky’s 2025 ML Models Raised the Bar for DLL Hijacking Detection

In 2025, Kaspersky advanced their detection capabilities against DLL hijacking attacks by developing and deploying machine learning (ML) models. DLL hijacking, used by both organized malware developers (such as those behind Lumma stealer) and advanced persistent threat (APT) groups, involves loading malicious DLLs in place of genuine libraries. Attackers exploited trusted processes to evade detection and complicate incident response. Kaspersky’s internal telemetry revealed a sharp uptick in these attacks across diverse regions and sectors, prompting an iterative ML-driven approach. By refining training datasets, extracting relevant behavioral features, and evolving their models through analyst feedback, Kaspersky achieved higher true positive rates and reduced false positives, integrating the solution into SIEM and MDR offerings to surface live threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Red Hat Breach 2025: ShinyHunters Escalate GitLab Data Extortion
Impact· high

Red Hat Breach 2025: ShinyHunters Escalate GitLab Data Extortion

In October 2025, Red Hat suffered a significant data breach after threat actor group Crimson Collective compromised its internal GitLab repositories, exfiltrating nearly 570GB of data including around 800 Customer Engagement Reports (CERs). These reports contained sensitive details about customers’ networks and infrastructure. Following unsuccessful ransom negotiations, Crimson Collective partnered with Scattered Lapsus$ Hunters and ShinyHunters to escalate extortion attempts, publicly posting data samples and demanding payment before a hard deadline. High-profile organizations such as Walmart, HSBC, Bank of Canada, and the US Department of Defense were among affected clients named in the leak. The collaboration between multiple threat actors and the rise of Extortion-as-a-Service operations like ShinyHunters highlight a new era of corporate extortion risk, with increasing pressure on organizations to proactively secure code repositories and sensitive customer communications against rapidly-evolving, multi-actor cyber threats.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
Kaspersky SIEM Uncovers ToddyCat DLL Hijacking Attacks in 2024
Impact· medium

Kaspersky SIEM Uncovers ToddyCat DLL Hijacking Attacks in 2024

In early 2024, Kaspersky detected several advanced persistent threat (APT) incidents during pilot testing of their machine-learning-based DLL-hijacking detection module within their SIEM platform. Notably, the ToddyCat APT group exploited a SharePoint vulnerability (CVE-2021-27076) to gain initial access, then leveraged DLL sideloading to execute Cobalt Strike implants using masqueraded Windows system libraries. Other real-world incidents uncovered included infostealer malware posing as a policy manager, and a malicious loader activated through a USB drive, all utilizing DLL hijacking for code execution and persistence. Kaspersky’s detection tool enabled rapid identification and response, preventing further compromise and data exfiltration. This case highlights the growing sophistication of DLL hijacking techniques in APT operations and the increasing use of AI-driven security products to detect lateral movement and stealthy intrusion behaviors. The incidents underscore the need for robust behavioral analytics and real-time anomaly detection as threat actors increasingly target supply chains and trusted binaries to bypass traditional security defenses.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Chinese Cybercrime Group Exploits IIS Servers in Global SEO & Credential Theft Scheme
Impact· medium

Chinese Cybercrime Group Exploits IIS Servers in Global SEO & Credential Theft Scheme

In October 2025, cybersecurity analysts uncovered a campaign orchestrated by a Chinese-speaking cybercrime group known as UAT-8099. The group exploited vulnerabilities in Microsoft Internet Information Services (IIS) servers, primarily targeting organizations across India and Thailand. Attackers deployed malicious scripts and leveraged the compromised servers for global search engine optimization (SEO) fraud while systematically stealing high-value credentials, configuration files, and certificate data. This sophisticated operation impacted business continuity, undermined trust, and exposed sensitive enterprise assets to further misuse. This breach exemplifies the growing threat from well-resourced cybercrime rings using server-side exploits to conduct financially motivated attacks. Similar credential theft and SEO manipulation TTPs are increasingly prevalent worldwide, highlighting an urgent need for enhanced internal server security, threat detection, and compliance with modern data protection standards.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Oracle E-Business Suite Hit by Cl0p: CVE-2025-61882 Breach Exposes Enterprise Data
Impact· high

Oracle E-Business Suite Hit by Cl0p: CVE-2025-61882 Breach Exposes Enterprise Data

In October 2025, Oracle urgently released a security patch addressing CVE-2025-61882, a critical vulnerability in its E-Business Suite platform with a CVSS score of 9.8. The flaw, allowing unauthenticated remote attackers network access via HTTP, was actively exploited by the Cl0p ransomware gang in a series of data theft attacks. Threat actors leveraged the bug to gain control of impacted systems, enabling lateral movement and the exfiltration of sensitive business data. Oracle customers with exposed E-Business Suite deployments were specifically targeted, prompting a rapid, emergency response. This incident highlights the resurgence of large-scale supply chain ransomware attacks exploiting zero-day vulnerabilities in widely used enterprise software. Threat actors like Cl0p are increasingly automating exploitation campaigns, raising the bar for threat detection, patch management, and regulatory compliance requirements in digital enterprises.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Oracle’s 2025 Mega Breach: 0-Day, BitLocker Bypass & VMScape Trigger Industry Wake-Up
Impact· medium

Oracle’s 2025 Mega Breach: 0-Day, BitLocker Bypass & VMScape Trigger Industry Wake-Up

In October 2025, Oracle faced a significant security incident that exposed critical new 0-day vulnerabilities, impacting key platforms via exploits including a BitLocker bypass, the 'VMScape' hypervisor escape, and a fast-spreading WhatsApp worm. Threat actors leveraged multiple sophisticated attack vectors, targeting both enterprise infrastructure and end-user devices. The campaign enabled unauthorized lateral movement, data exfiltration, and disruption of cloud workloads, with global enterprises and managed service providers feeling downstream impact as security researchers identified widespread exploitation across hybrid and multicloud environments. These multi-pronged intrusions forced urgent mitigation efforts, including rapid patching, segmentation, and new traffic visibility controls to stem active attacks. The incident underscores escalating attacker sophistication in blending 0-day exploitation, social engineering, and cloud platform abuse. As threat campaigns increasingly combine lateral spread mechanisms with supply chain risks and targeted ransomware, it highlights the necessity of modern Zero Trust frameworks, advanced detection, and continuous security governance for organizations operating at cloud scale.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Self-Propagating Malware Targets WhatsApp Users in Brazil with Financial Fraud Infostealer
Impact· medium

Self-Propagating Malware Targets WhatsApp Users in Brazil with Financial Fraud Infostealer

In early June 2024, an infostealer campaign dubbed Water Saci aggressively targeted WhatsApp users in Brazil using self-propagating malware named Sorvepotel. Attackers leveraged compromised accounts to automatically distribute malicious links via WhatsApp messages, luring recipients to execute malware payloads. Once installed, Sorvepotel exfiltrates credentials and tracks browser activities, enabling threat actors to target and defraud regional financial institutions. The infection chain’s ability to rapidly spread through trusted social contacts increased both the velocity and scale of impact, compromising both individual and enterprise devices in a short time frame. The Water Saci operation highlights the evolution of credential-stealing malware adopting worm-like features to maximize reach. With messaging platforms remaining core to business and personal communications, this incident underscores the urgency of intercepting lateral movement, especially as attackers blend social engineering with advanced propagation and data theft techniques.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports