Validated Containment Architectures are here. →Explore

Industry Category

Financial Services

Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.

3675 threat reports
Page 287 of 307

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Financial Services Threat Reports

Showing 34333444 / 3675 reports
Akira Ransomware: MFA-Protected SonicWall VPNs Breached in 2024
Impact· high

Akira Ransomware: MFA-Protected SonicWall VPNs Breached in 2024

In early 2024, the Akira ransomware group escalated its campaign by successfully breaching organizations through SonicWall SSL VPN appliances, even when multi-factor authentication (MFA) was enabled. Security researchers determined that Akira actors appeared to bypass one-time password (OTP) protections, potentially by leveraging previously obtained OTP seed information or exploiting weaknesses in authentication management. Following the VPN compromise, attackers moved laterally, exfiltrated data, and encrypted systems to demand substantial ransom payments. This attack vector enabled access to privileged internal resources, resulting in business disruption, data exposure, and financial losses for affected organizations. The incident underscores how ransomware operators are adapting to bypass commonly deployed defenses, specifically targeting VPN and MFA solutions. Such tactics highlight the urgent need for organizations to reassess remote access controls, authentication infrastructure, and visibility gaps, as similar techniques are increasingly observed in the wild.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Fake Microsoft Teams Installers Spread Oyster Malware via Malvertising
Impact· low

Fake Microsoft Teams Installers Spread Oyster Malware via Malvertising

In September 2025, cybercriminals exploited search engine advertisements and SEO poisoning to promote fake Microsoft Teams installers, which covertly delivered the Oyster backdoor (also known as Broomstick or CleanUpLoader) onto Windows devices. By luring users—often IT administrators—to download malicious 'MSTeamsSetup.exe' files from deceptive sites like teams-install[.]top, attackers established remote control over compromised systems. The malware facilitated persistent access by installing a scheduled task and enabled command execution, lateral movement, deployment of additional payloads, and file exfiltration, posing considerable risks to corporate environments. Organizations relying on user trust in branded software searches became targets for subsequent attacks, including potential ransomware deployment. This incident underscores a growing threat: attackers increasingly abuse mainstream search engines and brand impersonation to achieve initial corporate access. As malvertising and SEO poisoning campaigns surge, organizations must prioritize user security awareness, robust endpoint threat detection, and zero trust controls to defend against evolving infostealer delivery mechanisms.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
Threat Insights: Nation-State Exploitation of Cisco ASA Zero-Days (ArcaneDoor 2025)
Impact· medium

Threat Insights: Nation-State Exploitation of Cisco ASA Zero-Days (ArcaneDoor 2025)

In September 2025, Cisco disclosed that a sophisticated nation-state threat actor, linked to the ArcaneDoor campaign, exploited multiple zero-day vulnerabilities in its Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) software. These attackers targeted government networks and critical infrastructure globally, leveraging CVE-2025-20333 and CVE-2025-20362, which enabled remote code execution, persistent malware installation, and data exfiltration. Advanced evasion tactics allowed the attackers to disrupt device logging and remain undetected for extended periods, while the deployment of custom malware such as RayInitiator and LINE VIPER provided long-term backdoor access to compromised environments. This case highlights growing trends in state-sponsored exploitation of perimeter devices and demonstrates how quickly nation-state TTPs can proliferate to broader criminal groups. The campaign triggered urgent mandates from CISA and NCSC for organizations—especially in the public sector—to patch and monitor edge infrastructure, emphasizing the escalating risk from zero-day vulnerabilities and the increasing sophistication of attacker methods.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
GoAnywhere MFT Zero-Day (CVE-2025-10035): Anatomy of a 2025 Enterprise Breach
Impact· low

GoAnywhere MFT Zero-Day (CVE-2025-10035): Anatomy of a 2025 Enterprise Breach

In September 2025, a maximum severity zero-day vulnerability (CVE-2025-10035) in Fortra’s GoAnywhere Managed File Transfer (MFT) platform was actively exploited in the wild. Attackers remotely injected commands via a deserialization flaw in the License Servlet, requiring only a forged license response signature to achieve pre-authentication remote code execution. The breach timeline reveals attackers gained access at least a week before public disclosure, establishing persistence via a backdoor admin account and deploying secondary payloads like SimpleHelp for ongoing access, with evidence of lateral movement reconnaissance. The incident underscores the increasing sophistication and rapid weaponization of zero-day exploits targeting widely used enterprise file transfer solutions. With high-profile breaches tied to vulnerabilities in GoAnywhere, pressure is mounting for organizations to reassess their exposure and incident response practices amid a sharp uptick in exploit automation and data exfiltration attacks.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Cisco Firewall Zero-Day Incident: RayInitiator & LINE VIPER Malware Exposed
Impact· low

Cisco Firewall Zero-Day Incident: RayInitiator & LINE VIPER Malware Exposed

In September 2025, Cisco ASA firewalls faced a severe cybersecurity incident when threat actors leveraged recently disclosed zero-day vulnerabilities to secretly infiltrate network perimeters. The attackers exploited these flaws to deploy two newly discovered malware strains, RayInitiator and LINE VIPER, allowing them to bypass existing defenses, maintain persistence, and exfiltrate sensitive data from affected enterprises. This highly sophisticated campaign showcased advanced persistent threat (APT) tradecraft, utilizing encrypted command-and-control traffic and lateral movement within east-west network segments, impacting organizations across multiple sectors and creating significant operational and reputational risks. This incident underscores an emergent pattern of targeting network infrastructure devices with custom malware, reflecting broader shifts in attacker strategy. As attackers increasingly refine zero-day exploitation and expand their arsenal, organizations must adapt security postures to detect and respond to threats traversing both perimeter and internal network boundaries.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
New XCSSET Variant Hits macOS: Browser Credential Theft and Clipper Risk for Developers
Impact· medium

New XCSSET Variant Hits macOS: Browser Credential Theft and Clipper Risk for Developers

In September 2025, researchers identified a sophisticated new variant of the macOS XCSSET malware, targeting Apple devices with an updated focus on browser credential theft, clipboard hijacking (clipper), and improved persistence. Initially delivered through tainted Xcode projects, the malware leveraged encrypted and obfuscated code to avoid detection, and incorporated a persistence module for sustained access. Key changes included deeper targeting of browsers like Firefox, allowing attackers to intercept credentials, exfiltrate sensitive data, and potentially escalate attacks to other platforms or accounts. The XCSSET variant’s rise mirrors broader trends in information-stealing malware exploiting developer platforms and macOS. This incident highlights growing attacker interest in macOS ecosystems, the sophistication of obfuscation techniques, and the urgent need for endpoint monitoring and microsegmentation across development environments.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Fortra GoAnywhere Zero-Day CVSS 10 Exploited Before Disclosure in 2025
Impact· low

Fortra GoAnywhere Zero-Day CVSS 10 Exploited Before Disclosure in 2025

In September 2025, a critical zero-day vulnerability (CVSS 10.0) in Fortra GoAnywhere Managed File Transfer software was actively exploited for at least a week before its public disclosure. Attackers leveraged the flaw to gain unauthorized access and potentially exfiltrate sensitive data from organizations using the platform, which is widely adopted in regulated sectors. The attack vector was weaponized rapidly by sophisticated threat groups and ransomware actors, highlighting systemic risks in third-party file transfer applications. The incident resulted in significant business disruption, data exposure, and triggered urgent patching activities across affected enterprises. This breach reflects a broader trend of adversaries increasingly targeting secure file transfer solutions via 0-day vulnerabilities, often achieving lateral movement and persistent footholds. It underscores the pressing need for proactive vulnerability management, real-time threat detection, and strong compliance practices amid rising regulatory scrutiny around data handling and supply chain exposures.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
SSL.com Certificate Abuse: Iranian APTs Sign Malware with Trusted Keys in 2024
Impact· medium

SSL.com Certificate Abuse: Iranian APTs Sign Malware with Trusted Keys in 2024

In early 2024, multiple Iranian state-linked threat groups, including the Charming Kitten offshoot Subtle Snail, leveraged code-signing certificates issued by Houston-based SSL.com to digitally sign malware campaigns targeting organizations worldwide. Researchers discovered that the threat actors abused trusted certificates to bypass security controls and distribute malicious payloads, with their primary focus on espionage and data exfiltration. This compromised trust in legitimate software distribution channels and posed significant detection challenges for defenders, underscoring the evolving sophistication of APT campaigns tied to Iran. The incident highlights an uptick in supply chain and abuse-of-trust techniques among state-sponsored groups. Attackers are increasingly capitalizing on trusted processes—such as code signing—to slip past endpoint protection platforms, raising the regulatory and operational urgency for organizations dependent on digital certificate trust.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
COLDRIVER’s 2025 ClickFix Malware Campaign: Modular APT Tactics Evolve
Impact· low

COLDRIVER’s 2025 ClickFix Malware Campaign: Modular APT Tactics Evolve

In September 2025, the Russian APT group COLDRIVER launched a multi-stage cyber campaign using newly identified malicious tools, BAITSWITCH and SIMPLEFIX, delivered through ClickFix-style phishing attacks. Zscaler ThreatLabz observed that COLDRIVER targeted Russian-speaking entities with sophisticated social engineering and credential phishing tactics, ultimately compromising victims by deploying lightweight downloaders that enable remote access and further malware deployment. Impacted organizations faced stealthed data exfiltration risks and the threat actor's evolving persistence mechanisms, signifying a leap in their operational security evasion. This incident reflects an accelerating trend of APT actors developing nimble, modular malware to bypass traditional defenses and exploit collaboration platforms. Continued adaptation in attacker tradecraft underscores the growing urgency for zero trust controls, east-west visibility, and anomaly detection across hybrid environments.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Targeted SVG Phishing Hits Ukrainian Agencies with CountLoader, PureRAT
Impact· medium

Targeted SVG Phishing Hits Ukrainian Agencies with CountLoader, PureRAT

In September 2025, cybersecurity researchers uncovered a targeted phishing campaign impersonating Ukrainian government agencies. Attackers distributed emails containing malicious SVG file attachments, crafted to deliver the CountLoader malware. Upon execution, CountLoader dropped secondary payloads—Amatera Stealer and PureMiner—allowing cybercriminals to steal sensitive information and deploy cryptomining operations on victim systems. The attacks leveraged sophisticated social engineering and file formats to evade detection, threatening both public sector and affiliated organizations. This incident highlights a surge in phishing operations leveraging advanced loaders and novel file types, such as SVG. As more attackers exploit government-themed lures and multi-tool chains, organizations face an elevated risk of data exfiltration, credential theft, and operational disruption, demanding robust, adaptive security controls.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Salesforce Agentforce 2024: ForcedLeak AI Prompt Injection Breach Exposes CRM Data
Impact· medium

Salesforce Agentforce 2024: ForcedLeak AI Prompt Injection Breach Exposes CRM Data

In June 2024, researchers at Noma Security identified a severe vulnerability in Salesforce's Agentforce AI agents, termed 'ForcedLeak'. By exploiting prompt injection via web-to-lead forms, attackers were able to manipulate Agentforce into exfiltrating sensitive CRM data, including PII, corporate secrets, and transactional details, to unauthorized locations. The vulnerability hinged on whitelist misconfigurations of trusted domains and the agent’s overly broad prompt interpretation, leading to an attacker-controlled data leak chain. Salesforce addressed data exfiltration by patching URL restrictions and acquiring an expired trusted domain but ongoing risks persist with agentic AI’s prompt processing logic. The incident underscores the growing challenges as mainstream SaaS platforms rapidly integrate autonomous GenAI features, often lacking robust input validation and security boundaries. High CVSS-scored issues like ForcedLeak exemplify the urgent need for zero trust guardrails and more resilient AI security frameworks given the increasing velocity and sophistication of prompt injection attacks.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Nation-State Attackers Exploit Cisco Zero-Day Bugs in 2024: What You Need to Know
Impact· low

Nation-State Attackers Exploit Cisco Zero-Day Bugs in 2024: What You Need to Know

In early 2024, Cisco disclosed four actively exploited zero-day vulnerabilities impacting its firewalls and IOS software, affecting millions of devices globally. At least three of these flaws were exploited by a sophisticated nation-state threat actor behind the ArcaneDoor campaign. Attackers leveraged the zero-days to gain unauthorized access to networks, facilitating lateral movement, data interception, and potentially persistent backdoors in affected systems. The campaign specifically targeted high-value government and critical infrastructure entities, prompting urgent patching initiatives. This incident underscores a growing trend of state-backed actors aggressively targeting network infrastructure with zero-day exploits. As attackers focus on networking gear as an entry point, organizations must reevaluate perimeter defenses and accelerate patch management to remain resilient against such advanced threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports