Validated Containment Architectures are here. →Explore

Industry Category

Financial Services

Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.

3675 threat reports
Page 289 of 307

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Financial Services Threat Reports

Showing 34573468 / 3675 reports
Cisco 2025: Critical SNMP Vulnerability Actively Exploited in IOS and IOS XE
Impact· medium

Cisco 2025: Critical SNMP Vulnerability Actively Exploited in IOS and IOS XE

In September 2025, Cisco disclosed that an actively exploited vulnerability (CVE-2025-20352, CVSS 7.7) in its IOS and IOS XE software allows remote attackers to execute arbitrary code or trigger a denial-of-service (DoS) condition via specially crafted SNMP packets. The flaw, which came to light after attacker activity was observed leveraging previously compromised administrative credentials, impacts a broad range of Cisco networking equipment. The immediate impact includes risks of device takeover, network disruption, and possible lateral movement within victims’ environments. This incident underscores the criticality of securing network infrastructure against both external and internal threats, as attackers continue to exploit overlooked or unpatched vulnerabilities at the core of modern networks. The active exploitation highlights an urgent need for organizations to review segmentation, monitoring, and patch management practices in light of evolving attack techniques.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Malicious Rust Crates Infect Supply Chain, Steal Crypto Wallet Keys in 2025
Impact· high

Malicious Rust Crates Infect Supply Chain, Steal Crypto Wallet Keys in 2025

In May 2025, cybersecurity researchers identified a major supply chain attack targeting the Rust developer ecosystem. Two malicious Rust crates—faster_log and async_println—were published on the popular crates.io repository, masquerading as legitimate packages but designed to covertly exfiltrate Solana and Ethereum wallet private keys from software projects that incorporated them. The threat actors, using the aliases rustguruman and dumbnbased, achieved over 8,400 downloads, heightening the risk of cryptographic asset theft and potentially impacting both individual developers and organizations reliant on decentralized finance. This incident exemplifies the growing risks within open-source ecosystems, where attackers exploit trusted repositories to distribute malware. The trend of targeting crypto assets through developer-centric supply chain attacks highlights an urgent need for more robust vetting of third-party code and increased vigilance against evolving attacker tactics.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
DDoS Tsunami: Tech Overtakes Gaming in 2025 Attack Surge
Impact· high

DDoS Tsunami: Tech Overtakes Gaming in 2025 Attack Surge

In early 2025, a wave of Distributed Denial-of-Service (DDoS) attacks targeting the technology sector marked a significant shift in cyberattack patterns, according to Gcore's Q1–Q2 2025 Radar report. Attack volumes surged by 41% year-on-year, with the largest observed DDoS flood peaking at 2.2 Tbps—surpassing previous records set in 2024. Threat actors employed multi-layered strategies and protracted campaigns, specifically targeting technology companies with sophisticated, high-bandwidth assaults that caused operational disruptions, service outages, and reputational harm across multiple organizations. This evolution reflects attackers’ growing technical prowess and focus on critical service providers. The incident is particularly relevant as the threat landscape pivots towards the tech sector and away from previous gaming-centric targets. This trend underscores broader risks for infrastructure providers and the need for adaptive DDoS defenses in the face of escalating attack complexity and regulatory expectations.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
North Korean AkdoorTea Supply Chain Attack Hits Global Crypto Developers
Impact· low

North Korean AkdoorTea Supply Chain Attack Hits Global Crypto Developers

In September 2025, a sophisticated supply chain attack targeting the global cryptocurrency development sector was uncovered, orchestrated by North Korea-linked threat actors associated with the Contagious Interview campaign. Leveraging a newly identified backdoor named AkdoorTea—as well as tools like TsunamiKit and Tropidoor—the adversaries compromised software development environments across all major operating systems, including Windows. According to research from ESET, tracked as part of the DeceptiveDevelopment group, attackers used trojanized developer tools and social engineering tactics to infiltrate their targets and facilitate lateral movement, data theft, and potential deployment of further malware within sensitive crypto-related projects. This incident highlights the rising trend of nation-state attackers exploiting software supply chains to infiltrate innovative sectors such as cryptocurrency. It underscores the urgent need for improved east-west traffic visibility, zero trust segmentation, and threat detection controls, as organizations increasingly become targets for persistent, highly resourced adversaries.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Salesforce AI Prompt Injection Bug Exposes CRM Data in 2025 Breach
Impact· medium

Salesforce AI Prompt Injection Bug Exposes CRM Data in 2025 Breach

In September 2025, security researchers at Noma Security identified a critical vulnerability, termed ForcedLeak (CVSS 9.4), in Salesforce Agentforce, an AI-powered platform for constructing automation agents. The flaw allowed threat actors to launch indirect prompt injection attacks against Agentforce’s integration with Salesforce’s CRM, opening avenues for exfiltration of sensitive customer relationship data. The attack leveraged manipulated AI prompts that bypassed input validation, ultimately resulting in confidential business and customer information being at risk of exposure until Salesforce deployed a rapid patch. This incident highlights the growing risks stemming from AI prompt injection vulnerabilities as more enterprises embrace AI-integrated SaaS for customer-facing processes. The Salesforce episode underscores regulatory and security urgency to address trust boundaries around rapidly-evolving AI within business-critical platforms.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Vane Viper Powers 1 Trillion DNS Queries in 2025 Malvertising Mega-Breach
Impact· high

Vane Viper Powers 1 Trillion DNS Queries in 2025 Malvertising Mega-Breach

In September 2025, the threat actor group known as Vane Viper was revealed to be operating a vast and covert ad fraud and malvertising network, leveraging a staggering one trillion DNS queries to enable malware distribution globally. According to a detailed Infoblox technical report, Vane Viper manipulated core internet infrastructure using shell companies and complex ownership structures to obfuscate responsibility and perpetuate malicious adtech practices. Their operations enabled widespread malvertising campaigns, significantly impacting advertising platforms and exposing users worldwide to illicit downloads and credential theft. This breach underscores a recent surge in the use of advanced DNS tunneling and obfuscation tactics in cybercrime, particularly within ad fraud and malvertising schemes. The incident exemplifies how attackers increasingly exploit foundational internet protocols, challenging traditional detection and defense measures while prompting urgent regulatory attention and industry-wide response.

7 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Cisco ASA Zero-Day (CVE-2025-20333) Breach: Inside the CISA Emergency Response
Impact· low

Cisco ASA Zero-Day (CVE-2025-20333) Breach: Inside the CISA Emergency Response

In September 2025, Cisco disclosed a critical zero-day vulnerability (CVE-2025-20333, CVSS 9.9) affecting its Secure Firewall Adaptive Security Appliance (ASA) and Threat Defense (FTD) Software. Attackers actively exploited improper input validation in the VPN web server, enabling them to bypass authentication and potentially gain unauthorized access to sensitive environments. Cisco urged immediate patching as exploitation was observed targeting both perimeter and internal firewalls, demonstrating advanced lateral movement strategies. This exploitation prompted an emergency mitigation directive from CISA to reduce risk across U.S. federal agencies and private enterprises. This incident underscores the ongoing evolution of threat actors leveraging zero-days to target critical infrastructure firewalls, coinciding with a nationwide spike in sophisticated, identity-driven attacks. Organizations are under increasing regulatory scrutiny to patch rapidly and advance segmentation, threat monitoring, and east-west traffic controls.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Scattered Spider Ransomware: Teen Member Arrested, Group Claims Shutdown in 2024
Impact· high

Scattered Spider Ransomware: Teen Member Arrested, Group Claims Shutdown in 2024

In June 2024, law enforcement arrested a teenage member of the notorious Scattered Spider ransomware group, a cybercriminal collective linked to disruptive attacks against major organizations including MGM Resorts and Caesars Entertainment. The arrest followed claims by the group that it was shutting down operations amid heightened law enforcement scrutiny and infighting among its members. Scattered Spider became infamous for leveraging social engineering and identity-based attacks to gain initial entry, then rapidly moving laterally to deliver ransomware and conduct data theft. This latest development underscores the increasingly aggressive response from law enforcement to high-impact ransomware threats. The recent action highlights the continued evolution and volatility of ransomware groups, many of which are now using sophisticated identity compromise and cloud-based attack chains. Organizations should remain vigilant as law enforcement disruptions may cause threat actors to splinter, rebrand, or accelerate new attack campaigns using similar techniques.

7 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Webshells Hidden in .well-known Directories: The 2024 Web Application Attack Trend
Impact· medium

Webshells Hidden in .well-known Directories: The 2024 Web Application Attack Trend

In September 2024, cybersecurity researchers observed a surge in malicious actors targeting the .well-known directory on web servers to deploy PHP-based webshells. Attackers exploited this typically-overlooked directory, intended for status and authentication files, as it remains web-accessible but hidden within the Unix filesystem. Logs and honeypot data detailed repeated attempts to probe and establish footholds via .well-known and its subdirectories, such as acme-challenge and pki-validation, with the clear goal of persistent, covert remote control. This technique illustrates an evolving trend in web application attacks, where multistage threats exploit common web standards and overlooked controls. Organizations face heightened risk from such stealthy compromises, underscoring the need for continuous monitoring and adaptive defense in the current threat landscape.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Stately Taurus: 2022 Bookworm APT Campaign Unveiled in Southeast Asia
Impact· medium

Stately Taurus: 2022 Bookworm APT Campaign Unveiled in Southeast Asia

In 2022, cybersecurity researchers traced sophisticated spear-phishing attacks against government and commercial entities in Southeast Asia to Stately Taurus, a Chinese advanced persistent threat (APT) group active since at least 2012. Using the Bookworm malware, a modular remote access trojan (RAT) with advanced C2 and lateral movement capabilities, the threat actor gained initial access via tailored phishing emails, followed by persistence and data exfiltration. Detailed code analysis, shared infrastructure, unique PDB paths, and parallel tooling (e.g., ToneShell) confirmed high-confidence attribution. The campaign exposed OPSEC artifacts and overlapping infrastructure, confirming Stately Taurus’s long-term commitment to targeted espionage. This incident underscores a broader surge in targeted APT campaigns using modular malware and sophisticated infrastructure reuse. The precision of the Unit 42 Attribution Framework exemplifies the growing emphasis on multi-layered, evidence-based attribution, which is now critical as state-linked groups automate and diversify their attack techniques.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Cisco SNMP Zero-Day: Active Exploits Target IOS XE Network Devices in 2025
Impact· high

Cisco SNMP Zero-Day: Active Exploits Target IOS XE Network Devices in 2025

In September 2025, Cisco disclosed a critical vulnerability (CVE-2025-20352) affecting its IOS and IOS XE operating systems, actively exploited via the SNMP subsystem. The flaw stems from a stack-based buffer overflow that allows authenticated remote attackers to trigger denial-of-service or potentially achieve root-level remote code execution. Attackers utilized crafted SNMP packets over both IPv4 and IPv6 to compromise devices with SNMP enabled, including popular models like the Meraki MS390 and Catalyst 9300. Cisco confirmed attacks in the wild following credential compromise, urging immediate patching, as no reliable workarounds exist. This incident highlights the ongoing risks associated with ubiquitous network protocols like SNMP and the necessity of rapid response to zero-day exploits within core infrastructure. The rise of attacks targeting network management systems signals both increased attacker sophistication and heightened regulatory scrutiny.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
GitHub Notification Phishing Abuses Y Combinator Brand for Crypto Theft (2025)
Impact· high

GitHub Notification Phishing Abuses Y Combinator Brand for Crypto Theft (2025)

In September 2025, a widespread phishing campaign exploited GitHub's notification system to target software developers for cryptocurrency theft. Attackers impersonated the reputable startup accelerator Y Combinator and generated hundreds of fake issue notifications across GitHub repositories, tagging users to trigger authentic-looking emails. Victims were lured to a spoofed Y Combinator website with a subtle domain misspelling, where they were prompted to connect cryptocurrency wallets for 'verification.' Behind the scenes, obfuscated scripts authorized malicious transactions, draining wallets once users signed in. The fraudulent repositories were quickly reported and taken down, but it's unclear how many users suffered financial losses. This attack highlights the growing trend of threat actors leveraging trusted platforms for sophisticated social engineering, particularly as notification-based phishing campaigns increase and cryptocurrency remains a lucrative target. The evolving tactics underscore the urgent necessity for enhanced vigilance, technical controls, and authentication checks across digital collaboration tools.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports