Validated Containment Architectures are here. →Explore

Industry Category

Financial Services

Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.

3675 threat reports
Page 290 of 307

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Financial Services Threat Reports

Showing 34693480 / 3675 reports
PyPI Phishing Attack Exposes Open-Source Supply Chain in 2025
Impact· high

PyPI Phishing Attack Exposes Open-Source Supply Chain in 2025

In September 2025, the Python Package Index (PyPI) suffered a targeted supply-chain phishing campaign, where threat actors impersonated PyPI via convincing emails and domain lookalikes (such as pypi-mirror.org). Attackers sent phishing emails to PyPI maintainers, warning of account suspension and requesting email verification. Unsuspecting victims who followed malicious links and entered credentials risked account compromise, enabling attackers to breach legitimate developer accounts. The likely aim was to either infect existing packages with malware or introduce new malicious packages into trusted software repositories, potentially impacting the broader Python ecosystem. This incident underscores the growing sophistication of software supply-chain threats, especially as open-source repositories face sustained phishing campaigns and credential harvesting tactics. As phishing campaigns increasingly target developers and critical infrastructure, strong phishing-resistant authentication and vigilant domain monitoring are now essential industry-wide defenses.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Obscura Ransomware 2025: What Enterprises Must Learn About Active Directory Attacks
Impact· high

Obscura Ransomware 2025: What Enterprises Must Learn About Active Directory Attacks

In late August 2025, a newly discovered ransomware variant named Obscura was identified executing across several hosts within an enterprise network. The attack leveraged the organization's Active Directory infrastructure, using the NETLOGON share to automatically deploy a Go-based ransomware binary across all domain controllers and affected endpoints. The attackers created malicious scheduled tasks for persistent execution and attempted to enable remote desktop for potential lateral movement. The ransomware also attempted to disable endpoint recovery options, and the ransom note indicated both data encryption and exfiltration of sensitive company information. Limited security agent coverage hampered detection and response, amplifying the operational disruption and risk of sensitive data exposure. This incident underscores the evolving sophistication of ransomware actors in targeting critical authentication infrastructure and automated deployment mechanisms. As attackers increasingly combine data theft with operational disruption and target identity systems, organizations face heightened regulatory, financial, and reputational risks, warranting renewed focus on segmentation, visibility, and endpoint security.

7 months ago

Kill Chain

IC
Initial Compromise(low)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Interpol's 2024 Crackdown: $439 Million Seized from Global Cybercrime Networks
Impact· medium

Interpol's 2024 Crackdown: $439 Million Seized from Global Cybercrime Networks

In 2024, Interpol coordinated a global operation targeting cybercrime rings responsible for large-scale financial crimes. Over a period of five months, law enforcement agencies from 61 countries worked together to investigate and disrupt online scams that included business email compromise (BEC), investment fraud, romance scams, and e-commerce fraud. The operation resulted in the seizure of more than $439 million in cash and cryptocurrency, exposing elaborate money laundering networks and identifying approximately 1,300 suspects linked to cyber-enabled financial crime groups. Thousands of victims worldwide were impacted by these schemes. This incident highlights the growing sophistication and international reach of financially motivated cybercrime, as well as the increasingly effective law enforcement collaborations to disrupt illicit networks. The operation reflects a heightened urgency for organizations to strengthen controls against online fraud and cyber-enabled theft, as attackers continually evolve their tactics.

7 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Unpatched SMS Flaw in OnePlus Phones Leaves User Messages Exposed
Impact· medium

Unpatched SMS Flaw in OnePlus Phones Leaves User Messages Exposed

In September 2025, a critical, still-unpatched vulnerability (CVE-2025-10184) was publicly disclosed in OnePlus smartphones running OxygenOS 12 through 15. Discovered by Rapid7, the flaw enables any installed app—without explicit permissions or user input—to access and exfiltrate SMS content and metadata on affected devices. This exposure was caused by insecurely exported content providers in the custom Android Telephony package, allowing SQL injection-style inference attacks. Despite multiple disclosure attempts, OnePlus did not respond for over four months; the details, including a proof of concept, were disclosed publicly to accelerate a fix. The case underscores rising risks from insecure mobile customizations and vendor slow response, especially as attackers increasingly exploit flaws in widely deployed consumer devices. With the proliferation of mobile-centric attacks and regulatory scrutiny on data privacy, this breach highlights the urgent need for robust patch management and proactive mobile security.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Cisco's 2025 SNMP Zero-Day: Credential Compromise Drives Network Device Exploit Surge
Impact· high

Cisco's 2025 SNMP Zero-Day: Credential Compromise Drives Network Device Exploit Surge

In September 2025, Cisco disclosed a high-severity zero-day vulnerability (CVE-2025-20352) affecting IOS and IOS XE network infrastructure devices. The flaw, a stack-based buffer overflow in the SNMP subsystem, allowed remote, authenticated attackers with low privileges to cause denial-of-service and, in some cases, permitted high-privileged attackers to fully compromise devices. Exploitation was detected after local administrator credentials were stolen, enabling threat actors to send malicious SNMP packets over IPv4/IPv6, impacting unpatched devices globally. Immediate patching was recommended as no workarounds existed except tightly restricting SNMP access. This incident underscores the criticality of timely patching and robust identity and network access controls, as attackers increasingly target network infrastructure via both credential compromise and protocol-level vulnerabilities. Industry-wide, it marks an escalating trend of high-impact, infrastructure-level exploits requiring urgent coordinated response.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(high)
Read Report
Attackers Leverage Pandoc SSRF Vulnerability CVE-2025-51591 to Breach AWS IMDS
Impact· low

Attackers Leverage Pandoc SSRF Vulnerability CVE-2025-51591 to Breach AWS IMDS

In September 2025, threat actors exploited a newly disclosed Server-Side Request Forgery (SSRF) vulnerability in the open-source Linux utility Pandoc (CVE-2025-51591), targeting Amazon Web Services (AWS) cloud environments. The attackers leveraged the flaw to send unauthorized requests to the AWS Instance Metadata Service (IMDS), allowing them to obtain EC2 role credentials and elevate cloud permissions. Security researchers, including Wiz, observed active exploitation in the wild, leading to unauthorized access and potential data exfiltration from affected AWS infrastructure. Organizations relying on Pandoc as part of their cloud automation workflows face heightened risk of credential compromise and lateral movement across accounts. This incident underscores a fast-evolving cloud threat landscape, where attackers exploit supply-chain and open-source vulnerabilities to traverse trusted infrastructure and target sensitive identity and metadata services. The rapid weaponization of CVE-2025-51591 mirrors the broader trend of SSRF attacks on cloud metadata, driving urgent calls for proactive detection, segmentation, and credential management in multi-cloud environments.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
State-Sponsored Actors Breach Libraesva ESG via Command Injection Vulnerability
Impact· low

State-Sponsored Actors Breach Libraesva ESG via Command Injection Vulnerability

In September 2025, Libraesva disclosed a command injection vulnerability (CVE-2025-59689, CVSS 6.1) affecting its Email Security Gateway (ESG) platform, which was actively exploited by state-sponsored threat actors. Attackers leveraged maliciously-crafted email payloads to trigger remote command execution, bypassing ESG protections and potentially gaining persistent access to targeted networks. The intrusion method allowed attackers to move laterally and exfiltrate sensitive data, underscoring the risks posed by the exploitation of security appliances themselves. Libraesva released emergency patches and urged customers to upgrade immediately, as evidence emerged of ongoing targeted campaigns against critical sectors. This incident highlights the increasing use of email gateway exploits by sophisticated adversaries, aligning with a wider trend of targeting security infrastructure for initial access. With command injection flaws on the rise and ransomware operators adopting similar approaches, organizations face escalating pressure to rapidly patch vulnerabilities and reinforce segmentation and anomaly detection across their environments.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
YiBackdoor: A Sophisticated Backdoor Malware Campaign Bridging IcedID and Latrodectus
Impact· low

YiBackdoor: A Sophisticated Backdoor Malware Campaign Bridging IcedID and Latrodectus

In June 2025, researchers discovered YiBackdoor, a novel malware family exhibiting significant source code overlaps with the notorious IcedID and Latrodectus strains. Campaigns leveraging YiBackdoor execute advanced backdoor techniques that establish remote access, command execution, and data exfiltration within compromised environments. YiBackdoor is typically deployed as part of a multi-stage attack campaign, using phishing or malicious attachments as its primary entry vector. Its detection signaled the emergence of new collaborative threats between criminal malware groups, raising concerns over increased code sharing and tool evolution. This incident highlights growing technical sophistication and cross-pollination between established malware actors. The use of YiBackdoor in conjunction with IcedID and Latrodectus demonstrates adversary agility and the accelerated pace of malware innovation, elevating the threat to enterprises reliant on traditional detection models.

7 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Iframe Security Exposed: The 2025 Rise of Payment Skimmer Attacks
Impact· high

Iframe Security Exposed: The 2025 Rise of Payment Skimmer Attacks

In September 2025, a widespread web application attack exploited payment iframes across major online retailers to deploy advanced payment skimmer malware. Attackers leveraged vulnerabilities in embedded iframe components on e-commerce checkout pages, bypassing client-side security controls and web isolation policies to secretly harvest customer credit card data. The campaign remained undetected for weeks, affecting thousands of transactions globally and prompting emergency mitigation efforts, reputational impact, and regulatory scrutiny for affected organizations. This incident highlights the urgent need for stronger web application and iframe security, as payment skimming through novel overlay techniques continues to surge. Organizations are under increased regulatory pressure to harden PCI compliance and prevent supply chain-driven client-side attacks.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Wondershare RepairIt Vulnerabilities in 2025 Expose User Data and AI Models
Impact· medium

Critical Wondershare RepairIt Vulnerabilities in 2025 Expose User Data and AI Models

In September 2025, security researchers from Trend Micro uncovered two critical vulnerabilities in Wondershare RepairIt, a leading file repair software. Identified as CVE-2025-10643 (authentication bypass, CVSS 9.1) and a second AI model tampering flaw, these vulnerabilities allowed unauthorized attackers to access sensitive user information and potentially manipulate embedded AI models. Exploitation could be achieved over unencrypted traffic routes, making lateral movement and data exfiltration easier for adversaries. The flaws highlighted the growing risks associated with AI-driven software and the increased attack surface presented by supply chain exposures. This incident underscores the urgency of securing both traditional application logic and the growing use of embedded AI models. Adversaries are increasingly targeting AI supply chains and exploiting weak east-west segmentation controls, a pattern observed in several recent breaches. Regulatory scrutiny and customer expectations around data protection continue to mount.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
How a Single Weak Password Caused the Collapse of KNP Logistics
Impact· high

How a Single Weak Password Caused the Collapse of KNP Logistics

In August 2023, KNP Logistics Group—one of the UK’s oldest haulage companies—fell victim to a catastrophic ransomware attack after cybercriminals exploited a weak, reused password to gain initial access. The attackers leveraged this compromised credential to breach internal systems, move laterally, and deploy ransomware, severely encrypting business-critical data. Operations halted, hundreds of employees were affected, and the incident ultimately forced the 158-year-old business into administration, marking a rare instance where a cyberattack directly led to company collapse. This breach exemplifies a growing wave of highly disruptive ransomware attacks exploiting basic identity and password hygiene gaps. As threat actors increasingly target legacy industries and critical infrastructure with credential-based intrusions, the risk to business continuity is escalating—pressing organizations to reevaluate access controls and cyber resilience.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Steganography Strikes: npm Supply Chain Breach Hides Malware in JavaScript Package (2024)
Impact· medium

Steganography Strikes: npm Supply Chain Breach Hides Malware in JavaScript Package (2024)

In June 2024, a malicious npm JavaScript package was discovered masquerading as a utility library while covertly deploying a credential-stealing malware. Attackers cleverly embedded the malicious payload using steganography by hiding harmful code within QR code images bundled in the package. Once installed by developers, the malware extracted sensitive credentials and communicated with attacker-controlled infrastructure, posing a significant risk to any organization that unknowingly integrated the tainted dependency in its software supply chain. This incident underscores the mounting threat posed by highly obfuscated, supply chain attacks leveraging trusted open-source platforms. The attack highlights the emergence of sophisticated malware delivery via unconventional vectors such as steganographic encoding within common file formats. With broad software ecosystem dependencies and rapid code adoption, organizations face increasing urgency to vet third-party packages and enforce robust supply chain security controls.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports