✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
Multilingual Phishing: FileFix Variant Delivers StealC Infostealer in 2025
In September 2025, security researchers identified a sophisticated phishing campaign delivering a new variant of the StealC information-stealer malware via a convincing, multilingual phishing website impersonating popular brands such as Facebook Security. The attackers leveraged advanced social engineering tactics, widespread language support, heavy anti-analysis measures, and advanced obfuscation to successfully bypass traditional security detections. The campaign’s initial access was achieved through social engineering, leading victims to download malicious payloads disguised as legitimate files, which, once executed, exfiltrated credentials and sensitive data at scale. This incident highlights an ongoing surge in multilingual, highly tailored phishing approaches that utilize advanced anti-detection techniques, making detection and mitigation more difficult. Organizations face mounting pressure to strengthen controls against information stealers as attackers adapt proven TTPs to bypass endpoint protection and target a global victim base.
7 months ago
Kill Chain
Chaos Mesh Critical GraphQL Flaws Put Kubernetes Clusters at Risk in 2025
In September 2025, multiple critical vulnerabilities were discovered in Chaos Mesh, a popular cloud-native chaos engineering platform, exposing Kubernetes clusters to remote code execution (RCE) via unauthenticated GraphQL endpoints. Attackers with minimal in-cluster network access could exploit these flaws to execute arbitrary code, trigger disruptive fault injections (such as pod deletion and network outages), and ultimately achieve full cluster takeover. The vulnerability stemmed from insufficient access controls and improper GraphQL API handling, allowing adversaries to escalate privileges and compromise cluster workloads. As a result, organizations relying on Chaos Mesh in production faced heightened risk to workload integrity and business continuity until patches were applied. This breach highlights the increasing threat to supply-chain components in cloud-native environments, where tools with high privileges can inadvertently expose entire clusters. The rapid disclosure and fix cycle signals a need for strict RBAC, vigilant monitoring, and timely patching as attacker focus shifts towards exploiting platform-level risks.
7 months ago
Kill Chain
Microsoft & Cloudflare Dismantle RaccoonO365 Global Phishing Network (2025)
In September 2025, Microsoft’s Digital Crimes Unit (DCU), in partnership with Cloudflare, coordinated a global takedown of the RaccoonO365 phishing network. The PhaaS operation leveraged 338 domains to deliver convincing Microsoft 365 phishing campaigns, compromising over 5,000 credentials across 94 countries since July 2024. By obtaining a court order from the Southern District of New York, DCU seized infrastructure used by the financially motivated RaccoonO365 group, disrupting ongoing credential theft and reducing further business email compromise (BEC) risk to organizations worldwide. This incident underscores the rapid evolution and global scale of phishing-as-a-service networks, which are automating credential theft across cloud platforms. As attackers exploit trusted SaaS brands with commodity toolkits, vigilance around cloud identity and supply chain access is now a critical board-level concern.
7 months ago
Kill Chain
Scattered Spider Returns: New Wave of Social Engineering Attacks on Financial Services
In late 2025, cybersecurity researchers at ReliaQuest linked a new wave of attacks in the financial services sector to the notorious cybercrime collective Scattered Spider, despite previous claims that the group had disbanded. These attacks featured advanced social engineering tactics, the registration of lookalike domains, and exploitation of internal access paths to facilitate credential compromise and lateral movement inside targeted organizations. Impact resulted in unauthorized access to sensitive financial data, disruption of key operations, and raised concerns about the sector’s preparedness for sophisticated, identity-driven threats. The re-emergence of Scattered Spider underscores a resurgence of high-profile, financially motivated cybercrime against critical industries. The campaign highlights the evolving threat landscape—where even 'retired' threat groups rapidly adapt their tactics—reinforcing the urgency of east-west security monitoring, identity protections, and robust zero trust strategies.
7 months ago
Kill Chain
DOJ Resentences BreachForums Founder in 2025 Cybercrime Marketplace Crackdown
In September 2025, the U.S. Department of Justice resentenced Conor Brian Fitzpatrick—known online as Pompompurin and the former administrator of the notorious BreachForums cybercrime marketplace—to three years in prison. Fitzpatrick pleaded guilty after orchestrating access device fraud and facilitating the sale of stolen data, in addition to possessing child sexual abuse material (CSAM). BreachForums had become a major platform for trading compromised credentials, payment card information, and illicit content before law enforcement seized the site and apprehended its leader. The takedown disrupted a key meeting ground for cybercriminals involved in massive data breaches and identity theft operations. This incident underlines heightened law enforcement focus on cybercrime forums as hubs for illegal commerce, reflecting rising pressure on both administrators and users. The prosecution of BreachForums’ founder highlights regulatory and investigative trends aimed at deterring similar platforms and enforcing accountability for cyber-enabled offenses.
7 months ago
Kill Chain
TA558 Leverages AI-Generated Scripts to Deploy Venom RAT in 2025 Brazilian Hotel Attacks
In the summer of 2025, the threat actor group TA558 launched a series of targeted phishing campaigns against hotels and the hospitality sector in Brazil and other Spanish-speaking regions. Leveraging AI-generated scripts, TA558 distributed Remote Access Trojans (RAT) such as Venom RAT via malicious email attachments disguised as business invoices. The attackers gained unauthorized access to hotel infrastructure, enabling surveillance, data theft, and lateral movement within targeted environments. Kaspersky researchers attributed the activity to the RevengeHotels cluster and noted reliance on sophisticated social engineering and automation. This incident exemplifies the rising integration of AI in cyberattacks, increasing the efficacy and resilience of threat actors like TA558. Organizations in hospitality and other sectors with valuable customer data face growing risks from AI-driven malware and must adapt their defenses to faster-evolving adversarial techniques.
7 months ago
Kill Chain
Chinese TA415 Breaches US Economic Policy Experts Using VS Code Remote Tunnels
In mid-2025, the China-aligned threat actor TA415 launched a sophisticated spear-phishing campaign targeting U.S. government agencies, economic policy think tanks, and academic organizations. The attackers leveraged social engineering tactics, masquerading as high-profile U.S. officials, and delivered phishing emails containing malicious links. Through these lures, TA415 exploited Visual Studio Code Remote Tunnels—a legitimate feature used for remote development—to establish persistent, covert remote access within target environments. This allowed them to conduct extended espionage operations, exfiltrate sensitive economic policy data, and evade traditional endpoint and network defenses. The attack highlights the convergence of advanced phishing techniques with legitimate remote access tools, underscoring a shift toward stealthy, “living off the land” tactics by nation-state adversaries. Organizations are urged to address internal monitoring, east-west security, and robust detection of unauthorized remote connectivity, as similar techniques are expected to proliferate across sectors.
7 months ago
Kill Chain
ChillyHell: The macOS Backdoor That Outsmarted Notarization in 2024
In early May 2024, security researchers from Jamf Threat Labs identified a new version of the previously dormant "ChillyHell" modular backdoor targeting macOS systems. Initially observed in attacks against Ukrainian officials in 2021 and reported again by Mandiant in 2023, ChillyHell resurfaced in a sample uploaded to VirusTotal and discovered to have been publicly hosted on Dropbox. The malware achieves persistence through multiple mechanisms, brute-forces passwords, exfiltrates sensitive data, and communicates over several protocols, all while leveraging Apple notarization to evade detection before its certificates were revoked. With built-in timestamp manipulation and extensive C2 capabilities, ChillyHell poses a significant risk to macOS enterprise environments, blending stealth, flexibility, and longevity in its operations. This incident underscores the growing sophistication and targeting of macOS platforms by advanced threat actors, moving beyond Windows-centric malware trends. The use of valid codesigning and notarization further demonstrates challenges for defenders, highlighting the need for robust detection controls and ongoing vigilance for notarized—but malicious—macOS software.
7 months ago
Kill Chain
Chinese Hackers Impersonate US Congressman in Sophisticated 2024 Spear-Phishing Campaign
In early 2024, Chinese state-sponsored hackers allegedly orchestrated spear-phishing attacks by impersonating Michigan Congressman John Moolenaar. The threat actors crafted convincing emails designed to gain the trust of recipients, targeting government and private sector individuals. Using tailored messaging, the adversaries sought to trick victims into engaging with malicious links or attachments, potentially enabling credential theft, malware installation, or further lateral movement within targeted organizations. The incident demonstrates the growing sophistication and persistence of social engineering tactics deployed by advanced persistent threat (APT) groups with strategic intelligence-gathering objectives. This attack reflects a broader rise in politically themed spear-phishing campaigns leveraging impersonation of public officials to increase credibility. Organizations must remain alert as nation-state groups continually evolve their tactics, conducting highly targeted attacks that bypass technical safeguards and prey on human vulnerabilities.
7 months ago
Kill Chain
AI-Enhanced Malware: How EvilAI’s Stealth Attacks Redefined Cyber Threats in 2024
In early 2024, cybersecurity researchers identified a widespread campaign leveraging 'EvilAI'—a threat actor embedding artificial intelligence into seemingly legitimate productivity apps to deliver advanced malware. These AI-backed tools enable the malware to evade traditional antivirus detection, utilizing encrypted traffic and adaptive, stealthy behavior to propagate across organizational networks. The primary attack vectors were phishing emails and malicious downloads, which provided initial access before lateral movement was observed within compromised environments. As a result, hundreds of companies worldwide suffered business disruptions, data theft, and increased recovery costs from incident response efforts. This incident highlights the escalating sophistication of malware campaigns driven by artificial intelligence. The fusion of classic malware tactics with AI-enabled evasion makes traditional security controls less effective, underlining the urgency for organizations to adopt advanced, behavior-based defenses and prioritize zero trust architectures to mitigate evolving threats.
7 months ago
Kill Chain
CERT-FR Uncovers Advanced Apple Spyware Exploitation in 2024
In June 2024, a CERT-FR advisory revealed the exploitation of a zero-day vulnerability within Apple operating systems, alleged to be leveraged in targeted spyware attacks against select individuals. Discovered after reports of 'sophisticated' exploitation, the flaw allowed attackers to covertly gain access to devices, harvest sensitive data, and monitor communications by bypassing security defenses. Attackers deployed advanced tactics to deliver the payload, focusing on high-profile victims with a history of surveillance targeting. Apple has since released security updates to address the vulnerability, but the impact underscores persistent risks to user privacy and national security. This incident is particularly relevant amid a surge in zero-day exploitation by sophisticated threat actors, highlighting the elevated risks posed by commercial spyware and surveillance tools. It also reinforces regulatory and enterprise urgency to enhance detection, patch management, and mobile endpoint security strategies.
7 months ago
Kill Chain
FBI Alert: UNC6040 & UNC6395 Target Salesforce Customers with Cloud Attacks (2024)
In early 2024, the FBI’s Internet Crime Complaint Center (IC3) issued an alert detailing active campaigns by threat groups UNC6040 and UNC6395 targeting Salesforce customer environments. The attackers leveraged phishing and social engineering to obtain valid Salesforce credentials, subsequently exploiting misconfigurations and inadequate security controls in customer cloud instances. This enabled unauthorized access to sensitive data, including customer information and corporate records, leading to multiple data theft and extortion attempts. Salesforce itself was not breached, but its customers suffered direct operational impacts due to data compromise and disruption. This incident underscores a rising trend of advanced threat actors targeting supply chain and SaaS ecosystems, exploiting both human and technical gaps in cloud security. As cloud adoption accelerates, enterprises must address credential hygiene, proper configuration, and real-time anomaly detection to thwart similar attacks.
7 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports