Validated Containment Architectures are here. →Explore

Industry Category

Financial Services

Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.

3695 threat reports
Page 303 of 308

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Financial Services Threat Reports

Showing 36253636 / 3695 reports
How Stark Industries Evaded EU Sanctions: The Persistence of Bulletproof Hosts in 2025
Impact· high

How Stark Industries Evaded EU Sanctions: The Persistence of Bulletproof Hosts in 2025

In May 2025, Stark Industries Solutions Ltd.—a notorious bulletproof hosting provider closely linked to Russian cyberattacks and disinformation—was placed under EU financial sanctions, alongside its Moldova-based conduits and owners. Despite these efforts, Stark rapidly rebranded as the[.]hosting, shifted its assets to new legal entities (including Dutch-based WorkTitans BV and Moldova's PQ Hosting Plus S.R.L.), and maintained operational infrastructure with covert support from providers like MIRhosting. Investigations revealed continued operations and asset management by the original threat actors, rendering the sanctions ineffective and allowing persistent delivery of DDoS campaigns, Russian-language proxy services, and malware with minimal disruption. This incident highlights the sophisticated resilience and adaptability of bulletproof hosting operations, as well as the challenges for regulators attempting to curtail nation-state-aligned cyber infrastructure. Similar evasion techniques—including cross-border asset transfers and complex corporate rebranding—are on the rise, escalating pressure on global cybersecurity, law enforcement, and compliance efforts.

7 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Inside the 2025 Salesloft Drift SaaS Supply Chain Breach: Lessons in Token Management
Impact· medium

Inside the 2025 Salesloft Drift SaaS Supply Chain Breach: Lessons in Token Management

In early 2025, a significant supply chain breach occurred when threat actor UNC6395 exploited a dormant OAuth token from a third-party Salesloft Drift integration within a Salesforce environment. Leveraging the compromised token—which bypassed MFA—the attacker launched automated connections from multiple unknown VPNs, enumerating CRM accounts and exfiltrating customer data, including embedded credentials. This enabled lateral movement, granting persistent, unauthorized access to hundreds of downstream client Salesforce instances and facilitating privilege escalation into additional systems via harvested secrets. The incident underscores an urgent trend of attackers exploiting inadequately governed third-party integrations, token sprawl, and absent monitoring. With growing SaaS adoption and rising API-driven architectures, identity-driven supply chain attacks have become top risks, accelerating regulatory scrutiny and industry demand for automated token hygiene, lifecycle management, and more rigorous third-party security postures.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Salesloft Drift OAuth Breach Compromises Salesforce: 2025 Supply Chain Attack Analysis
Impact· high

Salesloft Drift OAuth Breach Compromises Salesforce: 2025 Supply Chain Attack Analysis

In August 2025, a supply chain attack leveraging the Salesloft Drift integration was used to compromise customer Salesforce instances. Threat actors exploited compromised OAuth credentials between August 8-18, enabling them to perform automated, high-volume data exfiltration from sensitive Salesforce objects such as Account, Contact, Case, and Opportunity records. Following exfiltration, the attackers reportedly scanned acquired data for credentials and leveraged anti-forensic tactics, including deletion of query logs, to obscure their activities. Salesloft promptly revoked all relevant tokens and notified impacted customers, while security teams advised immediate credential rotations and log investigation for signs of compromise. This incident spotlights the risks associated with third-party SaaS integrations and highlights the sophistication of attackers targeting popular business platforms. As OAuth-based attacks and API exploitations become more common, organizations must enhance supply chain monitoring, review privilege access, and adopt zero trust principles to mitigate similar breaches.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
2025 Salesforce Supply Chain Breach Unveiled: UNC6040 and UNC6395’s Advanced OAuth Attacks
Impact· medium

2025 Salesforce Supply Chain Breach Unveiled: UNC6040 and UNC6395’s Advanced OAuth Attacks

In mid-2025, cybercriminal threat clusters UNC6040 and UNC6395 launched coordinated attacks targeting the Salesforce environments of major global enterprises, leveraging supply chain compromises, OAuth token abuse, and social engineering tactics. Attackers tricked employees into authorizing malicious OAuth apps or exploited stolen access tokens, enabling mass data exfiltration from Salesforce—including sensitive 'Accounts', 'Contacts', and support case records containing credentials and cloud secrets. Stolen information was subsequently used by the ShinyHunters extortion group for ransom threats and further infiltrations, impacting organizations such as Google, Cisco, Adidas, and major cybersecurity firms. This incident exemplifies a growing wave of attacks exploiting trusted third-party platforms and identity federation weaknesses to compromise cloud SaaS data at scale. The sophisticated multi-stage approach highlights urgent risks related to SaaS supply chains, the need for robust OAuth governance, and increased vigilance toward privilege escalation via indirect access vectors.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Gentlemen Ransomware Exploits Vulnerable Driver to Disable Enterprise Security (2024)
Impact· high

Gentlemen Ransomware Exploits Vulnerable Driver to Disable Enterprise Security (2024)

In early 2024, the Gentlemen ransomware group executed a sophisticated attack leveraging a vulnerable version of the ThrottleStop.sys driver to disable antivirus and endpoint detection and response (EDR) systems. By exploiting this signed but flawed driver, the attackers were able to gain kernel-level privileges, terminate security defenses, and deploy ransomware effectively across targeted organizations. The impact resulted in rapid file encryption, significant operational disruption, and increased ransom demands as incident response capabilities were bypassed. This incident highlights the growing trend of ransomware operators abusing trusted, vulnerable drivers to evade security controls. The ease with which attackers weaponize driver vulnerabilities underscores the urgent need for organizations to enhance driver and device control, patch management, and implement Zero Trust security strategies.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
SonicWall Firewalls Under Siege: Akira Ransomware Exploits CVE-2024-40766
Impact· high

SonicWall Firewalls Under Siege: Akira Ransomware Exploits CVE-2024-40766

Between July and August 2024, Akira ransomware affiliates targeted SonicWall firewall devices by exploiting CVE-2024-40766, a vulnerability in the SSL VPN protocol, combined with widespread configuration errors. Despite the availability of patches, attackers successfully accessed devices where remediation steps such as local password resets after firmware upgrades and proper multi-factor authentication (MFA) implementation were neglected. These campaigns leveraged misconfigured LDAP group permissions and compromised credentials to gain initial access, enabling Akira to steal sensitive data and encrypt systems across numerous organizations. The resulting attacks led to data theft, system downtime, and expensive ransom demands, with impacts observed globally, including within Australia. Akira’s ongoing surge illustrates the growing sophistication and persistence of ransomware groups in targeting both unpatched and improperly configured perimeter devices. This attack wave highlights the critical need for organizations to not only apply security patches promptly but to rigorously follow up with secure configuration and identity management measures to prevent operational and financial losses.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
AsyncRAT Attackers Exploit ConnectWise ScreenConnect—Credential & Crypto Theft on the Rise
Impact· low

AsyncRAT Attackers Exploit ConnectWise ScreenConnect—Credential & Crypto Theft on the Rise

In September 2025, cybersecurity researchers identified a sophisticated attack leveraging the ConnectWise ScreenConnect remote monitoring tool to deliver AsyncRAT, a potent remote access trojan. Threat actors exploited legitimate RMM infrastructure to establish unauthorized access, bypass defenses, and deploy a VBScript-based loader on victim systems. Once installed, AsyncRAT facilitated unauthorized credential harvesting and cryptocurrency theft from compromised hosts, exposing sensitive business and personal data. The campaign’s use of trusted IT management software as an initial entry vector complicated detection and posed significant risks to organizations relying on remote administration tools. This incident underscores an increasing security challenge: the abuse of legitimate remote management solutions by attackers to evade detection and propagate malware. As identity-driven and tool-based attacks surge, businesses must re-examine their controls, segmentation, and monitoring to counter exploitation of sanctioned IT utilities.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Microsoft September 2025 Patch Tuesday: Critical Vulnerabilities in Cloud, URL Security Zones, and More
Impact· medium

Microsoft September 2025 Patch Tuesday: Critical Vulnerabilities in Cloud, URL Security Zones, and More

On September 9, 2025, Microsoft released its September Patch Tuesday updates, addressing 177 vulnerabilities across its ecosystem, including 86 that impacted Microsoft products directly. Among these, 13 were rated as critical, and two had already been publicly disclosed. Notable vulnerabilities included improper URL security zone classification (CVE-2025-54107, CVE-2025-54917), which could allow attackers to bypass security features, and several remote code execution flaws affecting critical workloads. While none of these vulnerabilities were exploited before disclosure, their wide range—including issues in Azure, Office, and the Windows kernel—signals continued risk across cloud and on-premises environments. These vulnerabilities highlight evolving attacker techniques, such as zone misclassification and privilege escalation in cloud services, while underscoring the complexity of patch management in hybrid infrastructures. The scale of affected Microsoft and open-source components (like Azure Linux/Mariner) points to the growing regulatory and operational urgency for comprehensive and timely vulnerability management.

7 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Vyro AI 2024 GenAI Data Leak: Why Cyber Hygiene Can't Wait
Impact· high

Vyro AI 2024 GenAI Data Leak: Why Cyber Hygiene Can't Wait

In early 2024, Vyro AI experienced a significant data leak involving the unintentional exposure of proprietary and sensitive user data via a GenAI platform. The incident occurred when internal users, unaware of best security practices, shared confidential information with generative AI tools that did not have adequate encryption or access controls. This exposed private data to unauthorized individuals and third parties, highlighting deficiencies in the company’s data protection policies and cloud application oversight. This breach is emblematic of the growing risks associated with GenAI usage in enterprise environments, where shadow IT and user-driven data sharing can sidestep traditional security controls. As organizations adopt AI at scale, ensuring robust data governance and compliance is more critical than ever to avoid regulatory and reputational fallout.

7 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
VMScape: 2025’s Critical Hypervisor Isolation Attack Exposes Cloud Risks
Impact· medium

VMScape: 2025’s Critical Hypervisor Isolation Attack Exposes Cloud Risks

In September 2025, security researchers from ETH Zurich disclosed 'VMScape,' a sophisticated side-channel attack that breaks guest-host isolation in virtualized environments by exploiting incomplete speculative execution mitigations in modern AMD and Intel CPUs. The exploit enables a malicious guest VM to leak sensitive data, such as cryptographic keys, from the unmodified QEMU hypervisor memory, bypassing existing Spectre defenses without requiring host compromise. The attack impacts AMD Zen 1–5 and Intel Coffee Lake CPUs, allowing memory leaks at rates that threaten cloud multi-tenancy and data privacy. While VMScape requires deep technical expertise and sustained attack duration, its discovery highlights ongoing challenges in securing virtualization infrastructure against novel hardware-level threats. The incident underscores the need for prompt hardware and software mitigation deployment and a renewed focus on isolation techniques amid rising CPU vulnerability disclosures.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Ascension Health 2024: Kerberoasting Ransomware Attack Exposes Microsoft Security Risks
Impact· high

Ascension Health 2024: Kerberoasting Ransomware Attack Exposes Microsoft Security Risks

In May 2024, Ascension Health experienced a major ransomware breach, impacting over 5.6 million patient records. Attackers exploited a contractor’s click on a malicious Bing search result in Microsoft Edge, leveraging a 'Kerberoasting' attack against Microsoft Active Directory. By abusing weak and legacy RC4-encrypted Kerberos service account credentials, attackers escalated privileges and moved laterally across sensitive healthcare infrastructure, ultimately exfiltrating patient data and disrupting operations. The incident highlighted significant shortcomings in Microsoft's default security settings and communication of critical risks to enterprise customers, even after prior warnings from security experts and U.S. government officials. The breach is emblematic of a rising trend in identity-based and ransomware attacks exploiting outdated cryptographic standards across critical infrastructure sectors, especially healthcare. Regulatory and public scrutiny on vendor responsibility, ransomware defense, and secure default configurations have intensified following this high-profile compromise.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Panama Ministry of Economy Breach: INC Ransomware’s 2025 Attack Explained
Impact· high

Panama Ministry of Economy Breach: INC Ransomware’s 2025 Attack Explained

In September 2025, Panama's Ministry of Economy and Finance (MEF) announced a cyber incident after the INC Ransomware gang claimed liability for a breach. The ministry reported detecting malicious software on one workstation, activating security protocols, and asserting no core systems or sensitive data were affected. However, INC Ransom posted evidence and claimed to have exfiltrated over 1.5 TB of emails, financial, and budgeting documents from MEF. The threat actor listed MEF on its leak site and began releasing data samples, raising concerns about the extent of exposure. This incident underscores the continued evolution and impact of ransomware-as-a-service (RaaS) operations targeting government and finance sectors. With INC Ransom’s repeated high-profile attacks, the breach reflects the growing risk of sophisticated data theft and extortion campaigns confronting public sector organizations globally.

7 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports