The Containment Era is here. →Explore

Industry Category

Financial Services

Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.

3560 threat reports
Page 66 of 297

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Financial Services Threat Reports

Showing 781792 / 3560 reports
BTMOB: The No-Code Android Malware Service Empowering Cybercriminals
Impact· HIGH

BTMOB: The No-Code Android Malware Service Empowering Cybercriminals

In May 2026, cybersecurity researchers identified BTMOB, an Android remote access trojan (RAT) offered as a malware-as-a-service (MaaS) platform. BTMOB provides cybercriminals with a no-code APK builder, enabling the creation of customized phishing payloads without programming expertise. The malware grants attackers extensive control over infected devices, including data exfiltration, financial transaction interception, screenshot capture, and remote operation. Distributed primarily through phishing websites impersonating legitimate services, BTMOB has been notably active in Brazil and Latin America. Its accessibility and comprehensive feature set pose a significant threat to Android users globally. The emergence of BTMOB underscores a concerning trend in the cyber threat landscape: the commoditization of sophisticated malware through MaaS platforms. This development lowers the barrier to entry for cybercriminals, facilitating the rapid proliferation of advanced threats. Organizations must remain vigilant, as the ease of deploying such malware increases the risk of widespread attacks targeting mobile devices.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Exploitation of FortiClient EMS Vulnerability Leads to Credential Theft
Impact· CRITICAL

Exploitation of FortiClient EMS Vulnerability Leads to Credential Theft

In May 2026, threat actors exploited a critical vulnerability (CVE-2026-35616) in Fortinet's FortiClient Endpoint Management Server (EMS) to deploy credential-stealing malware across managed endpoints. By abusing the trusted endpoint management infrastructure, attackers disguised the malicious payload as a legitimate Fortinet update, executing it via PowerShell. This allowed them to harvest sensitive data, including passwords and autofill details from web browsers, and exfiltrate the information to attacker-controlled servers. The exploitation of this vulnerability underscores the risks associated with unpatched management systems and the potential for widespread compromise through centralized infrastructure. Organizations are urged to apply the latest patches and review endpoint management configurations to mitigate such threats.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Critical Gogs RCE Vulnerability Discovered in 2026
Impact· CRITICAL

Critical Gogs RCE Vulnerability Discovered in 2026

In May 2026, a critical remote code execution (RCE) vulnerability was identified in Gogs, an open-source self-hosted Git service. This flaw allows authenticated users to execute arbitrary code on the server by creating a pull request with a malicious branch name that injects the --exec flag into git rebase during the 'Rebase before merging' operation. The vulnerability, rated 9.4 on the CVSS scale, does not require administrative privileges or interaction with other users, making exploitation straightforward for any registered user. ([thehackernews.com](https://thehackernews.com/2026/05/critical-gogs-rce-vulnerability-lets.html?utm_source=openai)) The discovery of this vulnerability underscores the ongoing risks associated with self-hosted development tools. Organizations relying on Gogs should promptly implement recommended mitigations, such as restricting user registration and repository creation, to prevent potential exploitation. ([thehackernews.com](https://thehackernews.com/2026/05/critical-gogs-rce-vulnerability-lets.html?utm_source=openai))

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Silent Ransom Group's In-Person Data Theft Tactics Target Law Firms
Impact· HIGH

Silent Ransom Group's In-Person Data Theft Tactics Target Law Firms

In May 2026, the FBI issued a warning about the Silent Ransom Group (SRG), a Russia-linked extortion gang targeting U.S. law firms. SRG employs sophisticated social engineering tactics, including impersonating IT support staff via phone calls and phishing emails to gain remote access. When these methods fail, they escalate to in-person visits, where operatives physically infiltrate offices, connect external storage devices to computers, and exfiltrate sensitive client data. This data is then used to extort firms, with threats to publish or sell the information if ransoms are not paid. ([techtimes.com](https://www.techtimes.com/articles/317293/20260527/silent-ransom-group-sends-operatives-law-firm-offices-38-firms-already-leaked.htm?utm_source=openai)) This incident underscores a concerning evolution in cybercriminal tactics, blending traditional cyber attacks with physical intrusion. The legal sector's sensitive data makes it a prime target, highlighting the urgent need for robust security protocols, employee training, and vigilance against both digital and physical social engineering threats.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
BTMOB RAT: A New Android Malware-as-a-Service Threat
Impact· HIGH

BTMOB RAT: A New Android Malware-as-a-Service Threat

In May 2026, cybersecurity researchers identified BTMOB, an Android Remote Access Trojan (RAT), actively targeting users in Brazil and Latin America. Distributed through phishing campaigns that mimic legitimate services, BTMOB is sold as a malware-as-a-service (MaaS), allowing attackers to create malicious apps without coding expertise. Once installed, it exploits Android's Accessibility Services to gain elevated permissions, enabling data exfiltration, screen capture, and full remote control of infected devices. This comprehensive access poses significant risks, including financial theft and privacy breaches. The emergence of BTMOB underscores a growing trend in the commoditization of sophisticated malware, lowering the barrier for cybercriminals and expanding the threat landscape. Its MaaS model facilitates rapid adaptation and distribution, making it a formidable challenge for cybersecurity defenses worldwide.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
JINX-0164's Sophisticated Attack on Cryptocurrency Firms
Impact· HIGH

JINX-0164's Sophisticated Attack on Cryptocurrency Firms

In mid-2025, a previously unidentified threat actor, JINX-0164, initiated a campaign targeting cryptocurrency organizations. Utilizing sophisticated social engineering tactics, the attackers posed as recruiters on LinkedIn, inviting victims to virtual meetings on counterfeit domains resembling legitimate teleconference services. During these meetings, victims were deceived into downloading a malicious file disguised as a meeting client, leading to the installation of a Python-based macOS malware named AUDIOFIX. This malware harvested sensitive data, including credentials from password managers, web browsers, and cryptocurrency wallet extensions, and facilitated lateral movement within the organizations' development infrastructure. ([thehackernews.com](https://thehackernews.com/2026/05/jinx-0164-targets-cryptocurrency-firms.html?utm_source=openai)) The campaign's relevance persists due to the increasing sophistication of social engineering attacks targeting the cryptocurrency sector. The use of custom macOS malware and the focus on compromising development pipelines underscore the evolving tactics of financially motivated threat actors. Organizations must remain vigilant against such multifaceted attacks to safeguard their digital assets. ([thehackernews.com](https://thehackernews.com/2026/05/jinx-0164-targets-cryptocurrency-firms.html?utm_source=openai))

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Microsoft Addresses Risks of Uncoordinated Zero-Day Disclosures
Impact· HIGH

Microsoft Addresses Risks of Uncoordinated Zero-Day Disclosures

In May 2026, security researcher Chaotic Eclipse publicly disclosed multiple zero-day vulnerabilities affecting Windows components such as Defender and BitLocker. These disclosures were made without prior notification to Microsoft, leading to active exploitation of vulnerabilities like BlueHammer (CVE-2026-33825), RedSun (CVE-2026-41091), and UnDefend (CVE-2026-45498). Microsoft criticized this uncoordinated approach, emphasizing the risks posed to customers and advocating for Coordinated Vulnerability Disclosure (CVD) to allow vendors time to address issues before public release. This incident underscores the ongoing tension between independent security researchers and software vendors regarding disclosure practices. The rapid exploitation of these vulnerabilities highlights the critical need for timely and coordinated communication to mitigate risks and protect end-users effectively.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Akira Ransomware 2026 Attack: Lessons for Mid-Sized Organizations
Impact· CRITICAL

Akira Ransomware 2026 Attack: Lessons for Mid-Sized Organizations

In May 2026, a mid-sized organization fell victim to an Akira ransomware attack. The intrusion began with the exploitation of a forgotten local VPN account lacking multi-factor authentication, allowing attackers to gain initial access. Subsequently, they conducted network reconnaissance, escalated privileges, and moved laterally across systems. The attackers exfiltrated sensitive data before deploying ransomware to encrypt files, culminating in a ransom demand. This incident underscores the critical need for robust access controls and vigilant monitoring of network activities to prevent such breaches. The Akira ransomware group has demonstrated a rapid escalation in attack sophistication and frequency, particularly targeting organizations with vulnerable VPN configurations. Their ability to swiftly transition from initial access to full data encryption within hours highlights the urgency for organizations to implement comprehensive cybersecurity measures, including timely patching, multi-factor authentication, and continuous network monitoring.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Zapier Vulnerabilities Exposed: Potential Account Takeover Risks
Impact· MEDIUM

Zapier Vulnerabilities Exposed: Potential Account Takeover Risks

In May 2026, security researchers from Token Security identified a chain of five vulnerabilities within Zapier, a widely-used workflow automation service. Exploiting these flaws required only a free Zapier account and could have allowed attackers to impersonate any signed-in user, potentially accessing millions of user accounts and their connected applications. The attack vector involved manipulating user-generated code, retrieving discarded login credentials, and accessing internal storage systems containing private software images. One such image included a publishing key for code running in every logged-in user's browser, enabling attackers to create or alter automations and interact with connected services as legitimate users. ([cyberscoop.com](https://cyberscoop.com/zapier-bug-chain-account-takeover-patched/?utm_source=openai)) This incident underscores the critical importance of securing automation platforms, especially as they gain increased authority to act on behalf of users across multiple services. The vulnerabilities were promptly reported and patched, with no evidence of exploitation. However, organizations are advised to review their automation logs for unauthorized activities and reauthorize connections to sensitive systems to mitigate potential risks. ([cyberscoop.com](https://cyberscoop.com/zapier-bug-chain-account-takeover-patched/?utm_source=openai))

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
CISA Mandates Urgent Patching of LiteSpeed cPanel Plugin Vulnerability CVE-2026-48172
Impact· CRITICAL

CISA Mandates Urgent Patching of LiteSpeed cPanel Plugin Vulnerability CVE-2026-48172

In May 2026, a critical privilege escalation vulnerability, CVE-2026-48172, was discovered in the LiteSpeed User-End cPanel Plugin versions 2.3 through 2.4.4. This flaw allows unauthenticated remote attackers to execute arbitrary scripts with root privileges by exploiting the 'lsws.redisAble' function, which mishandles Redis enable/disable features. The vulnerability has been actively exploited in the wild, leading to full system compromises on affected servers. LiteSpeed released urgent security updates to address the issue, urging users to update to version 2.4.5 or later. ([sentinelone.com](https://www.sentinelone.com/vulnerability-database/cve-2026-48172/?utm_source=openai)) The exploitation of CVE-2026-48172 underscores the critical importance of timely patch management and the need for robust privilege assignment mechanisms in web hosting environments. The incident highlights the potential risks associated with shared hosting platforms, where a single compromised account can lead to server-wide breaches. Organizations are advised to prioritize the implementation of security patches and to conduct thorough audits of their systems to prevent similar vulnerabilities from being exploited.

2 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
FBI Issues Warning on Silent Ransom Group's In-Person Data Theft Tactics
Impact· HIGH

FBI Issues Warning on Silent Ransom Group's In-Person Data Theft Tactics

In May 2026, the FBI issued a warning about the Silent Ransom Group (SRG), an extortion gang targeting U.S. law firms through sophisticated social engineering tactics. SRG actors impersonate IT support personnel via phone calls and phishing emails to gain remote access to victim computers. If these attempts fail, they escalate their efforts by sending individuals in person to the victim's location to physically access computers and exfiltrate sensitive data using external storage devices. The stolen data is then used to extort victims, with threats to sell or publicly disclose the information if ransom demands are not met. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/fbi-warns-of-silent-ransom-group-in-person-data-theft-attacks/?utm_source=openai)) This incident underscores a concerning evolution in cybercriminal tactics, blending traditional phishing with physical infiltration to bypass digital defenses. The legal sector, known for handling highly sensitive information, is particularly vulnerable to such targeted attacks. Organizations must enhance their security protocols, including employee training on social engineering, strict access controls, and monitoring for unauthorized physical access, to mitigate the risks posed by such multifaceted threats.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Glassworm Botnet Disrupted After Resilient C2 Infrastructure Takedown
Impact· HIGH

Glassworm Botnet Disrupted After Resilient C2 Infrastructure Takedown

In May 2026, a coordinated operation by CrowdStrike, Google, and The Shadowserver Foundation successfully disrupted the Glassworm botnet, which had been targeting software developers through the open-source supply chain since October 2025. The botnet employed resilient command-and-control (C2) infrastructure utilizing Solana blockchain transactions, BitTorrent Distributed Hash Table (DHT), Google Calendar events, and traditional virtual private servers (VPS). This sophisticated architecture enabled Glassworm to persistently deliver malicious payloads, compromising over 300 GitHub repositories and numerous npm packages, thereby posing significant risks to software supply chains. The takedown underscores a critical shift in cyber threats, with adversaries increasingly focusing on developers to infiltrate and compromise software supply chains. This incident highlights the necessity for enhanced security measures within development environments and the importance of safeguarding open-source ecosystems against such sophisticated attacks.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports