Industry Category

Financial Services

Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.

4272 threat reports
Page 10 of 356

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless
Writing/Editing

Financial Services Threat Reports

Showing 109120 / 4272 reports
ShinyHunters & Helix Gangs Weaponize Passkey Themes in Microsoft 365 Attacks
Impact· HIGH

ShinyHunters & Helix Gangs Weaponize Passkey Themes in Microsoft 365 Attacks

Since May 2026, threat actors linked to ShinyHunters, Helix, and other extortion gangs have been conducting sophisticated passkey-themed phishing campaigns targeting corporate Microsoft 365 accounts. The attacks begin with extensive pre-attack reconnaissance, followed by social engineering calls impersonating IT help desks to trick employees into urgently updating passkey or MFA configurations. Victims are directed to adversary-in-the-middle phishing sites or device-code authentication flows, allowing attackers to capture credentials and session tokens. Once inside Microsoft cloud environments, attackers perform systematic reconnaissance using Microsoft Graph APIs, establish persistence through MFA method registration, and conduct automated data exfiltration from SharePoint, OneDrive, and Exchange over periods spanning hours to days while avoiding detection. The attacks demonstrate the evolving threat landscape where modern authentication methods like passkeys are weaponized as social engineering lures, highlighting the critical need for phishing-resistant MFA implementations and enhanced cloud security controls in enterprise environments.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
JFrog Artifactory Under Attack: Critical Vulnerability Chain Enables Supply Chain Compromise
Impact· HIGH

JFrog Artifactory Under Attack: Critical Vulnerability Chain Enables Supply Chain Compromise

Between August and September 2026, threat actors exploited a chain of critical vulnerabilities in JFrog Artifactory (CVE-2026-42018, CVE-2026-42016, and CVE-2026-82329) to bypass authentication and gain administrative privileges on self-hosted instances. Attackers leveraged these flaws to obtain JWT tokens for anonymous users, escalate to admin-level permissions within minutes, and deploy custom Rust-based backdoors with command-and-control capabilities. The campaign affected multiple organizations, with attackers installing malicious Groovy plugins, establishing persistence, stealing configuration data, and creating rogue administrator accounts across vulnerable infrastructure. This incident highlights the escalating sophistication of supply chain attacks targeting development infrastructure, as 49-62% of internet-accessible Artifactory instances remain vulnerable to these authentication bypass flaws, creating widespread exposure across the software development ecosystem.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
GitLab's CVSS 10.0 Vulnerability: Why DevOps Security Can't Wait
Impact· HIGH

GitLab's CVSS 10.0 Vulnerability: Why DevOps Security Can't Wait

GitLab disclosed a critical path traversal vulnerability (CVE-2026-85706) with a maximum CVSS score of 10.0, allowing unauthenticated attackers to read arbitrary files from GitLab servers through the repository commits API. The flaw affects GitLab CE and EE versions from 18.7 through 19.3.1, stemming from improper path confinement and missing authentication enforcement. Within hours of public disclosure on September 11, 2026, security researchers observed active in-the-wild exploitation attempts targeting exposed GitLab instances to extract log files, configuration data, credentials, and sensitive information. This incident highlights the accelerating timeline from vulnerability disclosure to active exploitation, particularly for DevOps platforms that house critical source code and CI/CD secrets. Following a similar pattern to the recent GitLab GraphQL injection vulnerability (CVE-2026-19478), attackers are rapidly weaponizing these flaws to compromise software supply chains and inject malicious code into build pipelines.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
How Seven Chinese AI Labs Stole 190+ Million Claude Conversations in Massive Distillation Attack
Impact· HIGH

How Seven Chinese AI Labs Stole 190+ Million Claude Conversations in Massive Distillation Attack

In September 2026, Anthropic disclosed that seven China-based AI laboratories, including Alibaba, Moonshot, DeepSeek, and others, conducted industrial-scale illicit distillation attacks against Claude AI models between February and July 2026. The attackers used networks of fake accounts created with stolen credit cards and API keys to extract over 190 million conversation exchanges, routing requests through proxy services to harvest Claude's capabilities including chain-of-thought reasoning, coding abilities, and logical reasoning functions for unauthorized training of competing models. This incident highlights the emerging threat landscape of AI model theft and intellectual property extraction, representing a new category of cybercrime where nation-state affiliated entities systematically steal proprietary AI capabilities to advance their own technological development and competitive positioning.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
UAC-0099 Deploys GuardBreaker AI Manipulation Against Ukraine
Impact· MEDIUM

UAC-0099 Deploys GuardBreaker AI Manipulation Against Ukraine

In September 2026, Russia-aligned threat group UAC-0099 deployed a novel AI manipulation technique called GuardBreaker against Ukrainian targets. The attackers embedded nuclear weapon prompts within malicious VBScript comments to trigger AI safety mechanisms and prevent automated malware analysis systems from examining their code. This represents a significant evolution in adversarial tactics, where threat actors manipulate AI defensive reasoning rather than increasing malware sophistication to achieve compromise. This incident highlights the accelerating arms race between AI-powered security tools and adversaries who exploit their limitations. With AI systems now discovering vulnerabilities at unprecedented speed and scale, traditional 90-day patch cycles are obsolete, creating an urgent need for multilayered defense strategies that don't rely solely on AI-based detection mechanisms.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
The $21 Billion AI Scam Crisis: How Artificial Intelligence Became the Ultimate Social Engineer
Impact· CRITICAL

The $21 Billion AI Scam Crisis: How Artificial Intelligence Became the Ultimate Social Engineer

AI-enabled social engineering attacks have reached unprecedented sophistication, with cybercriminals leveraging large language models to create highly personalized and emotionally manipulative scams. Research by Fred Heiding of Menlo Park Intelligence reveals that AI systems excel at human manipulation through voice cloning, long-term relationship building, and cultural context adaptation. The FBI's Internet Crime Center reports that fraud losses skyrocketed from $4 billion in 2020 to $21 billion in 2025, primarily targeting vulnerable populations including senior citizens who develop emotional dependencies on AI-powered scam bots. This asymmetric threat landscape highlights a critical security gap where traditional technical defenses prove inadequate against AI-enhanced social engineering, as human cognitive vulnerabilities cannot be patched like software systems.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
The PaperCut AI Swarm Attack: When Machines Wage Cyber Warfare
Impact· CRITICAL

The PaperCut AI Swarm Attack: When Machines Wage Cyber Warfare

In August 2026, a Russian-speaking threat actor deployed hundreds of AI agents in a coordinated swarm attack targeting PaperCut NG and MF print management software. The AI-powered campaign compromised at least 440 instances across 395 organizations in 48 countries, achieving remote code execution within four hours and Active Directory domain admin access in just six hours total. Once fully launched, the swarm compromised 11 organizations in merely 26 seconds, demonstrating unprecedented speed and scale in automated cyberattacks. This incident represents a critical inflection point where AI agents are now actively integrated across the entire cyber kill chain, from reconnaissance to exfiltration. As nation-state actors and financially motivated groups increasingly weaponize large language models and agentic AI capabilities, organizations face a new reality where attackers can execute complex, multi-stage operations at machine speed while defenders still operate at human pace.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
How Storm-3032 and Storm-3121 Are Exploiting BYOD Policies to Breach Corporate Microsoft 365
Impact· HIGH

How Storm-3032 and Storm-3121 Are Exploiting BYOD Policies to Breach Corporate Microsoft 365

Since May 2026, Microsoft researchers have tracked threat actors Storm-3032 and Storm-3121 conducting sophisticated initial access campaigns targeting corporate executives through their personal devices. The attackers use voice calls and text messages impersonating IT helpdesks to trick employees into updating authentication credentials via phishing links. Once access is gained, the threat actors exploit Microsoft Graph API to enumerate corporate resources and exfiltrate sensitive data from SharePoint, OneDrive, and Exchange before potentially selling access to extortion groups like ShinyHunters. This campaign highlights the growing trend of attackers bypassing corporate security controls by targeting the weakest link - personal devices with minimal security protections. As organizations increasingly adopt BYOD policies and hybrid work models, identity-based attacks exploiting trusted communication channels represent a critical evolution in threat actor tactics.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
GoldFactory's Android Banking Malware Exploits Work Profiles to Steal $1M from Indonesian Banks
Impact· HIGH

GoldFactory's Android Banking Malware Exploits Work Profiles to Steal $1M from Indonesian Banks

Between February and July 2026, the Chinese-speaking threat group GoldFactory deployed a sophisticated Android banking malware campaign targeting Indonesia, resulting in 1,469 compromised devices and nearly $1 million in losses. The attackers used the Gigabud banking Trojan in combination with Vwork, a modified app-cloning tool, to exploit Android's Work Profile feature. This technique allowed fraudsters to clone legitimate banking applications into isolated environments where security controls and fraud detection systems could not follow, enabling them to conduct transactions while evading detection mechanisms that were triggered in the victim's primary profile. This incident highlights the evolution of mobile banking threats as attackers increasingly target regions with high mobile payment adoption and develop novel evasion techniques that exploit legitimate enterprise security features for malicious purposes.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
How Cisco FMC Vulnerabilities Enabled Qilin Ransomware Deployment
Impact· MEDIUM

How Cisco FMC Vulnerabilities Enabled Qilin Ransomware Deployment

In September 2026, Cisco revealed that three distinct threat clusters exploited critical vulnerabilities CVE-2026-20079 and CVE-2026-20316 in Cisco Secure Firewall Management Center (FMC) systems. The attacks involved state-sponsored groups and ransomware operators who leveraged these flaws to deploy web shells, steal credentials, conduct reconnaissance, and ultimately deploy Qilin ransomware. The exploitation allowed attackers to bypass authentication, gain root access, and perform living-off-the-land techniques using legitimate FMC tools to avoid detection while moving laterally through victim networks. This incident highlights the growing trend of threat actors targeting network security infrastructure as initial access vectors, demonstrating how critical security appliances themselves become single points of failure when unpatched vulnerabilities exist.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
How UNC3569 Weaponized Trusted Software: The Sogou Input Method Supply Chain Attack
Impact· HIGH

How UNC3569 Weaponized Trusted Software: The Sogou Input Method Supply Chain Attack

In April 2026, China-linked threat group UNC3569 exploited a critical vulnerability (CVE-2026-51990) in Sogou Input Method, a widely-used Chinese character input tool with over 455 million monthly users. The attackers leveraged a crafted sgbiz: link to bypass security controls and deploy the GRAYRABBIT backdoor through an outdated Chromium browser engine with disabled sandboxing. The exploit chain utilized a 2021 V8 JavaScript engine vulnerability (CVE-2021-38003) that had been patched in Chrome but remained unaddressed in Sogou's embedded browser, allowing remote code execution with user privileges. This incident highlights the growing sophistication of supply chain attacks targeting widely-deployed software components, particularly those serving large user bases in critical regions. The exploitation of years-old vulnerabilities in embedded browsers demonstrates how legacy code in trusted applications creates persistent attack surfaces for nation-state actors.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
CISA Adds Four Critical Infrastructure Vulnerabilities to KEV Catalog
Impact· CRITICAL

CISA Adds Four Critical Infrastructure Vulnerabilities to KEV Catalog

In September 2026, CISA added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog following evidence of active exploitation in the wild. The vulnerabilities affect widely deployed enterprise infrastructure including Fortinet security appliances (CVE-2025-25249 heap-based buffer overflow), Citrix NetScaler (CVE-2026-19490 authentication bypass), Google Chromium V8 engine (CVE-2026-87491 out-of-bounds write), and Cisco Firewall Management Center (CVE-2026-20079 authentication bypass). These vulnerabilities pose significant risks as they target critical network security infrastructure and web browsers used across federal and private sector environments. This incident highlights the ongoing threat landscape where attackers systematically target network security appliances and widely-used software components to establish persistent access and bypass security controls, reflecting the continued evolution of threat actor tactics toward infrastructure-level compromises.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports