The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Financial Services

Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.

4320 threat reports
Page 185 of 360

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Financial Services Threat Reports

Showing 22092220 / 4320 reports
Fortinet FortiClient EMS Vulnerability: Immediate Action Required
Impact· CRITICAL

Fortinet FortiClient EMS Vulnerability: Immediate Action Required

In April 2026, Fortinet disclosed a critical vulnerability (CVE-2026-35616) in its FortiClient Endpoint Management Server (EMS) versions 7.4.5 and 7.4.6. This improper access control flaw allows unauthenticated attackers to execute unauthorized code or commands via crafted requests. The vulnerability has been actively exploited in the wild, prompting Fortinet to release emergency hotfixes and advise customers to update to version 7.4.7. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/04/04/forticlient-ems-zero-day-cve-2026-35616/?utm_source=openai)) The rapid exploitation of CVE-2026-35616 underscores the increasing trend of attackers targeting endpoint management solutions to gain unauthorized access and control over enterprise networks. Organizations must prioritize timely patching and robust access controls to mitigate such risks.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Phishing Campaigns Exploit Open Redirects in 2026
Impact· MEDIUM

Phishing Campaigns Exploit Open Redirects in 2026

In early 2026, multiple phishing campaigns exploited open redirect vulnerabilities in trusted domains to deceive users into visiting malicious websites. Attackers crafted URLs that appeared legitimate by leveraging open redirects in services like Google Meet and Microsoft OAuth, effectively bypassing traditional email and browser security measures. This technique led to increased instances of credential theft and malware distribution, particularly targeting government and public-sector organizations. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/03/02/oauth-redirection-abuse-enables-phishing-malware-delivery/?utm_source=openai)) The prevalence of these attacks underscores the critical need for organizations to identify and remediate open redirect vulnerabilities within their web applications. As threat actors continue to refine their methods, maintaining robust security protocols and user awareness is essential to mitigate the risks associated with such sophisticated phishing tactics.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
React2Shell 2025: Credential Theft Campaign Exploiting CVE-2025-55182
Impact· CRITICAL

React2Shell 2025: Credential Theft Campaign Exploiting CVE-2025-55182

In December 2025, a critical vulnerability known as React2Shell (CVE-2025-55182) was disclosed, affecting React Server Components in versions 19.0.0 through 19.2.0. This flaw allowed unauthenticated remote code execution, enabling attackers to execute arbitrary JavaScript code on vulnerable servers. Exploiting this vulnerability, threat actors initiated a large-scale campaign targeting Next.js applications, compromising at least 766 hosts across various cloud providers. The attackers utilized an automated framework named NEXUS Listener to harvest sensitive data, including database credentials, SSH private keys, API keys, cloud tokens, and environment secrets. The operation was attributed to a threat cluster tracked as UAT-10608. ([articles.uvnetware.com](https://articles.uvnetware.com/news/react2shell-cve-2025-55182/?utm_source=openai)) The React2Shell incident underscores the critical importance of promptly addressing server-side vulnerabilities in widely used frameworks. The rapid exploitation by sophisticated threat actors highlights the need for organizations to implement robust security measures, including timely patching, comprehensive monitoring, and adherence to secure coding practices to mitigate the risk of similar attacks.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Fortinet FortiClient EMS Vulnerability CVE-2026-35616: Immediate Action Required
Impact· CRITICAL

Fortinet FortiClient EMS Vulnerability CVE-2026-35616: Immediate Action Required

In April 2026, Fortinet disclosed a critical vulnerability (CVE-2026-35616) in its FortiClient Enterprise Management Server (EMS) versions 7.4.5 and 7.4.6. This improper access control flaw allows unauthenticated attackers to execute arbitrary code or commands via specially crafted requests. The vulnerability was actively exploited in the wild, prompting Fortinet to release emergency patches and advise immediate application of hotfixes or upgrading to version 7.4.7 upon its release. This incident underscores the persistent threat posed by zero-day vulnerabilities and the importance of timely patch management. Organizations are reminded to maintain robust security practices, including regular software updates and monitoring for unauthorized activities, to mitigate risks associated with such critical flaws.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Beware: QR Code Phishing Scams Targeting Drivers in 2026
Impact· MEDIUM

Beware: QR Code Phishing Scams Targeting Drivers in 2026

In early 2026, a sophisticated phishing campaign emerged across multiple U.S. states, including New York, California, and Texas. Scammers sent fraudulent text messages impersonating state courts, alleging recipients had outstanding traffic violations. These messages included images of fake court notices embedded with QR codes, urging immediate payment of fines to avoid severe penalties. Scanning the QR codes redirected victims to phishing websites designed to steal personal and financial information. This method, known as 'quishing' (QR code phishing), represents an evolution in cybercriminal tactics, leveraging QR codes to bypass traditional security measures and exploit the trust users place in official-looking communications. The widespread nature of this scam underscores the need for heightened vigilance and public awareness regarding unsolicited messages containing QR codes.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Fortinet FortiClient EMS Vulnerability CVE-2026-35616: Immediate Action Required
Impact· CRITICAL

Fortinet FortiClient EMS Vulnerability CVE-2026-35616: Immediate Action Required

In early April 2026, Fortinet disclosed a critical vulnerability (CVE-2026-35616) in its FortiClient Endpoint Management Server (EMS) versions 7.4.5 and 7.4.6. This improper access control flaw allows unauthenticated attackers to execute unauthorized code or commands via crafted requests, effectively bypassing API authentication and authorization mechanisms. The vulnerability has been actively exploited in the wild, prompting Fortinet to release out-of-band hotfixes and advise customers to upgrade to version 7.4.7 upon its release. ([thehackernews.com](https://thehackernews.com/2026/04/fortinet-patches-actively-exploited-cve.html?utm_source=openai)) The exploitation of CVE-2026-35616 underscores a growing trend of attackers targeting management interfaces to gain elevated privileges within enterprise environments. This incident highlights the critical need for organizations to promptly apply security patches and maintain vigilant monitoring of their network infrastructure to mitigate potential breaches.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
36 Malicious npm Packages Exploited Redis, PostgreSQL to Deploy Persistent Implants
Impact· CRITICAL

36 Malicious npm Packages Exploited Redis, PostgreSQL to Deploy Persistent Implants

In April 2026, cybersecurity researchers identified 36 malicious npm packages masquerading as Strapi CMS plugins. These packages exploited Redis and PostgreSQL databases to deploy reverse shells, harvest credentials, and establish persistent implants. The malicious code was embedded within the postinstall script hook, executing upon installation without user interaction, thereby compromising systems with root access in CI/CD environments and Docker containers. The attackers utilized various payloads, including remote code execution via Redis, Docker container escapes, and credential harvesting, indicating a sophisticated and evolving threat. This incident underscores the escalating risks associated with software supply chain attacks, particularly within open-source ecosystems. The attackers' ability to infiltrate widely-used package repositories highlights the urgent need for enhanced security measures in software development pipelines. Organizations are advised to audit their dependencies, implement strict access controls, and monitor for anomalous activities to mitigate such threats.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Drift Protocol's $285 Million Loss: A Wake-Up Call for Crypto Security
Impact· CRITICAL

Drift Protocol's $285 Million Loss: A Wake-Up Call for Crypto Security

On April 1, 2026, Drift Protocol, a Solana-based decentralized exchange, suffered a significant security breach resulting in the theft of approximately $285 million in various cryptocurrencies. The attackers employed a sophisticated social engineering campaign over six months, culminating in the compromise of administrative controls through the exploitation of durable nonces. This allowed them to manipulate governance mechanisms and execute unauthorized transactions, leading to substantial financial losses and operational disruption for Drift Protocol. This incident underscores the escalating threat posed by state-sponsored cyber actors, particularly those from the Democratic People's Republic of Korea (DPRK), who have increasingly targeted the cryptocurrency sector to fund national programs. The attack highlights the critical need for robust operational security measures, including stringent access controls and vigilant monitoring of administrative activities, to mitigate the risks associated with social engineering and insider threats.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
LinkedIn's 2026 Browser Extension Scanning: A Privacy Wake-Up Call
Impact· MEDIUM

LinkedIn's 2026 Browser Extension Scanning: A Privacy Wake-Up Call

In April 2026, reports emerged that LinkedIn was injecting hidden JavaScript into user sessions to scan for over 6,000 installed Chrome extensions and collect detailed device data. This practice, termed 'BrowserGate,' raised significant privacy concerns as it linked extension data to identifiable user profiles, potentially exposing sensitive personal and corporate information. LinkedIn acknowledged the scanning but stated it was intended to detect extensions that violate their terms of service by scraping data without consent. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/linkedin-secretly-scans-for-6-000-plus-chrome-extensions-collects-data/?utm_source=openai)) This incident underscores the growing scrutiny over corporate data collection practices and the balance between platform security and user privacy. It highlights the need for transparency in how user data is gathered and utilized, especially as similar fingerprinting techniques have been employed by other companies in the past. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/linkedin-secretly-scans-for-6-000-plus-chrome-extensions-collects-data/?utm_source=openai))

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Understanding the 2026 Surge in Device Code Phishing Attacks
Impact· HIGH

Understanding the 2026 Surge in Device Code Phishing Attacks

In early 2026, device code phishing attacks exploiting the OAuth 2.0 Device Authorization Grant flow surged by over 37 times. Attackers initiated device authorization requests to service providers, obtained codes, and deceived victims into entering these codes on legitimate login pages, thereby granting unauthorized access to their accounts. This method, originally designed for devices lacking standard input options, was co-opted by cybercriminals to bypass traditional authentication mechanisms. The proliferation of phishing-as-a-service kits, notably EvilTokens, has significantly contributed to the widespread adoption of this technique, enabling even low-skilled attackers to execute sophisticated phishing campaigns. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/device-code-phishing-attacks-surge-37x-as-new-kits-spread-online/?utm_source=openai)) The rapid escalation of device code phishing underscores a critical shift in cyberattack strategies, emphasizing the need for organizations to reassess and fortify their authentication processes. The commoditization of such attack methods through services like EvilTokens highlights the urgency for enhanced security measures and user education to mitigate the risks associated with these evolving threats.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Drift Protocol's $280 Million Loss: A Case Study in Advanced Cyber Attacks
Impact· CRITICAL

Drift Protocol's $280 Million Loss: A Case Study in Advanced Cyber Attacks

In April 2026, Drift Protocol, a decentralized finance platform on the Solana blockchain, suffered a significant security breach resulting in the loss of approximately $280 million. The attackers employed a sophisticated strategy involving durable nonce accounts and pre-signed transactions to gain unauthorized administrative control over Drift's Security Council. This method allowed them to execute malicious transactions at a predetermined time, effectively transferring control and draining funds from the platform. Notably, the breach did not exploit any vulnerabilities in Drift's smart contracts or programs, and no seed phrases were compromised. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/drift-loses-280-million-north-korean-hackers-seize-security-council-powers/?utm_source=openai)) This incident underscores the evolving tactics of cybercriminals targeting the cryptocurrency sector, particularly the use of social engineering and advanced transaction manipulation techniques. The attribution to North Korean state-sponsored actors highlights the persistent threat posed by nation-state cyber operations in the digital asset space. Organizations must remain vigilant and enhance their security protocols to mitigate such sophisticated attacks.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Surge in Multi-Extortion Ransomware Attacks in 2026
Impact· HIGH

Surge in Multi-Extortion Ransomware Attacks in 2026

In early 2026, the University of Mississippi Medical Center (UMMC) and payment processing network BridgePay were severely impacted by multi-extortion ransomware attacks. UMMC's Epic electronic health record system was taken offline across 35 clinics and over 200 telehealth sites, leading to the cancellation of critical medical procedures. Similarly, BridgePay's services were disrupted, affecting numerous financial transactions. These incidents underscore the escalating threat posed by ransomware groups employing double and triple extortion tactics, which involve encrypting data, exfiltrating sensitive information, and threatening public disclosure to pressure victims into paying ransoms. The increasing sophistication of these attacks highlights the urgent need for organizations to implement robust data encryption and access control measures to protect sensitive information and ensure rapid recovery in the event of a breach.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports