The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Financial Services

Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.

4309 threat reports
Page 213 of 360

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Financial Services Threat Reports

Showing 25452556 / 4309 reports
HungerRush Faces 2026 Customer Data Extortion Threat
Impact· HIGH

HungerRush Faces 2026 Customer Data Extortion Threat

In early March 2026, customers of restaurants utilizing the HungerRush point-of-sale (POS) platform reported receiving extortion emails from a threat actor. The emails warned that both restaurant and customer data would be exposed if HungerRush did not comply with the attacker's demands. HungerRush, a provider of restaurant technology solutions, serves over 16,000 establishments, including notable chains like Sbarro and Jet's Pizza. The attacker initiated the campaign by sending emails from support@hungerrush.com, urging the company to address the extortion threats to prevent potential data exposure. This incident underscores the evolving tactics of cybercriminals, who are now directly targeting end-users to pressure service providers. The approach not only threatens customer trust but also highlights the critical need for robust cybersecurity measures and rapid incident response protocols within the restaurant technology sector.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
FBI Dismantles LeakBase Cybercrime Forum in Coordinated International Operation
Impact· HIGH

FBI Dismantles LeakBase Cybercrime Forum in Coordinated International Operation

In early March 2026, the FBI, in collaboration with international law enforcement agencies, dismantled LeakBase, a major cybercriminal forum with over 142,000 members. LeakBase facilitated the trade of stolen data and hacking tools, hosting an extensive archive of compromised databases containing hundreds of millions of account credentials. The coordinated operation, known as 'Operation Leak,' involved synchronized actions across 14 countries, including domain seizures, arrests, and evidence collection. This takedown underscores the escalating global efforts to combat cybercrime networks and disrupt platforms that enable the proliferation of stolen data and cyberattack tools. The seizure of LeakBase serves as a stark warning to cybercriminals about the increasing reach and effectiveness of international law enforcement collaborations.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Coruna iOS Exploit Kit: A 2025 Cybersecurity Threat Analysis
Impact· HIGH

Coruna iOS Exploit Kit: A 2025 Cybersecurity Threat Analysis

In 2025, the Coruna iOS exploit kit emerged as a sophisticated tool targeting iPhone users across multiple campaigns. Initially identified in February 2025, it was deployed by a surveillance vendor's customer. By summer, the same exploit kit was utilized by the Russian espionage group UNC6353 in watering hole attacks on Ukrainian websites. Later in the year, the financially motivated Chinese threat actor UNC6691 employed Coruna to compromise fake Chinese gambling and cryptocurrency sites. The kit comprises 23 exploits forming five full exploit chains, affecting iOS versions 13.0 through 17.2.1. These exploits enable remote code execution, sandbox escapes, and kernel privilege escalation, leading to unauthorized access and data exfiltration. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/spyware-grade-coruna-ios-exploit-kit-now-used-in-crypto-theft-attacks/?utm_source=openai)) The proliferation of Coruna underscores a concerning trend: advanced exploit kits, possibly originating from state-sponsored entities, are increasingly accessible to a broader range of threat actors. This shift highlights the urgent need for organizations to stay vigilant, update their systems promptly, and implement robust security measures to mitigate the risks posed by such sophisticated tools. ([wired.com](https://www.wired.com/story/coruna-iphone-hacking-toolkit-us-government/?utm_source=openai))

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Cisco Firewall Vulnerabilities Disclosed in 2026
Impact· CRITICAL

Critical Cisco Firewall Vulnerabilities Disclosed in 2026

In March 2026, Cisco disclosed two critical vulnerabilities in its Secure Firewall Management Center (FMC) software: an authentication bypass flaw (CVE-2026-20079) and a remote code execution (RCE) vulnerability (CVE-2026-20131). Both vulnerabilities allow unauthenticated, remote attackers to gain root access to affected devices. CVE-2026-20079 enables attackers to execute scripts and commands by sending crafted HTTP requests, while CVE-2026-20131 allows execution of arbitrary Java code through crafted serialized Java objects. These flaws affect both on-premises FMC installations and Cisco's Security Cloud Control (SCC) Firewall Management. Cisco has released patches to address these issues and recommends immediate updates to mitigate potential risks. ([sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh?utm_source=openai)) The disclosure of these vulnerabilities underscores the ongoing challenges in securing network management interfaces. Organizations are urged to review their security postures, especially concerning remote access and authentication mechanisms, to prevent potential exploitation of similar flaws in the future.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
LastPass Users Targeted in Sophisticated Phishing Attack
Impact· HIGH

LastPass Users Targeted in Sophisticated Phishing Attack

In early March 2026, LastPass users were targeted by a sophisticated phishing campaign. Attackers sent emails impersonating LastPass support, claiming unauthorized attempts to change users' account email addresses. These emails included links labeled 'report suspicious activity' and 'disconnect and lock vault,' directing recipients to a counterfeit LastPass login page designed to harvest credentials. The phishing emails often appeared as forwarded internal conversations to create a sense of urgency and legitimacy. LastPass confirmed that their systems remained uncompromised and emphasized that they would never request users' master passwords via email. This incident underscores the evolving tactics of cybercriminals who exploit trust in established brands to deceive users. The use of realistic email threads and urgent security alerts highlights the need for continuous vigilance and user education to recognize and resist such social engineering attacks.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Critical Unauthenticated Command Injection Vulnerability in VMware Aria Operations
Impact· HIGH

Critical Unauthenticated Command Injection Vulnerability in VMware Aria Operations

In February 2026, a critical command injection vulnerability (CVE-2026-22719) was identified in VMware Aria Operations, allowing unauthenticated attackers to execute arbitrary commands during support-assisted product migrations. This flaw, with a CVSS score of 8.1, could lead to remote code execution, potentially compromising the entire system. Broadcom released patches to address this issue, but reports indicate active exploitation in the wild. ([thehackernews.com](https://thehackernews.com/2026/03/cisa-adds-actively-exploited-vmware.html?utm_source=openai)) The inclusion of CVE-2026-22719 in CISA's Known Exploited Vulnerabilities catalog underscores the urgency for organizations to apply the provided patches promptly. Delayed remediation increases the risk of unauthorized access and system compromise, especially during migration processes. ([securityweek.com](https://www.securityweek.com/vmware-aria-operations-vulnerability-exploited-in-the-wild/?utm_source=openai))

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
2025 Mobile Malware Surge: Key Threats and Protective Measures
Impact· HIGH

2025 Mobile Malware Surge: Key Threats and Protective Measures

In 2025, Kaspersky's analysis revealed a significant surge in mobile malware attacks, with over 14 million incidents involving malicious, advertising, or unwanted software targeting mobile devices. Notably, adware constituted 62% of these detections, while the number of new Trojan banker installation packages for Android escalated to 255,090, marking a 271% increase from the previous year. This sharp rise underscores the growing profitability of such attacks for cybercriminals. ([kaspersky.com](https://www.kaspersky.com/about/press-releases/the-number-of-trojan-banker-attacks-on-smartphones-increased-by-56-in-2025?utm_source=openai)) The proliferation of preinstalled backdoors like Triada and Keenadu, embedded during device manufacturing, presents a formidable challenge, granting attackers extensive control over compromised devices. Additionally, the emergence of the Kimwolf IoT botnet, which exploits Android TV boxes for DDoS attacks and as reverse proxies, highlights the expanding threat landscape. These developments necessitate heightened vigilance and robust security measures to safeguard mobile users. ([kaspersky.com](https://www.kaspersky.com/about/press-releases/the-number-of-trojan-banker-attacks-on-smartphones-increased-by-56-in-2025?utm_source=openai))

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Malicious Laravel Packages Deploy PHP RAT
Impact· HIGH

Malicious Laravel Packages Deploy PHP RAT

In March 2026, cybersecurity researchers identified malicious PHP packages on Packagist, masquerading as Laravel utilities, which deployed a cross-platform remote access trojan (RAT) functional on Windows, macOS, and Linux systems. The packages—nhattuanbl/lara-helper, nhattuanbl/simple-queue, and nhattuanbl/lara-swagger—were published by the user 'nhattuanbl' and contained obfuscated code that, once installed, connected to a command-and-control server, granting attackers full remote access to compromised hosts. This access allowed for execution of shell commands, file manipulation, and system reconnaissance, posing significant security risks to affected applications. ([thehackernews.com](https://thehackernews.com/2026/03/fake-laravel-packages-on-packagist.html?utm_source=openai)) This incident underscores the growing threat of supply chain attacks targeting open-source ecosystems. Developers are urged to exercise caution when incorporating third-party packages, especially from less-known sources, and to implement rigorous security audits to detect and mitigate such vulnerabilities.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Surge in Hacktivist DDoS Attacks Amid Middle East Tensions
Impact· HIGH

Surge in Hacktivist DDoS Attacks Amid Middle East Tensions

Between February 28 and March 2, 2026, a surge of 149 hacktivist-driven distributed denial-of-service (DDoS) attacks targeted 110 organizations across 16 countries. This wave of cyber assaults was primarily in response to the U.S.-Israel coordinated military campaign against Iran, codenamed Epic Fury and Roaring Lion. The attacks predominantly focused on government entities, financial institutions, and telecommunications sectors, with the majority occurring in the Middle East, particularly in Kuwait, Israel, and Jordan. Notably, two hacktivist groups, Keymous+ and DieNet, were responsible for nearly 70% of the attack activity during this period. ([thehackernews.com](https://thehackernews.com/2026/03/149-hacktivist-ddos-attacks-hit-110.html?utm_source=openai)) This incident underscores the escalating trend of cyber retaliation in geopolitical conflicts, highlighting the need for organizations to bolster their cybersecurity defenses against ideologically motivated threat actors. The concentrated nature of these attacks emphasizes the importance of proactive threat intelligence and robust incident response strategies to mitigate potential disruptions to critical infrastructure and services.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Understanding the Coruna iOS Exploit Kit: Implications and Protections
Impact· HIGH

Understanding the Coruna iOS Exploit Kit: Implications and Protections

In early 2026, Google’s Threat Intelligence Group identified 'Coruna,' a sophisticated iOS exploit kit targeting devices running iOS versions 13.0 through 17.2.1. The kit comprises five full exploit chains utilizing 23 vulnerabilities, enabling attackers to execute remote code and escalate privileges. Initially observed in February 2025 within a surveillance vendor's operations, Coruna was subsequently employed by Russian espionage groups in mid-2025 and later by financially motivated Chinese cybercriminals by December 2025. The exploit kit facilitates the deployment of malware capable of exfiltrating sensitive data, including cryptocurrency wallets and personal information. ([thehackernews.com](https://thehackernews.com/2026/03/coruna-ios-exploit-kit-uses-23-exploits.html?utm_source=openai)) The emergence of Coruna underscores a concerning trend where advanced cyber tools, potentially developed by nation-states, proliferate into the hands of various threat actors. This incident highlights the critical need for organizations and individuals to maintain up-to-date software and implement robust security measures to mitigate the risks posed by such sophisticated exploits. ([techcrunch.com](https://techcrunch.com/2026/03/03/a-suite-of-government-hacking-tools-targeting-iphones-is-now-being-used-by-cybercriminals/?utm_source=openai))

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Iranian Cyber Retaliation in March 2026: A Wake-Up Call for Critical Infrastructure Security
Impact· HIGH

Iranian Cyber Retaliation in March 2026: A Wake-Up Call for Critical Infrastructure Security

In March 2026, following coordinated US-Israeli military strikes on Iran, Iranian state-sponsored cyber actors launched retaliatory cyber operations targeting critical infrastructure across the Middle East and the United States. These operations included Distributed Denial-of-Service (DDoS) attacks, phishing campaigns, and attempts to compromise surveillance systems. Notably, a malicious replica of the Israeli Home Front Command's RedAlert application was distributed to deliver surveillance malware, and internet-connected surveillance cameras in multiple countries were targeted to support operational planning and battle damage assessment. ([unit42.paloaltonetworks.com](https://unit42.paloaltonetworks.com/iranian-cyberattacks-2026/?utm_source=openai)) The escalation underscores the persistent cyber threat posed by Iranian actors, who have demonstrated the capability to exploit geopolitical tensions to conduct disruptive cyber activities. Organizations, especially those in critical infrastructure sectors, should remain vigilant and enhance their cybersecurity measures to mitigate potential risks associated with such state-sponsored cyber operations.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Understanding the 2026 Google Workspace OAuth Attack
Impact· HIGH

Understanding the 2026 Google Workspace OAuth Attack

In March 2026, a sophisticated phishing campaign exploited OAuth redirection mechanisms to compromise Google Workspace accounts. Attackers crafted malicious OAuth applications that, when users attempted to authenticate, redirected them from trusted identity providers to attacker-controlled sites, leading to malware downloads. This method allowed adversaries to bypass traditional phishing defenses by leveraging legitimate authentication flows. The incident underscores the evolving tactics of threat actors who exploit standard protocol behaviors to gain unauthorized access, highlighting the need for organizations to implement stringent OAuth governance and cross-domain detection strategies.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports