The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
AI-Assisted Cyber Attack Compromises 600+ FortiGate Devices in 2026
Between January 11 and February 18, 2026, a Russian-speaking, financially motivated threat actor exploited exposed management ports and weak credentials to compromise over 600 FortiGate devices across 55 countries. Utilizing commercial generative AI tools, the attacker automated scanning for vulnerable devices and executed authentication attempts, leading to unauthorized access and potential data exfiltration. This incident underscores the growing trend of cybercriminals leveraging AI to scale operations, enabling even low-skilled actors to conduct widespread attacks. Organizations must prioritize securing management interfaces, enforcing strong authentication mechanisms, and monitoring for unauthorized access to mitigate such threats.
7 months ago
Kill Chain
Starkiller Phishing Kit: A New Era of MFA Bypass Attacks
In February 2026, cybersecurity researchers uncovered 'Starkiller,' a sophisticated phishing-as-a-service platform developed by the cybercrime group Jinkusu. Unlike traditional phishing kits that use static replicas of login pages, Starkiller employs a headless Chrome browser within a Docker container to proxy live login pages of targeted brands such as Microsoft, Google, and Apple. This method allows attackers to capture user credentials, including multi-factor authentication (MFA) codes, in real-time by acting as a man-in-the-middle between the victim and the legitimate site. The platform offers features like keylogging, session token theft, geo-tracking, and real-time session monitoring, all accessible through an intuitive dashboard that lowers the technical barrier for cybercriminals. ([krebsonsecurity.com](https://krebsonsecurity.com/2026/02/starkiller-phishing-service-proxies-real-login-pages-mfa/?utm_source=openai)) The emergence of Starkiller signifies a significant escalation in phishing tactics, reflecting a broader trend toward commoditized, enterprise-style cybercrime tooling. Its ability to bypass MFA protections and its user-friendly interface make it a potent tool for attackers, necessitating a shift in defensive strategies toward behavioral detection and identity-aware analysis to effectively counter such advanced threats. ([darkreading.com](https://www.darkreading.com/threat-intelligence/starkiller-phishing-kit-mfa?utm_source=openai))
7 months ago
Kill Chain
React2Shell Exploitation 2025: A Wake-Up Call for Web Security
In December 2025, a critical vulnerability known as React2Shell (CVE-2025-55182) was disclosed in React Server Components, affecting versions 19.0 through 19.2.0. This flaw allowed unauthenticated remote code execution via crafted HTTP requests. Within hours of disclosure, state-sponsored threat actors, including Chinese groups Earth Lamia and Jackpot Panda, as well as North Korean operatives, began exploiting the vulnerability to deploy malware, establish persistent backdoors, and conduct cyber-espionage activities. The widespread use of React in web applications amplified the impact, leading to numerous system compromises across various sectors. ([aws.amazon.com](https://aws.amazon.com/blogs/security/china-nexus-cyber-threat-groups-rapidly-exploit-react2shell-vulnerability-cve-2025-55182/?utm_source=openai)) The rapid exploitation of React2Shell underscores the increasing speed at which threat actors weaponize newly disclosed vulnerabilities. Organizations are urged to prioritize timely patching and enhance monitoring to mitigate risks associated with such critical flaws.
7 months ago
Kill Chain
AI-Powered Cyberattack Compromises Hundreds of FortiGate Devices Globally
Between January 11 and February 18, 2026, a Russian-speaking, financially motivated threat actor leveraged commercial generative AI services to compromise over 600 FortiGate devices across more than 55 countries. The attackers exploited exposed management ports and weak, single-factor authentication credentials, without utilizing any known FortiGate vulnerabilities. This campaign enabled the threat actor to extract full device configurations, including credentials and network topology information, facilitating further post-exploitation activities such as Active Directory compromise and credential harvesting. ([aws.amazon.com](https://aws.amazon.com/blogs/security/ai-augmented-threat-actor-accesses-fortigate-devices-at-scale/?utm_source=openai)) This incident underscores the evolving threat landscape where AI tools lower the technical barrier for cybercriminals, allowing even those with limited skills to execute large-scale attacks. Organizations must prioritize fundamental security measures, including securing management interfaces, enforcing strong authentication protocols, and maintaining vigilant monitoring to detect and respond to such AI-augmented threats.
7 months ago
Kill Chain
Roundcube 2025 Remote Code Execution Vulnerability
In June 2025, a critical vulnerability (CVE-2025-49113) was identified in Roundcube Webmail versions prior to 1.5.10 and 1.6.11. This flaw allowed authenticated users to execute arbitrary code on the server due to improper validation of the '_from' parameter in the 'upload.php' script, leading to PHP object deserialization. Exploitation of this vulnerability could result in complete server compromise, unauthorized access to sensitive email data, and potential lateral movement within the network. ([feedly.com](https://feedly.com/cve/CVE-2025-49113?utm_source=openai)) The discovery of this vulnerability underscores the importance of rigorous input validation and prompt patch management. Organizations using affected versions of Roundcube Webmail are urged to upgrade to the latest versions to mitigate potential exploitation risks.
7 months ago
Kill Chain
FBI Reports Surge in ATM Jackpotting Attacks in 2025
In 2025, the FBI reported a significant surge in ATM 'jackpotting' attacks across the United States, with over 700 incidents leading to more than $20 million in losses. These attacks involve cybercriminals exploiting physical and software vulnerabilities in ATMs to deploy malware, such as Ploutus, which forces machines to dispense cash without legitimate transactions. Attackers often gain access using generic keys to open ATM panels, then install malware that manipulates the ATM's operating system to execute unauthorized cash withdrawals. ([techcrunch.com](https://techcrunch.com/2026/02/19/fbi-says-atm-jackpotting-attacks-are-on-the-rise-and-netting-hackers-millions-in-stolen-cash/?utm_source=openai)) This trend underscores the evolving tactics of cybercriminals who blend physical intrusion with sophisticated malware to exploit financial systems. The rise in such attacks highlights the urgent need for financial institutions to enhance ATM security measures, including updating software, implementing robust physical security protocols, and educating staff on emerging threats to prevent substantial financial losses and maintain customer trust.
7 months ago
Kill Chain
North Korean IT Workers Exploit Remote Work to Infiltrate U.S. Companies in 2025
In 2025, U.S. authorities uncovered a sophisticated scheme where North Korean IT workers, using stolen or fabricated identities, secured remote positions within over 300 U.S. companies. These operatives, often based in China and Russia, infiltrated organizations by posing as legitimate American employees, thereby accessing sensitive corporate data and systems. The illicit earnings, estimated at over $88 million, were funneled back to North Korea to support its weapons programs. ([forbes.com](https://www.forbes.com/sites/alonzomartinez/2025/04/25/north-korean-hackers-pose-as-remote-workers-to-infiltrate-us-firms/?utm_source=openai)) This incident underscores the escalating threat of nation-state actors exploiting remote work vulnerabilities to bypass traditional security measures. The use of advanced tactics, including AI-generated profiles and deepfake technologies, highlights the need for enhanced identity verification processes and continuous monitoring of remote access points to safeguard organizational assets. ([fortune.com](https://fortune.com/2025/08/04/north-korean-it-worker-infiltrations-exploded/?utm_source=openai))
7 months ago
Kill Chain
PayPal's 2025 Data Breach: A Cautionary Tale in Financial Data Security
In 2025, PayPal experienced a significant data breach due to a code change in its Working Capital application, which inadvertently exposed sensitive customer information, including Social Security numbers and dates of birth, for nearly six months. The breach was discovered on December 12, 2025, but had been active since July 1, 2025. Approximately 100 customers were affected by this incident. ([cybernews.com](https://cybernews.com/security/paypal-six-month-breach-ssn-working-capital-app/?utm_source=openai)) This incident underscores the critical importance of rigorous code review processes and robust access controls in financial applications. The prolonged exposure period highlights the necessity for continuous monitoring and rapid response mechanisms to detect and mitigate unauthorized access to sensitive data.
7 months ago
Kill Chain
Credential Theft Leads to Massive Data Breach at French Ministry of Finance
In late January 2026, the French Ministry of Finance reported a significant data breach involving unauthorized access to the national bank account registry, FICOBA. A threat actor exploited stolen credentials from a government official to access sensitive information on approximately 1.2 million bank accounts. The compromised data included bank account details (RIBs/IBANs), account holder identities, physical addresses, and, in some cases, taxpayer identification numbers. Upon detection, the Ministry promptly restricted the unauthorized access and initiated measures to notify affected individuals and financial institutions. This incident underscores the critical importance of robust access controls and credential management within governmental systems. The breach highlights the escalating risks associated with credential theft and the necessity for enhanced cybersecurity measures to protect sensitive financial data. Organizations are urged to reassess their security protocols to mitigate similar threats.
7 months ago
Kill Chain
BeyondTrust 2026 RCE Vulnerability Exploited in Ransomware Attacks
In early February 2026, BeyondTrust disclosed a critical pre-authentication remote code execution (RCE) vulnerability, CVE-2026-1731, affecting its Remote Support (RS) and Privileged Remote Access (PRA) products. This flaw allows unauthenticated attackers to execute arbitrary operating system commands by sending specially crafted requests to vulnerable endpoints. Despite the release of patches, active exploitation began almost immediately, with threat actors deploying ransomware and exfiltrating data. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on February 13, 2026, emphasizing the urgency for organizations to apply the necessary updates. The rapid exploitation of CVE-2026-1731 underscores a concerning trend where attackers swiftly leverage newly disclosed vulnerabilities to launch ransomware campaigns. This incident highlights the critical need for organizations to implement robust patch management processes and maintain vigilant monitoring to detect and respond to such threats promptly.
7 months ago
Kill Chain
FBI Reports Surge in ATM Jackpotting Attacks in 2025
In 2025, the FBI reported a significant surge in ATM jackpotting incidents across the United States, with over 700 attacks resulting in more than $20 million in losses. These attacks involve cybercriminals exploiting physical and software vulnerabilities in ATMs, often deploying malware like Ploutus to force machines to dispense cash without legitimate transactions. Criminals typically gain access by using generic keys to open ATM fronts and then install malware to control the machines remotely. This alarming trend underscores the evolving tactics of cybercriminals and highlights the urgent need for financial institutions to bolster their ATM security measures. The rise in such sophisticated attacks calls for enhanced vigilance and the implementation of robust security protocols to protect against these threats.
7 months ago
Kill Chain
Ukrainian National Sentenced for Facilitating North Korean IT Worker Fraud
In February 2026, Ukrainian national Oleksandr Didenko was sentenced to five years in U.S. federal prison for orchestrating a scheme that enabled North Korean IT workers to fraudulently secure employment at 40 U.S. companies. Didenko operated the website Upworksell.com, facilitating the sale of stolen U.S. citizen identities to these workers, who then funneled their earnings back to North Korea to support its weapons programs. He also managed multiple 'laptop farms' in the U.S. to create the illusion of domestic employment locations. This case underscores the persistent threat of nation-state actors exploiting identity theft to infiltrate and financially exploit U.S. businesses. The incident highlights the evolving tactics of North Korean operatives, who now leverage authentic LinkedIn profiles to enhance the credibility of their fraudulent job applications, posing ongoing risks to corporate security and compliance.
7 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports