The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Financial Services

Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.

4294 threat reports
Page 237 of 358

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Financial Services Threat Reports

Showing 28332844 / 4294 reports
WinRAR 2025: Nation-State & Cybercrime Groups Exploit Six-Month Software Flaw
Impact· low

WinRAR 2025: Nation-State & Cybercrime Groups Exploit Six-Month Software Flaw

In late July 2025, Google Threat Intelligence Group reported that both nation-state actors and financially motivated cybercriminals are actively exploiting a critical WinRAR path traversal vulnerability (CVE-2025-8088) that remained unpatched for over six months. The flaw was widely abused starting two weeks before RARLAB released a fix, allowing attackers to craft specially designed archive files. These malicious files executed code or dropped malware undetected onto victim systems, targeting government, military, and technology sectors—most notably Ukrainian entities—while criminal groups focused campaigns in Latin America, Indonesia, and Brazil. The widespread exploitation continues, leveraging malware and remote access tools for espionage and credential theft. The current landscape highlights accelerated adoption of public exploit tools by both advanced persistent threats and opportunistic criminals. The event underscores urgent industry challenges in rapid patching, software supply chain trust, and the escalating convergence of state and criminal cyber operations sharing technical tradecraft.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Fortinet’s 2026 Zero-Day: Attackers Bypass FortiCloud SSO to Compromise Firewalls
Impact· low

Fortinet’s 2026 Zero-Day: Attackers Bypass FortiCloud SSO to Compromise Firewalls

In January 2026, Fortinet disclosed a critical zero-day vulnerability (CVE-2026-24858) affecting FortiCloud’s single sign-on authentication, enabling attackers with a FortiCloud account and a registered device to bypass authentication controls and gain privileged access to FortiGate firewalls and other products. Malicious actors leveraged the flaw in the wild, making unauthorized configuration changes, creating unauthorized accounts, and manipulating VPN settings across exposed management interfaces. Fortinet responded by disabling FortiCloud SSO, blocking the known malicious accounts, and issuing mitigations, though patches for multiple affected products remained unavailable at disclosure. This incident highlights the persistent targeting of network infrastructure devices by threat actors seeking initial access and lateral movement. With thousands of Fortinet instances exposed globally and repeated inclusion of Fortinet CVEs in known exploited vulnerabilities catalogs, organizations face increased regulatory scrutiny and pressure to rapidly address vulnerabilities affecting critical network management infrastructure.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
Kingdom Market Darknet Takedown: How Law Enforcement Disrupted a Global Cybercrime Hub (2021–2023)
Impact· high

Kingdom Market Darknet Takedown: How Law Enforcement Disrupted a Global Cybercrime Hub (2021–2023)

Between March 2021 and December 2023, the Kingdom Market darknet platform operated as a large-scale cybercrime marketplace facilitating the sale of narcotics, cybercrime tools, stolen personal information, and fraudulent documents. Slovakian national Alan Bill, also known as "Vend0r" or "KingdomOfficial," admitted in January 2026 to administering the illicit platform, handling site infrastructure, and orchestrating anonymous cryptocurrency payments. The marketplace boasted over 42,000 illegal listings and tens of thousands of customer accounts. Its takedown culminated in coordinated law enforcement actions, domain seizures, and Bill's arrest in the U.S., where evidence linked him directly to site operations. This case highlights the persistent challenge of global, darknet-enabled cybercrime, the evolution of anonymous payment technologies, and the international scope of enforcement efforts. Cybercrime marketplaces remain a top concern for regulators and enterprises alike, with attackers rapidly adapting business models and operational security to evade detection.

7 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Enterprise AI at Risk: Hackers Hijack Exposed LLM Endpoints in Bizarre Bazaar Operation
Impact· low

Enterprise AI at Risk: Hackers Hijack Exposed LLM Endpoints in Bizarre Bazaar Operation

In early June 2024, security researchers revealed an active campaign—dubbed the Bizarre Bazaar operation—where threat actors systematically scanned for and exploited publicly exposed Large Language Model (LLM) service endpoints. Attackers hijacked these AI/ML endpoints by bypassing inadequate API controls and leveraging unsecured cloud configurations, enabling unauthorized access to advanced AI resources. Compromised infrastructure became part of an underground market offering illicit AI compute power, leading to business risks ranging from intellectual property leakage to tool misuse and service disruption for impacted organizations. This incident spotlights the growing exploitation of AI infrastructure, with attackers rapidly adopting novel tactics as organizations rush to deploy LLMs. Weak segmentation, lack of egress controls, and poor visibility have left many organizations vulnerable to sophisticated abuse, elevating urgency for robust enterprise AI security and compliance measures.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(low)
Read Report
SolarWinds Web Help Desk Flaws: Critical RCE and Authentication Bypass in 2024
Impact· low

SolarWinds Web Help Desk Flaws: Critical RCE and Authentication Bypass in 2024

In June 2024, SolarWinds disclosed and patched multiple critical vulnerabilities in its Web Help Desk software, including an authentication bypass (CVE-2024-28995) and a remote command execution (RCE) flaw. These security issues, if left unpatched, allow attackers to compromise systems with minimal or no authentication, granting them access to execute arbitrary commands and potentially control affected servers. SolarWinds urged its customers to update immediately and disclosed that no in-the-wild exploitation had been confirmed at the time of announcement, but the severity of the flaws warranted immediate action across enterprise environments. This incident is particularly relevant due to a surge in software supply chain and IT management platform attacks, where adversaries exploit widely used admin tools to gain privileged access. Critical RCE and authentication vulnerabilities present potent risks to organizations, intensifying regulatory scrutiny and heightening the importance of timely patch management and proactive security measures.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(low)
Read Report
New Sandbox Escape Flaws in n8n Expose Instances to Remote Code Execution
Impact· medium

New Sandbox Escape Flaws in n8n Expose Instances to Remote Code Execution

In January 2026, security researchers uncovered two critical sandbox escape vulnerabilities in the popular n8n workflow automation platform, identified as CVE-2026-1470 and CVE-2026-0863. The flaws allowed authenticated users to exploit weaknesses in JavaScript and Python sandboxing mechanisms, enabling remote code execution on affected self-hosted instances. Attackers with valid user credentials could abuse these vulnerabilities to gain control of underlying systems, access sensitive data, and potentially compromise integrated services. Despite requiring authentication, the ease of privilege escalation and potential for lateral movement made these vulnerabilities highly impactful. This incident is highly significant given the large number of exposed n8n instances and the growing reliance on workflow automation by organizations worldwide. The vulnerabilities underline persistent challenges in securely sandboxing dynamic scripting languages, a common risk in platforms that allow code-based automation or AI integrations. The slow patching pace also highlights the pressing need for improved vulnerability management across self-hosted cloud infrastructure.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Empire Market Dark Web Takedown: Owner Pleads Guilty in $430M Cybercrime Plot
Impact· high

Empire Market Dark Web Takedown: Owner Pleads Guilty in $430M Cybercrime Plot

In January 2026, U.S. authorities announced that Raheim Hamilton (“Sydney”/“ZeroAngel”), a co-founder of the notorious Empire Market, pleaded guilty to federal drug conspiracy charges. From 2018 to 2020, Empire Market operated as a large-scale dark web marketplace accessible via TOR, facilitating over $430 million in illegal transactions, primarily enabling drug sales but also distributing stolen credentials, hacking tools, and counterfeit currency. Hamilton and partner Thomas Pavey laundered illicit proceeds through cryptocurrency and designed the site to evade law enforcement, directly overseeing vendor disputes and operational security. This prosecution underscores the ongoing threat and operational sophistication of dark web cybercrime marketplaces, even after earlier takedowns. As digital criminal platforms persistently adapt, law enforcement and organizations must address the evolving risks involving anonymized markets, cryptocurrency transactions, and the proliferation of illicit digital goods and services.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
FBI Takedown of RAMP: Ransomware's Last Open Forum Seized in 2026
Impact· medium

FBI Takedown of RAMP: Ransomware's Last Open Forum Seized in 2026

In January 2026, the FBI seized control of the notorious Russian-speaking RAMP cybercrime forum, widely used by ransomware gangs to promote operations, recruit affiliates, and trade access to compromised networks. Both its Tor and clearnet domains were confiscated, and a seizure notice was displayed in coordination with U.S. law enforcement agencies. As one of the last prominent ransomware-friendly forums, RAMP had become a hub for multiple groups, facilitated by threat actor Mikhail Matveev (aka Orange/Wazawaka). The FBI now possesses potentially incriminating data on user identities, logins, and private communications, increasing the risk of arrests for those with poor operational security. This takedown reflects a broader law enforcement crackdown on cybercrime infrastructure supporting ransomware attacks. The RAMP seizure is significant amid heightened regulatory and industry focus on disrupting the ransomware ecosystem and demonstrates the ongoing risk of exposure for those operating in or near dark web forums.

7 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
MicroWorld eScan Update Server Breach Exposes Supply Chain Risks
Impact· medium

MicroWorld eScan Update Server Breach Exposes Supply Chain Risks

In June 2024, MicroWorld Technologies, developers of eScan antivirus, experienced a breach where attackers compromised one of its update servers. The intruders leveraged this access to push a malicious software update to a limited subset of customers, effectively deploying unauthorized code via the trusted antivirus delivery mechanism. MicroWorld quickly detected the incident, notified impacted users, and began forensic analysis with assistance from cybersecurity experts. The compromised update posed potential risks including malware infection and lateral network movement. This incident is part of a growing trend of supply chain attacks, where adversaries exploit trusted update channels to infiltrate enterprise environments. As organizations increasingly rely on third-party software, vigilance and layered security controls around update infrastructures have become a pressing necessity.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Fake PyPI Spellchecker Packages Delivered RAT in Supply Chain Attack (2026)
Impact· low

Fake PyPI Spellchecker Packages Delivered RAT in Supply Chain Attack (2026)

In early 2026, security researchers uncovered a supply chain attack involving two malicious packages—spellcheckerpy and spellcheckpy—distributed on the popular Python Package Index (PyPI). Masquerading as legitimate spellchecking tools, these packages were downloaded over 1,000 times before removal, each covertly containing a remote access trojan (RAT). When unsuspecting developers installed the packages, attackers could gain persistent access to compromised systems, enabling data exfiltration, lateral movement, and remote command execution. No specific organizational victims were named, but the risk extended globally to Python developers and projects that leveraged these components. This incident is emblematic of the growing trend of supply chain attacks targeting open source repositories, exploiting trust in widely used ecosystems like PyPI. As software supply chains become common attack vectors, organizations face heightened pressure to vet dependencies and implement controls to prevent compromise via upstream components.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Exposed Interfaces & Supply Chain Risks: The 2026 Moltbot AI Assistant Breach
Impact· medium

Exposed Interfaces & Supply Chain Risks: The 2026 Moltbot AI Assistant Breach

In January 2026, researchers uncovered widespread security vulnerabilities in Moltbot (formerly Clawdbot), an open-source AI assistant that achieved viral adoption among both consumers and employees in the enterprise sector. Due to prevalent misconfigurations—specifically, exposed admin interfaces and reverse proxy errors—hundreds of Moltbot instances were accessible online, allowing unauthenticated attackers to steal API keys, OAuth tokens, credentials, message histories, and even execute commands remotely with system-level permissions. Additional risks arose as malicious skills (modules) could be planted in the official registry, rapidly propagating supply-chain threats to unsuspecting enterprise and developer systems, further compounded by the assistant lacking sandboxing or privilege separation by default. This incident highlights a growing trend where AI/GenAI tools, easily adopted outside corporate IT control, create new vectors for credential theft, data leakage, and lateral movement. As attackers focus on AI-driven endpoints and shadow IT, failure to enforce zero trust, segmentation, and robust monitoring introduces significant business risk and regulatory exposure.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Fortinet Authentication Bypass: CVE-2026-24858 (2026 Breach & Response)
Impact· low

Fortinet Authentication Bypass: CVE-2026-24858 (2026 Breach & Response)

In January 2026, Fortinet released emergency security patches to address a critical authentication bypass vulnerability (CVE-2026-24858, CVSS 9.4) actively exploited in the wild. Attackers leveraged the flaw in FortiOS's Single Sign-On (SSO) feature, bypassing authentication to gain unauthorized access to sensitive systems including FortiManager and FortiAnalyzer. The incident highlights the risks of unpatched perimeter defenses, with exploitation enabling potential lateral movement, privilege escalation, and access to business-critical data or control systems—potentially at scale for unremediated customers. This event is significant given the continued targeting of network infrastructure through novel bypass techniques. Escalating regulatory scrutiny and threat actor sophistication underscore the need for timely patching, robust segmentation, and ongoing monitoring of privileged identity solutions.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports