The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
How PDFSider Malware Enabled a Major Fortune 100 Ransomware Breach in Finance
In January 2026, a Fortune 100 financial services company was compromised by a ransomware group utilizing a sophisticated new Windows malware strain dubbed PDFSider. Attackers used social engineering, posing as support staff to trick employees into running malicious files and installing remote-access tools. The payload was delivered via spearphishing emails containing a ZIP archive with a legitimate, signed PDF24 Creator executable and an altered cryptbase.dll, exploiting DLL side-loading to bypass security controls. Once activated, PDFSider established a covert backdoor, loaded its code into memory, and exfiltrated system information over encrypted DNS channels, employing advanced evasion and anti-analysis tactics to maintain persistent access and enable ransomware deployment. This incident underscores a surge in targeted ransomware and espionage-style operations, where attackers blend APT tradecraft with financial motives. As threats increasingly leverage trusted tools, memory-resident malware, and advanced encryption, organizations face mounting pressure to bolster detection and containment strategies in response to evolving attacker sophistication.
8 months ago
Kill Chain
NexShield Fake Ad Blocker & CrashFix: 2026's Browser Extension Malware
In January 2026, a sophisticated malvertising campaign leveraged a fake Chrome and Edge extension named NexShield to target corporate environments. Purported as a privacy-focused ad blocker, NexShield was distributed through the Chrome Web Store and social engineering tactics. Upon installation, the extension intentionally crashed browsers and subsequently displayed fake warnings instructing users to run malicious commands in Windows Command Prompt, thereby installing ModeloRAT—a Python-based remote access tool with extensive reconnaissance and persistence capabilities. The campaign, dubbed 'CrashFix' and attributed to threat actor KongTuke, demonstrated advanced evasion techniques, delayed payload execution, and targeted both corporate and individual users. This incident exemplifies the growing threat from malicious browser extensions and evolving malvertising techniques. Security experts note a marked increase in targeted, multi-stage attacks that exploit trusted distribution channels and leverage social engineering to compromise endpoints, underlining the urgent need for robust browser extension controls and ongoing user awareness.
8 months ago
Kill Chain
CrashFix Chrome Extension Attack Delivers ModeloRAT in ClickFix-Style Campaign
In January 2026, security researchers uncovered the 'KongTuke' campaign, which weaponized a malicious Chrome extension named CrashFix, disguised as an ad blocker. Attackers exploited a faux browser crash workflow—imitating ClickFix lures—to trick victims into running malicious commands, delivering the new ModeloRAT remote access trojan (RAT). The campaign allowed threat actors to silently gain persistent, covert access, facilitating lateral movement and potential data exfiltration within corporate environments. The incident highlights the evolving sophistication of browser-based attack chains and underscores browser extension risk as a modern threat vector for organizations reliant on SaaS and web apps. This breach is emblematic of a surge in malicious browser extensions delivering advanced malware. It showcases a growing trend toward supply chain compromise and the abuse of user trust in widely used browser platforms, calling for improved extension vetting and proactive security controls.
8 months ago
Kill Chain
How an XSS Bug in StealC Malware Panel Unmasked Threat Actors in 2026
In January 2026, cybersecurity researchers exploited a cross-site scripting (XSS) vulnerability in the StealC information stealer's web-based control panel. By leveraging this flaw, they monitored active threat actor sessions, collected system fingerprints, and obtained critical intelligence on StealC's illicit operations. The StealC malware, known for targeting credentials and sensitive data from infected endpoints, was actively managed via this compromised control panel by cybercriminal operators. As a result of this research, defenders gained unprecedented visibility into threat actor workflow and TTPs, turning a malicious tool’s own infrastructure against its controllers. This incident highlights the growing focus on attacking the infrastructure of threat actors themselves, signifying a shift in defensive strategies. Vulnerabilities within criminal tooling and panels can be weaponized by blue teams to gain actionable threat intelligence, reflecting broader trends in intrusion analysis and adversary disruption.
8 months ago
Kill Chain
Fortinet 2026: How RedLine Clipjack and Copilot Shaped a New Breed of Multi-Vector Attacks
In early 2026, multiple organizations suffered a multi-vector cyberattack campaign leveraging Fortinet device vulnerabilities, RedLine stealer variants with clipjack capabilities, and weaponized Copilot-integrated phishing. Threat actors gained initial access through unpatched Fortinet appliances, moved laterally via east-west traffic, and deployed RedLine malware to intercept credentials and exfiltrate sensitive data. The attackers further abused cloud AI tools to automate reconnaissance and launch targeted campaigns, leading to significant data compromise and operational disruption across cloud and hybrid environments. This incident underscores an accelerating trend: attackers are combining zero-day exploits, infostealers, and AI-driven automation to bypass traditional defenses. As threat actors become more agile and creative with emerging tools, organizations face growing pressure to secure east-west flows and implement real-time anomaly detection to mitigate multi-stage breaches.
8 months ago
Kill Chain
Google Gemini AI Prompt Injection Breach Exposes Calendar Data in 2026
In early 2026, researchers uncovered a significant security flaw in Google Gemini’s AI/ML integrations that allowed attackers to exploit indirect prompt injection to circumvent authorization guardrails and access private Google Calendar events. By embedding hidden instructions in malicious calendar invites, attackers could cause Gemini to exfiltrate sensitive information from users’ calendars without their knowledge or explicit consent. The exploit, disclosed by Miggo Security, demonstrated how AI-driven features can inadvertently expand attack surfaces, resulting in unauthorized data exposure and raising serious concerns for enterprise users relying on AI-powered productivity platforms. This breach highlights an evolving trend of attackers targeting embedded AI agents within trusted cloud services. As organizations increasingly leverage AI-powered workflows, the risks of novel exploitation methods like prompt injection become more pressing, driving renewed urgency around reinforcing authorization layers and AI security best practices.
8 months ago
Kill Chain
CIRO 2023 Data Breach Exposes Sensitive Data of 750,000 Canadian Investors
In late 2023, the Canadian Investment Regulatory Organization (CIRO) disclosed that a cyberattack compromised the personal and financial data of approximately 750,000 Canadian investors. The breach, involving unauthorized access to sensitive investor information, stemmed from an attack on a third-party IT provider responsible for maintaining the data. The breach's detection and subsequent investigation prompted CIRO to initiate notification procedures with impacted individuals and regulatory bodies. The incident highlighted critical weaknesses in third-party vendor security, raising concerns about the protection of confidential financial data within the regulated investment sector. This event is particularly relevant as it underscores a growing trend of attacks targeting regulatory and financial organizations via supply chain vectors. With increasing regulatory scrutiny and heightened risks from third-party service providers, organizations face renewed pressure to modernize data protection strategies and enforce robust vendor risk management frameworks.
8 months ago
Kill Chain
Fortinet FortiSIEM CVE-2025-64155: Critical Vulnerability Exploited in the Wild
In June 2025, Fortinet disclosed CVE-2025-64155, a critical command injection vulnerability affecting FortiSIEM, its security information and event management solution. Attackers began exploiting the flaw almost immediately after disclosure, leveraging it to execute unauthorized system commands and gain persistent access across multiple targeted networks. Malicious activity was detected from a diverse array of IP addresses, suggesting widespread probing and potential compromise. The rapid weaponization of the vulnerability placed organizations relying on FortiSIEM at risk of data exfiltration, lateral movement, and potential service disruption, underscoring the importance of timely patch management and layered defenses. This incident is emblematic of a growing trend where attackers aggressively target newly disclosed vulnerabilities in widely used security platforms. The event highlights the urgent need for rapid vulnerability response processes and reevaluation of vendor risk in security-critical infrastructure, as threat actors continue to automate exploitation of critical flaws in security tooling itself.
8 months ago
Kill Chain
Inside the 2024 Payroll Social Engineering Breach: Lessons from the Payroll Pirates
In early 2024, a major payroll provider experienced a sophisticated social engineering breach orchestrated by attackers dubbed the 'Payroll Pirates.' The threat actors engineered convincing phishing campaigns targeting payroll staff, tricking them into divulging critical credentials. Once initial access was secured, the attackers leveraged lateral movement techniques to escalate privileges and manipulate internal payroll processes, ultimately leading to fraudulent fund transfers and sensitive data exposure. Rapid detection efforts limited further impact, but the breach resulted in financial losses, operational disruption, and increased scrutiny over internal controls. This incident underscores the resurgence of highly targeted social engineering attacks, specifically in the payroll and finance sectors. As attackers blend human manipulation with advanced technical tactics, organizations must prioritize zero trust architectures, staff awareness, and continuous threat monitoring to defend against this evolving risk landscape.
8 months ago
Kill Chain
Google Pixel 9's 2025 Zero-Click Exploit Chain: Lessons in Mobile Supply Chain Security
In 2025, security researchers demonstrated a critical 0-click exploit chain targeting Google Pixel 9 and other Android devices, leveraging vulnerabilities in the Dolby UDC audio codec and the BigWave driver. Attackers could remotely execute code without user interaction by exploiting flaws in audio file processing and privilege escalation within device drivers. Despite early reporting and clear exploitability, it took vendors up to 139 days to release patches, leaving millions of Android users at risk. Gaps in patch management, inconsistent security controls, and delayed vulnerability classification contributed to prolonged exposure and a significant operational risk. This incident underscores the urgency of promptly addressing zero-click vulnerabilities and supply chain security issues in mobile ecosystems. As attackers increasingly exploit overlooked decoders, device drivers, and rapidly introduced AI features, coordinated patching and proactive privilege reduction remain essential to counter evolving mobile threats.
8 months ago
Kill Chain
Fortinet FortiSIEM Zero-Day: Exploitation Surge Exposes SIEM Risks in 2024
In June 2024, attackers began actively exploiting a critical vulnerability (CVE-2024-XXXX) in Fortinet FortiSIEM, a widely deployed security event management solution. The flaw, which allows remote code execution via specially crafted API requests, was leveraged soon after public proof-of-concept exploit code emerged. Threat actors targeted unpatched FortiSIEM instances to gain privileged access, deploy malware, and establish persistence within enterprise environments, impacting security visibility and putting sensitive data at risk. Public advisories highlighted patch urgency, as exploitation was observed globally in both private and government sectors. This incident underscores sharp escalation in exploitation of high-impact vulnerabilities immediately following public disclosure and POC release. The attack illustrates the need for rapid patching, robust segmentation, and comprehensive monitoring, as threat actors increasingly automate targeting of critical management infrastructure.
8 months ago
Kill Chain
Sitecore 2025: China-Linked APT UAT-8837’s Zero-Day Attack Reveals Modern Espionage Tactics
In early September 2025, an advanced persistent threat group known as UAT-8837, believed to be linked to China, exploited a zero-day vulnerability (CVE-2025-53690) in Sitecore products to gain initial access to critical infrastructure targets in North America. The attackers obtained credentials and leveraged living-off-the-land tools, open-source utilities, and custom backdoors—including 'WeepSteel'—to conduct deep reconnaissance, move laterally, and collect sensitive data such as credentials and Active Directory configurations. Post-exploitation activity also included disabling security controls and exfiltrating internal DLLs, which could be leveraged for future supply chain attacks. This incident spotlights a surge in targeted espionage exploiting both zero-day and known software vulnerabilities, with an emphasis on credential compromise and lateral movement. Growing overlap in TTPs among China-nexus actors and continued attack innovation reinforce the importance of modernizing defenses against sophisticated identity- and supply-chain-driven attacks.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports