The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
TOTOLINK EX200 Unpatched Flaw Enables Remote Takeover in 2026
In January 2026, a critical unpatched firmware vulnerability (CVE-2025-65606) was disclosed by CERT/CC affecting TOTOLINK EX200 wireless range extenders. This flaw resides in the device’s firmware-upload error-handling logic, allowing a remote authenticated attacker to trigger processes leading to full device compromise. Successful exploitation provides total administrative control, enabling attackers to alter configurations, secretly listen to traffic, or pivot to other devices on the network. TOTOLINK has not released an update, leaving vulnerable devices exposed in both home and enterprise environments. This breach highlights the ongoing threat posed by IoT device vulnerabilities—especially as attackers increasingly exploit authentication-bypass flaws and manufacturer patch delays. The incident underscores the importance of swift vulnerability management and robust network segmentation in mitigating the risk from unpatched IoT endpoints.
8 months ago
Kill Chain
900,000 Users Targeted: Malicious Chrome Extensions Harvest AI Chat & Browser Data
In January 2026, cybersecurity researchers uncovered two malicious Chrome extensions—'Chat GPT for Chrome with GPT-5, Claude Sonnet & DeepSeek AI' and 'AI Sidebar with Deepseek, ChatGPT, Claude, and more.'—that secretly exfiltrated ChatGPT, DeepSeek conversations, and extensive browsing data from over 900,000 users. These extensions masqueraded as legitimate browser tools but harvested sensitive data by scraping web pages and Chrome tabs, transmitting this information to attacker-controlled command-and-control servers every 30 minutes. This breach potentially exposed confidential business information, intellectual property, and user identities, underscoring the heightened risks posed by seemingly innocuous browser add-ons in enterprise environments. The incident marks a broader uptick in malicious and even some legitimate browser extensions turning to 'prompt poaching'—stealing user interactions with AI and chatbots. As AI adoption accelerates, organizations face new data exposure risks, demanding updated monitoring, awareness, and policy enforcement around browser extensions.
8 months ago
Kill Chain
Ransomware 2026: Inside the Surge of DDoS, Insiders, and Gig Worker Threats
In early 2026, ransomware groups rapidly adapted their extortion playbooks following a revenue decline, marked by a 47% year-over-year surge in attacks but falling ransom payments. Threat actors broadened tactics—reviving DDoS-for-hire within the Ransomware-as-a-Service (RaaS) model, ramping up recruitment of insiders (including targeting trusted employees and gig workers), and executing data theft via both technical and social attack vectors. Notably, attackers expanded beyond traditional Russian operators, evidencing global proliferation. These methods bypassed conventional defenses, with incidents tracked across multiple sectors and frequently resulting in significant data breaches, operational disruption, and reputational harm. The evolution of ransomware in 2026 highlights a rising urgency for enterprises to harden insider defenses, revisit DDoS mitigation, and validate physical security and third-party access. With attackers exploiting workforce instability, gig economy platforms, and hybrid extortion, a modernized, multi-layered security posture is now critical across all industries.
8 months ago
Kill Chain
Insider Threat Reality: US Cyber Pros Caught as BlackCat Ransomware Affiliates
In 2023, two U.S.-based cybersecurity professionals—formerly employed by major security firms—pleaded guilty to acting as affiliates for the ALPHV/BlackCat ransomware group. The individuals leveraged their insider knowledge and technical expertise to facilitate the deployment of the ransomware, compromising sensitive systems in targeted organizations. By exploiting weaknesses in internal security protocols and bypassing detection mechanisms, they assisted in the encryption of files and extortion of affected businesses, resulting in operational disruptions and significant reputational damage across multiple sectors. This incident highlights an escalating threat posed by insiders with privileged knowledge and skills, who collaborate with sophisticated ransomware groups like BlackCat. The convergence of advanced ransomware-as-a-service operations and trusted industry insiders signals a dangerous shift, amplifying calls for more robust zero trust strategies, stricter network segmentation, and improved insider threat monitoring.
8 months ago
Kill Chain
MongoBleed: Active Exploitation of MongoDB Memory Leak Puts Credentials at Risk in 2024
In June 2024, a critical vulnerability nicknamed "MongoBleed" was discovered in MongoDB, exposing servers to a memory leak flaw that enables unauthenticated attackers to extract sensitive data such as passwords and authentication tokens. Threat actors are actively exploiting the flaw by sending specially crafted requests to exposed MongoDB endpoints, resulting in chunks of memory—including user credentials and potentially session information—being sent in response. Organizations running unpatched MongoDB instances faced increased risk of credential theft, lateral movement, and potential data breaches, with attacks escalating once public proof-of-concept exploits were released. The MongoBleed incident highlights a surge in opportunistic attacks against cloud-managed databases and underscores the crucial need for rapid patch deployment. The attack's simplicity, combined with the prevalence of cloud-exposed databases in hybrid environments, makes this vulnerability especially relevant as organizations transition to zero-trust and improved segmentation to defend against credential harvesting and related threats.
8 months ago
Kill Chain
NordVPN 2026: False Data Breach Claim Traced to Vendor Test Environment
In January 2026, a threat actor claimed to have breached NordVPN's internal Salesforce development servers, alleging access to over ten databases containing sensitive Salesforce API keys and Jira tokens. The attacker purportedly leveraged brute-force tactics against a misconfigured server; however, NordVPN clarified that the data originated from a vendor's temporary test environment used months prior for automated testing. The breached environment contained only non-sensitive, dummy data, was never linked to NordVPN's production infrastructure, and did not expose customer information or production credentials. The company immediately investigated, engaged with the affected vendor, and publicly denied any compromise of its operational assets. This incident highlights how false breach claims—when amplified by threat actors and forums—can impact enterprise reputation, erode trust, and distract security teams. The event also spotlights the importance of robust controls and clear communication regarding third-party environments, even those used only for testing, as threat actors increasingly seek to exploit every operational touchpoint.
8 months ago
Kill Chain
Ledger Customer Data Exposed in 2024 Global-e Third-Party Breach
In June 2024, Ledger, the hardware cryptocurrency wallet provider, disclosed that a third-party service provider, Global-e, suffered a security breach resulting in unauthorized exposure of customer data. Attackers gained access to Global-e’s e-commerce system, compromising customers’ names, addresses, phone numbers, and emails used for Ledger purchases. Financial information and cryptocurrencies remained unaffected, but impacted individuals could be at greater risk for phishing or other targeted attacks leveraging their leaked information. This incident underscores the growing risks organizations face from third-party vendors. As supply chain and partner ecosystems expand, attackers increasingly target less secure partners, leading to significant data exposures even when a primary company’s own systems are uncompromised.
8 months ago
Kill Chain
VSCode IDE Forks Expose Software Supply Chain Risks via Recommended Extensions
In late 2025, researchers at Koi Security identified a vulnerability across several AI-powered IDEs forked from Microsoft Visual Studio Code—including Cursor, Windsurf, Google Antigravity, and Trae—whereby hardcoded lists of "recommended" extensions pointed to namespaces that were unclaimed in the OpenVSX extension registry. Threat actors could exploit this by registering these namespaces and publishing malicious extensions, leveraging user trust in built-in recommendations. The risk affected any developer using these IDE forks, potentially opening the door for supply chain malware. After reporting, project maintainers began removing vulnerable recommendations and placeholder, non-functional extensions were uploaded to block exploitation. No evidence of active malicious abuse was found prior to remediation. This incident underscores the growing risk of software supply chain attacks, particularly via open-source repositories and trusted platform recommendations. As more AI-powered tools automate software development environments, attackers are increasingly targeting overlooked dependency and plugin ecosystems, forcing organizations to enhance extension and third-party controls.
8 months ago
Kill Chain
Corporate Cloud File-Sharing Sites Targeted in Major Zestix Data Theft (2024)
In early 2024, a threat actor identified as Zestix orchestrated a widespread campaign targeting corporate instances of popular cloud file-sharing services, including ShareFile, Nextcloud, and OwnCloud. By exploiting vulnerable configurations and access controls, Zestix infiltrated dozens of organizations, exfiltrating sensitive corporate data and offering it for sale on underground forums. Attackers leveraged cloud-native techniques to blend in with legitimate traffic, complicating detection and response efforts. The incident has resulted in operational disruption for several affected companies and increased scrutiny over cloud data management strategies. This breach highlights the growing sophistication of cybercriminals in targeting SaaS-based collaboration platforms, exploiting the accelerated shift to cloud storage. As data sovereignty and regulatory demands intensify, organizations must urgently address evolving cloud security gaps to counter both traditional and cloud-native threats.
8 months ago
Kill Chain
Bitfinex 2016 Hack: Anatomy of a Record Crypto Heist and Its Aftermath
In 2016, cryptocurrency exchange Bitfinex suffered one of the largest crypto thefts to date when hackers, including Ilya Lichtenstein, exploited security weaknesses to steal nearly 120,000 Bitcoins, worth billions of dollars at the time. Lichtenstein laundered the stolen funds through a sophisticated network of wallets and exchanges to obscure the assets' origin. Following a lengthy investigation, U.S. authorities arrested Lichtenstein in 2022, later convicting and sentencing him for money laundering tied to this high-profile breach. The Bitfinex hack has become a landmark case in cryptocurrency security and digital money laundering tactics. Its legacy persists as the industry faces increased regulatory scrutiny and ongoing threats targeting exchanges via increasingly sophisticated cyber methods.
8 months ago
Kill Chain
Inside the ClickFix Hospitality Attack: How Fake BSOD Screens Delivered Malware in Europe
In early 2024, a social engineering campaign dubbed 'ClickFix' targeted hospitality sector organizations across Europe by deploying convincing fake Windows Blue Screen of Death (BSOD) screens. Threat actors lured hotel staff into believing their systems were compromised, instructing them to download and execute what appeared to be legitimate fixes. Instead, victims manually compiled and ran malware, granting attackers access to sensitive information and operational networks. The campaign highlights how attackers combine psychological manipulation with technical tactics to bypass traditional security and leverage low-privilege endpoints for initial access, risking data loss and downstream attacks on partners. This incident signals a shift toward increasingly sophisticated social engineering and blended attack methods targeting industries with high customer throughput. As phishing tactics evolve, organizations must bolster employee awareness and deploy proactive threat detection to counter these multifaceted threats.
8 months ago
Kill Chain
Brightspeed Hit by Crimson Collective: Major 2026 Data Breach Exposes Customer PII
In January 2026, Brightspeed, one of the largest fiber broadband providers in the United States, launched an investigation after the Crimson Collective extortion gang claimed to have breached the company’s networks and stolen sensitive data. The group asserted they had accessed personal and account-related information of over 1 million customers, including names, addresses, emails, phone numbers, payment histories, and some payment card details. The threat actors reportedly targeted user account systems and exfiltrated personally identifiable information (PII), subsequently pressuring Brightspeed to respond to their extortion demands by threatening to publish samples of the stolen data. This attack underscores the persistent risk posed by targeted data breaches in the telecom sector, where expansive networks and large customer bases make attractive targets for financially motivated threat actors. The incident further highlights a concerning trend: extortion groups are increasingly leveraging cloud misconfigurations, stolen credentials, and lateral movement within corporate environments to maximize data theft and pressure on organizations.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports