The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
How Telegram Became the World's Largest Darknet Market Platform in 2026
In early 2026, major Chinese-speaking darknet markets known as Tudou Guarantee and Xinbi Guarantee emerged on the encrypted messaging platform Telegram, quickly becoming the world’s largest such entities. Following enforcement action and the banning of two prior networks, these new markets enabled an illicit ecosystem reportedly handling nearly $2 billion each month in laundering, sale of scamware, stolen data, deepfake technologies, and a disturbing array of black-market services. Their operations fuel high-volume crypto investment and romance scams, including the so-called 'pig butchering' schemes, which exploit trafficked labor and result in billions in global losses—with US victims alone losing around $10 billion a year. This incident illustrates the adaptability of cybercriminal infrastructure, highlighting Telegram’s evolving role as a trusted communications and trading platform for serious organized cyber threats. The surge in Telegram-based darknet activity coincides with increased regulatory scrutiny, growing law enforcement action, and a shift toward encrypted, resilient, and cross-border cybercrime tactics.
8 months ago
Kill Chain
Resecurity 2025: How a Cybersecurity Firm Turned an Alleged Breach Into a Threat Intelligence Win
In December 2025, threat actors identifying as the 'Scattered Lapsus$ Hunters' claimed they had breached systems belonging to cybersecurity firm Resecurity, stealing employee data, internal communications, threat intelligence reports, and client information. The attackers published screenshots to support their claims, including evidence of access to collaboration platforms. However, Resecurity quickly countered the claims, explaining that the compromised environment was actually a carefully monitored honeypot populated with synthetic datasets and fake credentials, intentionally designed to attract cybercriminals for research purposes. The company monitored and logged the attackers’ behaviors, collected valuable intelligence—including reconnaissance, OPSEC failures, and the use of residential proxy infrastructure—and shared key data with law enforcement. No real customer data or production systems were at risk during the incident, according to Resecurity. This case highlights the growing trend of cyber attackers targeting security firms as retaliation for investigations, as well as the strategic use of deceptive honeypots to gather adversary intelligence. The incident underlines the importance of controlled cyber deception, advanced detection, and proactive threat intelligence amid an escalating environment of data theft claims and public leak extortion tactics.
8 months ago
Kill Chain
RondoDox Botnet: React2Shell Flaw Drives Massive Next.js Server Breaches
In December 2025, the RondoDox botnet exploited the critical React2Shell vulnerability (CVE-2025-55182) to breach hundreds of Next.js servers worldwide. Researchers observed the botnet initiating mass scans and automated remote code execution attacks against exposed servers, deploying malware, persistent botnet loaders, and cryptominers. RondoDox leveraged the unpatched flaw in the widely used React Server Components protocol, enrolling compromised systems and IoT devices into its botnet and wiping out competing malware. The attack impacted both consumer and enterprise networks, risking data exfiltration, service outages, and broader supply chain compromise. This campaign underscores the increased urgency around patching application-layer vulnerabilities at scale, as attackers rapidly weaponize zero-day and n-day exploits across popular frameworks. The prevalence of automated exploitation and lateral expansion tactics reflects a shifting threat landscape that challenges traditional perimeter security and requires robust detection, segmentation, and rapid response capabilities.
8 months ago
Kill Chain
Crypto Phishing 2026: How Chatbots and Telegra.ph Power Modern Scams
Between October 2025 and early 2026, a persistent cryptocurrency phishing campaign leveraged fake chatbot websites and phishing emails to target users, primarily using minimalist publishing platforms such as telegra.ph and Google Forms. The attackers distributed scam emails promising recipients substantial payouts in Bitcoin, directing them to malicious pages purporting to automate cryptocurrency mining profits. Victims were eventually asked to pay a fraudulent conversion fee to claim their non-existent funds, with payments funneled into wallets controlled by the attackers. The campaign’s simplicity and abuse of free digital services allowed it to evade basic filtering and reach a wide audience repeatedly. This incident highlights an ongoing rise in abuse of cloud-based publishing and forms services for elaborate phishing scams. Attackers are increasingly automating social engineering techniques, combining chatbots and “cash out” lures that have proven cost-effective and resilient even as major platforms improve traditional anti-phishing measures.
- Banking/Mortgage
- Capital Markets/Hedge Fund/Private Equity
- Investment Management/Hedge Fund/Private Equity
8 months ago
Kill Chain
GlassWorm Malware Hits macOS: Supply Chain Attack via Malicious VSCode Extensions (2026)
In late 2025 and into January 2026, a new wave of the "GlassWorm" malware campaign targeted macOS developers by infiltrating Visual Studio Code and OpenVSX extension marketplaces. Malicious extensions, embedding AES-256-CBC–encrypted JavaScript payloads, were uploaded using covert techniques. Once installed, the malware stole sensitive credentials, including GitHub, NPM, and crypto wallet data, and established persistence via AppleScript and LaunchAgents. The campaign also attempted to replace popular hardware cryptocurrency wallet apps like Ledger Live and Trezor Suite, although this payload failed due to incomplete attacker infrastructure. Over 33,000 installs were recorded, potentially impacting individual developers and organizations reliant on secure software supply chains. GlassWorm’s evolution targets not only Windows but also macOS ecosystems, signaling a rising trend in sophisticated supply chain attacks against developer tooling. This incident is a cautionary reminder for organizations and developers to tightly scrutinize third-party plugins, raising urgency to implement stronger extension vetting, threat detection, and least-privilege controls.
8 months ago
Kill Chain
AI Supply Chain: Ultralytics, Nx, and ChatGPT Breaches Expose Massive Secrets Leakage
Between late 2024 and mid-2025, a series of major AI supply chain security breaches exposed severe vulnerabilities in widely used machine learning and development platforms. In December 2024, the Ultralytics AI library was compromised and distributed malicious code that hijacked victims’ systems for illicit cryptocurrency mining. By August 2025, attackers published malicious Nx packages that leaked over 2,300 GitHub, cloud, and AI credentials, enabling unauthorized access to sensitive resources. Throughout 2024, vulnerabilities in ChatGPT enabled cross-user data extractions via memory leakage, resulting in the exposure of personal and proprietary information. In total, an alarming 23.77 million secrets were leaked through AI-centric software and supply chain vectors within this period. This string of incidents impacted a wide spectrum of organizations, undermining trust in AI-based workflows and amplifying compliance and regulatory risk. These attacks underscore the rapidly escalating risk of supply chain compromise in AI-centric infrastructure. As organizations increasingly rely on open-source ML libraries and cloud-native platforms, threats targeting code dependencies, API memory, and package repositories are proliferating, outpacing traditional security controls. The incident highlights the urgent need for AI-aware, zero-trust frameworks, advanced east-west traffic monitoring, and routine credential hygiene to prevent similar future exposures.
8 months ago
Kill Chain
Trust Wallet Breach 2023: How a Shai-Hulud NPM Supply Chain Attack Stole $8.5M
In November 2023, Trust Wallet suffered a significant security breach in which an attacker exploited a malicious NPM supply chain package—most notably associated with the "Shai-Hulud" attack campaign. By leveraging this industry-wide incident, threat actors managed to compromise the Trust Wallet web browser extension, executing a targeted attack to steal approximately $8.5 million from over 2,500 crypto wallets. The threat actors utilized sophisticated techniques to inject malicious code via the open-source software supply chain, highlighting vulnerabilities in component dependencies and the risk of lateral movement within affected environments. This incident is especially relevant as supply chain attacks using compromised open-source packages are on the rise, impacting a broad range of organizations that rely on third-party code. The Trust Wallet breach underscores the urgency for robust supply chain security strategies, better monitoring of dependencies, and solid east-west traffic controls to detect anomalous behaviors and restrict lateral movement.
- Computer Software/Engineering
- Computer/Network Security
- Investment Management/Hedge Fund/Private Equity
8 months ago
Kill Chain
Mustang Panda’s 2025 Kernel Rootkit: How a Signed Driver Enabled Stealth Espionage in Asia
In mid-2025, the Chinese cyber espionage group Mustang Panda deployed a previously undocumented, signed kernel-mode rootkit to secretly load a TONESHELL backdoor variant during targeted attacks against government organizations in Southeast and East Asia—mainly Myanmar and Thailand. Leveraging a stolen legacy digital certificate, the attackers installed a Windows minifilter driver to inject TONESHELL into system processes, evade security controls, and shield their malware and associated files from detection. The backdoor enabled ongoing remote control, data exfiltration, and further malware deployments via encrypted channels, establishing persistent clandestine access. This incident is notable for its innovative use of signed kernel drivers to enhance stealth, resilience, and anti-forensic measures. It reflects a broader trend among sophisticated threat actors who increasingly leverage advanced rootkit technology and certificate abuse to bypass endpoint protections and remain undetected for extended periods.
8 months ago
Kill Chain
Worm in the Code: Shai Hulud & Cobalt Strike Unleash Supply Chain Threats on npm and Maven (2025)
In December 2025, researchers identified a modified strain of the Shai Hulud worm circulating in the npm registry via the package '@vietmoney/react-big-calendar.' While detected early with no large-scale infections, analysis showed the worm’s ability to compromise developer environments, harvest API keys, cloud credentials, and npm/GitHub tokens, and exfiltrate them to attacker-controlled GitHub repositories. Simultaneously, an unrelated but similar threat surfaced on Maven Central, where a typosquatted 'org.fasterxml.jackson.core/jackson-databind' package delivered an obfuscated Cobalt Strike beacon through supply chain compromise. Both incidents exploited weaknesses in public software repositories, targeting developer trust and facilitating potential lateral spread across the ecosystem. These incidents underscore the escalating risks of open source supply chain attacks, in which adversaries leverage trusted development components to sneak malware into organizations. With attacker sophistication growing and repository defenses lagging, enterprises face pressure to enhance visibility, automate dependency monitoring, and enforce zero-trust principles for third-party code integration.
8 months ago
Kill Chain
Over 10,000 Fortinet Firewalls Still Exposed to 2FA Bypass Attack in 2026
In early January 2026, it was revealed that over 10,000 Fortinet FortiGate firewalls remain exposed to a critical authentication bypass vulnerability (CVE-2020-12812) first patched by Fortinet in July 2020. Attackers exploit this flaw by manipulating username case sensitivity to bypass two-factor authentication (2FA) on SSL VPNs—allowing unauthorized access to devices with unpatched software and certain LDAP configurations. Despite years of vendor and government warnings, more than 1,300 vulnerable systems in the United States alone are still online, placing organizations at ongoing risk of compromise. The persistence of this five-year-old flaw’s exploitation highlights chronic issues in vulnerability management and patch adoption within network infrastructure. Active targeting by both cybercriminal and state-backed actors, combined with evidence of ransomware deployment, underscores the need for continuous configuration hardening, zero trust adoption, and rapid remediation of exposed security controls.
8 months ago
Kill Chain
Phishing Goes Cloud-Native: Google Cloud Application Integration Abused in 2026 Attack
In early 2026, a sophisticated phishing campaign was uncovered in which cybercriminals leveraged Google Cloud’s Application Integration service to send deceptive emails that mimicked legitimate Google communications. By exploiting the inherent trust in Google’s cloud infrastructure, attackers generated emails from authentic Google addresses, increasing the likelihood of victims engaging with malicious links or sharing sensitive information. According to Check Point researchers, this multi-stage approach enabled attackers to bypass traditional email security measures, posing significant risks to organizations that rely heavily on cloud-based productivity suites for daily operations. This campaign highlights an emerging trend in the abuse of trusted SaaS and cloud platforms for targeted phishing attacks. As adversaries shift toward cloud-native TTPs and social engineering techniques, organizations must enhance detection, improve user awareness, and adapt inline controls to mitigate risks tied to trusted service abuse.
8 months ago
Kill Chain
How the 2022 LastPass Breach Fueled $35M+ in Crypto Thefts
In 2022, LastPass suffered a significant data breach after attackers infiltrated a developer environment and stole company source code, later exploiting stolen credentials to breach cloud storage and extract encrypted customer password vaults. Despite vault encryption, weak or reused master passwords allowed attackers to eventually crack vaults offline, exposing sensitive credentials—including cryptocurrency wallet keys and seed phrases. Over the following years, coordinated threat actors drained victim wallets in distinct waves, laundering more than $35 million through techniques such as CoinJoin mixing, before cashing out via Russian-linked exchanges. This incident highlights the security risks of weak master passwords and illustrates the growing sophistication of post-breach credential exploitation, including the long-tail impact on industries handling digital assets. Organizations now face mounting regulatory pressure to strengthen secrets management and rapidly adapt to evolving attacker tradecraft targeting credential stores.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports