Industry Category

Financial Services

Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.

4282 threat reports
Page 277 of 357

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Financial Services Threat Reports

Showing 33133324 / 4282 reports
Sunbird DCIM Vulnerabilities Expose Critical Infrastructure: 2025 Authentication Bypass & Credential Risks
Impact· medium

Sunbird DCIM Vulnerabilities Expose Critical Infrastructure: 2025 Authentication Bypass & Credential Risks

In December 2025, security vulnerabilities were disclosed in Sunbird DCIM's dcTrack and Power IQ products, affecting all versions up to v9.2.0. Two significant flaws—an Authentication Bypass Using an Alternate Path or Channel (CVE-2025-66238) and the Use of Hard-coded Credentials (CVE-2025-66237)—could allow attackers to gain unauthorized access or escalate privileges within critical infrastructure environments. Threat actors abusing these vulnerabilities could redirect network traffic, access restricted services, or take control of host machines, exposing organizations to severe operational and reputational risks. This incident highlights the ongoing challenges organizations face in securing infrastructure management tools. Authentication and credential weaknesses remain a leading vector for cyberattacks amid increasing regulatory oversight and the proliferation of critical systems connected globally. Prompt patching and improved credential handling are now essential across industries facing similar risks.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Arizona AG Files 2024 Suit Against Temu Over User Data Harvesting
Impact· medium

Arizona AG Files 2024 Suit Against Temu Over User Data Harvesting

In May 2024, the Arizona Attorney General filed a lawsuit against Temu, a Chinese online retailer, over allegations that its mobile app covertly accesses and collects sensitive user data from U.S. consumers without their consent. According to the suit, Temu’s app harvested extensive information—including location data, contacts, and device details—beyond what was necessary for shopping functionality by exploiting excessive permissions and transmitting this data to servers in China. The unauthorized data harvesting raised concerns about deceptive business practices, potential privacy violations, and the exposure of personal information to foreign entities with unclear data handling standards. This incident is particularly important as governments and regulators escalate actions against technology firms accused of aggressive or opaque data-collection practices. With privacy regulations and user scrutiny on the rise, the Temu case highlights the urgent need for robust compliance and modern security controls to guard against stealthy apps harvesting sensitive information at scale.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Millions Exposed: ShadyPanda’s 2024 Browser Supply Chain Attack
Impact· high

Millions Exposed: ShadyPanda’s 2024 Browser Supply Chain Attack

In early 2024, the ShadyPanda cyber-threat group, linked to China, orchestrated a large-scale malware campaign by exploiting browser extensions on the Google Chrome and Microsoft Edge marketplaces. The attackers embedded malicious code into seemingly innocuous browser add-ons, silently weaponizing millions of user browsers worldwide. Once installed, these extensions enabled covert surveillance, data exfiltration, and potentially even lateral movement within corporate environments, posing severe risks to both individual privacy and enterprise security. The incident highlights the vulnerabilities in browser supply chains, with organizations scrambling to assess exposure and patch endpoints. This breach underscores a rising trend of sophisticated supply chain and browser-based attacks, where adversaries blend into daily workflows to evade detection. Security leaders must quickly reassess extension controls, threat detection strategies, and regulatory compliance amid growing regulatory scrutiny and persistent attacker innovation.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
How MuddyWater Used a Snake Game to Breach Israeli Networks in 2024
Impact· medium

How MuddyWater Used a Snake Game to Breach Israeli Networks in 2024

In early 2024, Iranian state-sponsored APT MuddyWater launched a series of cyberattacks against Israeli organizations using a novel evasion method involving a modified version of the classic Snake mobile game. Attackers embedded malicious code within the game to establish a covert communication channel and facilitate lateral movement within compromised networks. Initial access was likely achieved through phishing emails, followed by deployment of specially crafted files to disguise data exfiltration activities. The campaign resulted in unauthorized access to sensitive data and disruption of critical business operations for targeted Israeli entities. This incident highlights a growing trend of threat actors leveraging benign-looking applications and creative techniques to bypass traditional security controls. The use of retro games as a decoy demonstrates that sophisticated attackers are continually adapting, raising the bar for detection and forensic analysis across industries.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
How a 2025 SSH Trojan Attack Leveraged a Government IP and Masquerading Tactics
Impact· low

How a 2025 SSH Trojan Attack Leveraged a Government IP and Masquerading Tactics

In November 2025, a sophisticated cyberattack was observed when an adversary used SSH brute-force tactics to infiltrate a honeypot system, exploiting default 'root' credentials. Once inside, the attacker uploaded a malicious ELF binary, masquerading as the legitimate OpenSSH daemon ('sshd'), designed for persistence and stealth. The operation originated from a government-owned IP address, but evidence suggests the IP was likely compromised and misused, underscoring the complexity of attributing attacks. No commands were executed post-login, highlighting advanced attacker tradecraft focused on evasion and long-term foothold. This incident exemplifies modern threats leveraging credential reuse, sophisticated masquerading, and the abuse of trusted system binaries. Such attacks signal the growing use of covert techniques, presenting heightened risks to organizations and reinforcing the need for proactive defense, improved authentication practices, and advanced monitoring.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
Critical Supply Chain React Vulnerability Puts Major Web Apps at Risk
Impact· medium

Critical Supply Chain React Vulnerability Puts Major Web Apps at Risk

In June 2025, a critical deserialization vulnerability (CVE-2025-55182) was discovered in React Server Components, an open-source project underpinning a vast ecosystem of web frameworks. The flaw, initially reported by security researcher Lachlan Davidson, allowed unauthenticated attackers to execute remote code in default configurations of major frameworks—most notably Next.js—and impacted about 39% of cloud environments using vulnerable packages. Meta, Vercel, and affected project maintainers issued emergency patches, with no exploitation observed before public disclosure, but technical details were widely circulated, causing industry-wide urgency for remediation. This incident demonstrates the growing risks associated with open-source supply chain dependencies and highlights how a single upstream vulnerability can propagate rapidly across major SaaS platforms and developer environments. The ease of exploitation and prevalence of the affected components elevate concerns about lateral movement, credential exposure, and long-tail risk in environments slow to update or lacking robust software composition analysis.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Clop Ransomware Hits University of Phoenix: Oracle Vulnerability Exposes Data
Impact· high

Clop Ransomware Hits University of Phoenix: Oracle Vulnerability Exposes Data

In August 2025, the University of Phoenix reported a significant data breach stemming from a ransomware data theft campaign attributed to the Clop threat group. Attackers exploited vulnerabilities in Oracle E-Business Suite environments, enabling them to gain unauthorized access to sensitive records. As a result, personal and possibly financial information of students and staff were exposed, with operational disruptions and incident response activities triggering increased scrutiny. The attack is part of a broader campaign that has targeted multiple U.S. universities using similar tactics, highlighting systemic weaknesses in ERP system security posture across higher education. The University of Phoenix incident exemplifies the ongoing evolution of ransomware operations targeting critical business applications and underscores the rise of supply-chain and third-party software attacks. Institutions now face heightened regulatory expectations for safeguarding sensitive data as ransomware groups escalate attacks on educational and enterprise systems.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Aisuru Botnet Shatters DDoS Record with 29.7 Tbps Assault in 2024
Impact· high

Aisuru Botnet Shatters DDoS Record with 29.7 Tbps Assault in 2024

Between February and April 2024, the Aisuru botnet orchestrated an unprecedented series of over 1,300 distributed denial-of-service (DDoS) attacks, culminating in a world-record 29.7 Tbps bombardment against a major cloud service provider. Leveraging a vast network of compromised devices, the attackers demonstrated advanced traffic amplification techniques and targeted both edge and core network infrastructure, disrupting service availability and highlighting weaknesses in current DDoS defense postures. The scale and velocity of the assault challenged existing mitigation limits and underscored the dynamic evolution of botnet-driven attacks. This incident sets a new benchmark for volumetric DDoS attacks, illustrating the growing sophistication of threat actors and the accelerating arms race between attackers and defenders. It signals a pressing need for organizations to reassess cloud and network security strategies, emphasizing adaptive, zero trust, and layered defense frameworks.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(low)
I
Impact(high)
Read Report
DragonForce & Scattered Spider: Ransomware Collaboration Highlights the 2025 Threat Landscape
Impact· high

DragonForce & Scattered Spider: Ransomware Collaboration Highlights the 2025 Threat Landscape

In early 2025, the DragonForce ransomware group expanded its global campaign by collaborating with Scattered Spider, an English-speaking threat actor notorious for advanced social engineering and initial access techniques. This partnership allowed DragonForce to leverage Scattered Spider’s skills in phishing, credential harvesting, and network penetration to facilitate rapid, multi-stage compromises of major corporate networks across various sectors. Attackers gained initial access using phishing and social engineering against IT and security staff, followed by lateral movement and deployment of ransomware to encrypt critical data. The attacks resulted in significant operational disruption, data loss, and extortion demands for affected organizations. This incident exemplifies a growing threat trend: ransomware operators teaming up with specialized access brokers to accelerate intrusion success and maximize impact. Organizations now face highly coordinated, multi-vector attacks that challenge traditional defenses, driving urgency around zero trust architectures and improved lateral security controls.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Microsoft Mitigates Windows LNK Zero-Day Exploited in Active Attacks
Impact· medium

Microsoft Mitigates Windows LNK Zero-Day Exploited in Active Attacks

In June 2024, Microsoft addressed a high-severity zero-day vulnerability (CVE-2024-38112) affecting Windows LNK files. Multiple state-sponsored and cybercriminal groups exploited this flaw in-the-wild, leveraging maliciously crafted shortcut files to execute arbitrary code with user privileges. Attackers gained initial access by delivering LNK payloads via phishing emails and drive-by downloads, bypassing standard user awareness and endpoint defenses. Successful exploitation enabled threat actors to deploy malware, pivot laterally, exfiltrate sensitive data, and disrupt business operations before Microsoft’s silent mitigation, which came ahead of a formal patch release. The incident highlights increasing trends in the exploitation of novel and low-friction attack vectors, such as Windows shortcuts, which evade traditional detection. With LNK abuse on the rise among advanced persistent threats (APTs) and financially motivated actors, organizations face mounting pressure to close gaps in endpoint security, monitoring, and privilege management.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Supply Chain Attack: Malicious Rust Crate Targets Web3 Developer Ecosystems
Impact· medium

Supply Chain Attack: Malicious Rust Crate Targets Web3 Developer Ecosystems

In April 2025, cybersecurity researchers identified a malicious Rust package named "evm-units" that was uploaded to crates.io, the central Rust package registry. Disguised as an Ethereum Virtual Machine (EVM) helper tool, the crate targeted developers working in Web3 environments across Windows, macOS, and Linux systems. Once installed, the package stealthily executed OS-specific malware to compromise developer endpoints, enabling threat actors to potentially gain access to sensitive credentials and project intellectual property. The incident underscores sophisticated, hard-to-detect supply chain tactics exploiting trusted ecosystems and automated developer workflows. This attack highlights the increasing prevalence of supply chain threats targeting open source development pipelines and blockchain ecosystems. Recent trends show attackers adapting to security controls by embedding malware into widely used software components, pressuring organizations to enhance package vetting, anomaly detection, and Zero Trust strategies.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Marquis Data Breach: 2024 Supply Chain Attack Exposes US Banking Customers
Impact· high

Marquis Data Breach: 2024 Supply Chain Attack Exposes US Banking Customers

In early 2024, Marquis Software Solutions, a financial marketing service provider, was the victim of a significant data breach that compromised sensitive personal information across more than 74 US banks and credit unions. The attackers gained unauthorized access through a third-party vulnerability and exfiltrated data sets containing names, addresses, Social Security numbers, financial account details, and demographic information of hundreds of thousands of customers. The breach not only impacted Marquis’s direct clients but also exposed downstream institutions and their end-users, triggering regulatory notifications and potential reputational damage to affected financial entities. This incident highlights the enduring risk posed by supply chain vulnerabilities within highly regulated industries, as attackers continue targeting trusted vendors with access to sensitive data. It underscores increasing regulatory scrutiny on vendor risk management and data protection, especially within financial and healthcare sectors.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports