Industry Category

Financial Services

Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.

4282 threat reports
Page 280 of 357

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Financial Services Threat Reports

Showing 33493360 / 4282 reports
ShadyPanda: 4.3 Million Impacted in Massive Malicious Browser Extension Attack (2024)
Impact· medium

ShadyPanda: 4.3 Million Impacted in Massive Malicious Browser Extension Attack (2024)

In early 2024, the ShadyPanda campaign targeted users of Chrome and Edge browsers by distributing over 4.3 million malicious extensions disguised as legitimate utilities. Attackers leveraged browser extension supply chains—often through fraudulent developer accounts and aggressive social engineering—to gain access to users’ browsing data, credentials, and sensitive online activity. The malware evolved over time, adapting to evade security controls and harnessing sophisticated capabilities to extract data, redirect web sessions, and facilitate persistent surveillance, affecting millions globally and highlighting gaps in browser marketplace vetting. This incident exemplifies a rapid escalation in supply-chain attacks focusing on widely used platforms like web browsers. The surge in malicious browser extension campaigns underscores the increasing sophistication of threat actors and the urgent need for organizations and individuals to be vigilant about third-party software, browser hygiene, and visibility into user-installed code.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Coupang Data Breach 2024: 33 Million Customers Exposed in Massive Retail Incident
Impact· high

Coupang Data Breach 2024: 33 Million Customers Exposed in Massive Retail Incident

In early 2024, Coupang, South Korea's largest online retailer, reported a significant data breach affecting approximately 33.7 million customers. The incident involved unauthorized access to personal information, potentially including customer names, phone numbers, addresses, and partial payment details. Coupang disclosed the breach after detecting unusual access patterns and subsequently notified both customers and regulatory authorities. Initial investigations suggest attackers exploited vulnerabilities in Coupang's data management or access controls, raising concerns over the safeguarding of sensitive information in large-scale e-commerce environments. This breach is especially notable due to the unprecedented scale within the South Korean retail industry and highlights a broader trend of cybercriminals targeting high-profile, data-rich organizations. With customer trust and regulatory scrutiny at stake, organizations globally are urged to reassess their data security and compliance strategies.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
Glassworm Malware Returns: Third Wave Targets VS Code with Supply-Chain Attack (2024)
Impact· low

Glassworm Malware Returns: Third Wave Targets VS Code with Supply-Chain Attack (2024)

In early 2024, a new wave of the Glassworm malware campaign was discovered infiltrating the Microsoft Visual Studio Code and OpenVSX marketplaces with 24 malicious packages. These supply-chain attacks targeted software developers by masquerading as legitimate extensions, but upon installation delivered trojans capable of stealing sensitive files, authentication tokens, and establishing persistence for command-and-control activities. The campaign began in October 2023, with this third and most extensive wave compromising both trusted VS Code ecosystems and potentially impacting thousands who unknowingly downloaded tainted packages. The threat actors have not been formally attributed but demonstrated sophisticated understanding of both developer environments and software supply chains. This incident is a striking example of the increasing shift toward attacking upstream dependencies, leveraging trusted developer tools to gain footholds deeper in organizations. With open-source and third-party marketplaces under continuous attack, businesses face growing pressure to implement better package vetting and monitoring along with zero-trust segmentation and detection capabilities.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
Albiriox MaaS Android Malware: On-Device Fraud Spreads Across 400+ Financial Apps
Impact· high

Albiriox MaaS Android Malware: On-Device Fraud Spreads Across 400+ Financial Apps

In late 2025, a new Android malware strain dubbed Albiriox emerged on underground forums as a malware-as-a-service (MaaS) solution. Distributed primarily through phishing and malicious downloads, Albiriox targets over 400 financial, fintech, and cryptocurrency applications to enable on-device fraud and real-time manipulation of compromised devices. The malware supports screen control, credential theft, interception of two-factor authentication, and covert interaction, enabling attackers to bypass traditional defenses and commit large-scale financial fraud via victim phones. The impact has been significant, with financial institutions and consumers reporting substantial losses and operational disruptions, as attackers exploit compromised user devices for unauthorized transactions. This incident underscores the growing sophistication and accessibility of mobile malware platforms offered as a service by cybercriminals. The rise of on-device fraud capabilities—especially those circumventing multi-factor authentication and real-time security controls—demands renewed vigilance, continuous threat monitoring, and integrated security measures from organizations in the financial sector.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Multi-Vector Breach: npm Worm, Firefox RCE, and M365 Email Raids Rock 2025
Impact· high

Multi-Vector Breach: npm Worm, Firefox RCE, and M365 Email Raids Rock 2025

In December 2025, a coordinated multi-vector cyberattack was observed targeting organizations through the exploitation of critical zero-day vulnerabilities (CVEs), a resurgence of the npm InfoStealer Worm, a remote code execution flaw in Mozilla Firefox, and widespread credential compromise leading to Microsoft 365 email account takeovers. Attackers leveraged a blend of social engineering, poisoned open-source packages, and malicious links to infiltrate developer environments, gain access to corporate cloud accounts, and spread laterally via trusted supply chains. Impacted organizations faced the risk of sensitive data exfiltration, widespread internal compromise, and disruption of core IT services across software development and communications. This incident underscores the growing sophistication and scale of modern attack campaigns that blend supply chain, RCE, SaaS compromise, and worm tactics. The convergence of these vectors highlights the urgent need for zero trust segmentation, continuous threat detection, and cloud-specific defenses as attackers increasingly target developer and business collaboration tools.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
ShadyPanda: The 2024 Browser Extension Supply Chain Breach Impacting 4.3 Million Installs
Impact· high

ShadyPanda: The 2024 Browser Extension Supply Chain Breach Impacting 4.3 Million Installs

In mid-2024, the threat actor group ShadyPanda executed a sophisticated supply chain attack by compromising five popular browser extensions, which had previously been legitimate and widely trusted. These extensions, with a cumulative total of over 4.3 million installs, were maliciously updated to include spyware functionality, enabling covert surveillance and data exfiltration from unsuspecting users. The malicious modifications went undetected for several months, enabling the attackers to harvest browser data, credentials, and potentially sensitive user files, impacting organizations and individuals globally before the extensions were finally removed following a report by Koi Security. This incident highlights the increasing trend of supply chain compromise via browser extension ecosystems, which often lack sufficient vetting and monitoring. The attack underscores growing regulatory and operational pressure to secure third-party components and software supply chains, especially as similar tactics proliferate across widely adopted digital platforms.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Shai-hulud: npm Supply Chain Attack Hits Cloud Ecosystem
Impact· low

Shai-hulud: npm Supply Chain Attack Hits Cloud Ecosystem

In early 2024, security researchers uncovered a major supply chain attack involving a new variant of the Shai-hulud malware worm, which propagated through poisoned npm packages targeting cloud-based development environments. The malware autonomously infiltrated thousands of systems, harvesting credentials and secrets from cloud infrastructure providers including AWS, Google Cloud Platform, and Azure. Attackers achieved persistence and lateral movement by exploiting weaknesses in east-west traffic controls, leveraging the npm ecosystem’s trust to escalate impact across enterprise CI/CD pipelines and critical workloads. The breach resulted in significant operational risks, requiring emergency remediation from affected organizations and cloud providers. This incident highlights the evolving sophistication of supply chain threats, especially in cloud-native environments where development speed often outpaces traditional security controls. Attackers are increasingly abusing open-source package repositories for automated, scalable attacks—raising concerns for both cloud security and compliance teams.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Asahi Group Data Breach: 1.9 Million Records Exposed in 2023 Cyberattack
Impact· high

Asahi Group Data Breach: 1.9 Million Records Exposed in 2023 Cyberattack

In September 2023, Asahi Group Holdings, Japan’s largest beer producer, experienced a significant data breach affecting up to 1.9 million individuals, including customers, business partners, and employees. The investigation revealed that threat actors accessed personal data such as names, addresses, phone numbers, and email addresses through unauthorized access to its IT systems. Asahi’s systems were compromised via a cyberattack, resulting in the potential leak of sensitive information, although there was no initial evidence of misuse or ransomware demands reported. The company has since completed its forensic review and alerted regulatory bodies and affected individuals. This incident highlights the growing scale and impact of cyberattacks on major global brands and the risks posed by large-scale data exposures. With increasing regulatory scrutiny and evolving attacker methodologies targeting consumer data, organizations across all sectors face heightened pressure to enhance detection, segmentation, and rapid response to data breaches.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
November 2025 Cybersecurity Review: Akira, Operation Endgame, and AI Data Exposure
Impact· medium

November 2025 Cybersecurity Review: Akira, Operation Endgame, and AI Data Exposure

In November 2025, the cybersecurity landscape was rocked by a surge of major incidents spanning data exposure at leading AI companies, a high-profile ransomware campaign by the Akira gang, and an unprecedented law enforcement operation targeting prolific malware families. Attackers leveraged advanced lateral movement and encryption bypass techniques, with Akira exfiltrating critical business data and setting new records for ransom hauls. Meanwhile, Operation Endgame—an international collaborative effort—dismantled several prominent malware botnets, arresting key operators and seizing digital infrastructure, all while organizations scrambled to contain threats and patch vulnerabilities across multi-cloud and hybrid environments. This period highlights a convergence of advanced extortion, data privacy, and large-scale coordinated response, reflecting escalating threat sophistication and the increasing pressure on organizations to meet evolving compliance and security demands.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
AI-Fueled LLMs Put Advanced Attacks in Reach for Novice Hackers (2024)
Impact· medium

AI-Fueled LLMs Put Advanced Attacks in Reach for Novice Hackers (2024)

In early 2024, cybersecurity researchers observed a surge in the use of malicious, unrestricted large language models (LLMs) such as WormGPT 4 and KawaiiGPT. These AI-powered tools have been weaponized to generate sophisticated attack scripts—including ransomware encryptors and custom code for lateral movement—allowing even low-skilled threat actors to execute complex cyberattacks. Access to these malicious LLMs was facilitated via underground markets, democratizing advanced techniques and increasing the frequency and complexity of attacks targeting organizations across multiple sectors. This incident underscores a growing trend where AI-enabled cyber threats lower the barrier to entry for attackers. As malicious LLMs gain capabilities and proliferation increases, organizations face heightened risks from a new wave of adversaries and must adapt their defenses to address evolving, AI-driven tactics.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Over 17,000 Secrets Exposed: Inside the 2024 GitLab Public Repository Incident
Impact· medium

Over 17,000 Secrets Exposed: Inside the 2024 GitLab Public Repository Incident

In early 2024, a security engineer conducting a large-scale scan of all 5.6 million public repositories hosted on GitLab Cloud uncovered more than 17,000 exposed secrets—such as API keys, credentials, and tokens—affecting over 2,800 unique domains. Although the incident did not involve a targeted cyberattack, the finding highlights the pervasive risk of accidental data exposure due to developer error or misconfiguration. The exposed secrets could have enabled threat actors to access sensitive services, launch attacks, or exfiltrate data unnoticed, exposing organizations to operational risk, reputational harm, and regulatory scrutiny. This discovery signals a growing trend as attackers increasingly automate scans for leaked credentials in public code repositories. With supply chain attacks, shadow IT, and cloud misconfigurations rising, such incidents underscore the urgency for automated secret scanning, centralized controls, and enhanced security training for development teams.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Australia 2024 Airport Evil Twin WiFi Attack: Network Intrusion Threat Exposed
Impact· low

Australia 2024 Airport Evil Twin WiFi Attack: Network Intrusion Threat Exposed

In 2024, Australian authorities sentenced a 44-year-old man to over seven years in prison for orchestrating a series of 'evil twin' WiFi attacks at major Australian airports. The perpetrator set up rogue wireless networks mimicking legitimate airport WiFi, luring unsuspecting travelers into connecting and unknowingly handing over sensitive data, including credentials and personal information. Over a prolonged period, these attacks evaded detection due to the sophistication of the deceptive access points and inherent insecurity of public wireless networks. The incident highlighted significant risks for both individuals and organizations, demonstrating effective tactics for harvesting credentials in the wild. This case exemplifies a broader trend of attackers exploiting public and unsecured networks to launch network intrusion campaigns, especially as remote work and mobile connectivity surge. Such methods bypass conventional perimeter defenses and increase compliance and regulatory pressures for organizations to protect data in transit.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports