Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
Tycoon 2FA: How Phishing-as-a-Service Broke Legacy MFA at Scale in 2024
In 2024, cybercriminals leveraged the Tycoon Phishing-as-a-Service (PaaS) platform to orchestrate over 64,000 successful real-time attacks bypassing legacy multi-factor authentication (MFA) with relay-based phishing toolkits. Tycoon allowed even low-skilled attackers to automate the interception and relay of users’ MFA tokens, defeating common one-time passcodes and push-based authentication. This Phishing-as-a-Service campaign targeted a wide array of industries and organizations, exposing user credentials and compromising sensitive systems at scale. The incident underscores the urgent collapse of legacy MFA methods under modern, scalable phishing threats. The widespread exposure from Tycoon demonstrates how phishing-resistant authentication (such as FIDO2 hardware tokens and biometrics) are now critical. Regulatory agencies and security experts have since elevated calls for organizations to rapidly phase out vulnerable MFA in favor of hardware-backed solutions, as attackers weaponize automated, scalable PaaS infrastructure.
8 months ago
Kill Chain
Pajemploi Data Breach Exposes 1.2 Million French Citizens: What Went Wrong?
In June 2024, French public agency Pajemploi, responsible for social security management for parents and home childcare providers, suffered a large-scale data breach. Attackers exploited a flaw in the agency's online system that enabled them to access personal data belonging to approximately 1.2 million individuals, including names, addresses, social security numbers, bank details, and tax identification data. The breach was discovered after abnormal activity was detected, and Pajemploi acted swiftly to close the vulnerability, notify affected users, and inform regulatory authorities, including France's data privacy regulator CNIL. The incident temporarily restricted access to certain online services for impacted users. This breach highlights the ongoing targeting of government and public-sector databases holding sensitive citizen data. With regulatory requirements such as GDPR placing heavy penalties on agencies that fail proper controls, the Pajemploi incident underscores the urgency of robust data protection, zero trust segmentation, and advanced anomaly detection across Europe’s digital public services.
8 months ago
Kill Chain
Google Chrome’s 2025 V8 Zero-Day: What Organizations Must Do After the Latest Exploit
In June 2025, Google disclosed an actively exploited zero-day vulnerability (CVE-2025-13223) in the V8 JavaScript and WebAssembly engine powering Chrome. Attackers leveraged this type confusion flaw to execute arbitrary code or trigger program crashes, enabling them to compromise vulnerable browsers. Google promptly released patches to address the flaw after receiving reports of in-the-wild exploitation. At-risk users included anyone running unpatched Chrome versions across platforms, with attackers potentially able to hijack sessions, install malware, or steal sensitive data simply by enticing users to visit a malicious web page. This incident highlights the persistent risks posed by emerging browser vulnerabilities, as both sophisticated threat actors and opportunistic cybercriminals increasingly exploit zero-day flaws for rapid compromise. Security teams face mounting urgency to prioritize browser patching cycles to counter fast-moving, exploitation-ready threats.
8 months ago
Kill Chain
Microsoft Thwarts Record-Breaking 15.72 Tbps DDoS Attack Orchestrated by AISURU Botnet
In November 2025, Microsoft successfully detected and mitigated an unprecedented Distributed Denial-of-Service (DDoS) attack that peaked at 15.72 Tbps, targeting a cloud endpoint in Australia. The attack, orchestrated by the AISURU botnet leveraging TurboMirai-class malware, generated nearly 3.64 billion packets per second. Advanced protections within Microsoft's Azure platform automatically neutralized the threat before it could affect customer availability or data. Microsoft attributed the attack to highly automated botnets leveraging compromised IoT devices and observed a rapid, multi-vector assault designed to test cloud resilience and incident response. This record-breaking event highlights the escalating scale and sophistication of DDoS activity targeting foundational cloud infrastructure. As attackers exploit larger IoT botnets and novel malware strains, defenders face mounting pressure to evolve detection and mitigation at cloud-scale. Organizations must increasingly invest in robust DDoS protection and continuously monitor for emerging threats.
8 months ago
Kill Chain
ShadowRay 2.0: How Ray Cluster Flaws Fueled a Cryptomining Botnet
In June 2024, cybersecurity researchers identified a coordinated global attack campaign dubbed ShadowRay 2.0 targeting exposed Ray clusters—open-source distributed computing environments widely used in AI and machine learning workloads. Attackers exploited an unpatched remote code execution vulnerability in Ray's dashboard service, gaining unauthorized access to cloud and on-premises clusters. Once inside, adversaries deployed self-spreading cryptomining malware, turning infected clusters into part of a large-scale botnet that harnessed high-performance compute resources for illicit cryptocurrency mining, causing potential performance degradation, elevated cloud bills, and risk of further lateral movement. This campaign demonstrates the growing threat surface posed by AI and data infrastructure, as adversaries increasingly automate the exploitation of software supply chain and configuration weaknesses. The incident highlights the urgency of securing east-west traffic, enforcing least privilege, and maintaining continuous vulnerability management in distributed and cloud-native environments.
8 months ago
Kill Chain
npm Supply-Chain Threat: Seven Malicious Packages Cloak Crypto Scams in 2025
In late 2025, cybersecurity researchers uncovered a supply-chain attack involving seven malicious npm packages uploaded by the threat actor 'dino_reborn.' These packages leveraged Adspect cloaking technology to detect if visitors were victims or security researchers. Unsuspecting users were redirected to fraudulent cryptocurrency-themed websites, exposing them to potential scams or malware. The packages were published between September and November 2025 and remained available until detection, highlighting the challenges in securing open-source ecosystems. This incident is part of a growing trend involving supply-chain attacks targeting widely used software repositories. As more attackers adopt advanced evasion measures like traffic cloaking and nuanced social engineering, the risk and complexity of defending modern development pipelines are rapidly increasing.
8 months ago
Kill Chain
Researchers Reveal Tuoni C2’s Role in 2025 Real-Estate Cyber Attack
In early November 2025, a prominent U.S.-based real-estate company was targeted in a sophisticated cyber attack utilizing the Tuoni command-and-control (C2) framework, a new red-teaming tool known for implementing stealthy, in-memory payload delivery. The attackers exploited Tuoni C2’s advanced capabilities to infiltrate the network while evading traditional security controls, demonstrating lateral movement and attempting data collection within internal segments. Although swift detection halted major exfiltration, the intrusion highlighted gaps in east-west traffic visibility and segmentation, causing temporary disruption to key business systems and prompting an urgent review of internal controls. This attack underscores the growing trend of adversaries adopting novel, freely available C2 tools to bypass existing enterprise defenses. It reflects broader industry concern as C2 frameworks like Tuoni fuel increased attack sophistication, especially in sectors handling large volumes of sensitive data such as real estate and finance.
8 months ago
Kill Chain
Sneaky 2FA Kit Innovates with BitB Pop-up Phishing: MFA Bypass at Scale
In November 2025, security researchers reported on the evolving Sneaky 2FA Phishing-as-a-Service (PhaaS) kit, which now features sophisticated Browser-in-the-Browser (BitB) pop-ups that convincingly mimic legitimate browser address bars. These enhancements enable threat actors, including low-skilled attackers, to deploy highly realistic phishing attacks at scale and bypass multi-factor authentication (MFA) protections. Victims, typically employees of enterprises and large organizations, are tricked into entering credentials and 2FA codes into deceptive portals, facilitating account compromise and potential unauthorized access to sensitive business assets. This incident highlights a troubling trend of phishing toolkits increasing in sophistication, making advanced attacks accessible to broader criminal audiences. Organizations are now facing growing regulatory and operational pressure to update authentication, identity protection, and detection controls amid a wave of phishing leveraging MFA bypass and deceptive visual TTPs.
8 months ago
Kill Chain
CISA Flags Critical Fortinet FortiWeb Vulnerability: CVE-2025-58034 Joins KEV Catalog
In November 2025, CISA added CVE-2025-58034, a Fortinet FortiWeb OS Command Code Injection vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog following evidence of in-the-wild exploitation against internet-exposed FortiWeb appliances. Threat actors leveraged this critical flaw to execute arbitrary system commands remotely, enabling them to gain unauthorized access, pivot laterally, or deploy additional malware. The urgency was amplified by ongoing exploitation and a recently published Fortinet security advisory, prompting CISA to recommend an accelerated one-week remediation deadline for federal and enterprise environments. This incident exemplifies the continued targeting of web application infrastructure by attackers exploiting unpatched devices. The rapid exploitation timeline, coupled with directives like BOD 23-02, highlights the increasing regulatory focus and operational risk posed by known—but unremediated—vulnerabilities in public-facing systems.
8 months ago
Kill Chain
Malicious npm Packages Leverage Adspect Cloaking to Fuel Crypto Supply Chain Scam (2024)
In early 2024, a sophisticated supply chain attack was uncovered involving a wave of malicious npm packages that abused Adspect cloaking techniques to avoid detection. Attackers published seemingly benign JavaScript libraries to the official npm registry. Once installed, these packages deployed malware via fake cryptocurrency-related sites, using cloaking to distinguish between legitimate victims and security researchers. The campaign allowed threat actors to evade automated scans, maximize the longevity of their malicious payloads, and target developers and end users with credential theft and crypto scams. This incident highlights the evolving threat landscape around open-source software supply chains. The use of advanced traffic cloaking and victim filtering marks a new escalation in attacker TTPs, forcing organizations to revisit how they vet third-party dependencies and monitor developer ecosystems for hidden threats.
8 months ago
Kill Chain
KongTuke 2025: Real-World Insights from a Fake CAPTCHA Malware Campaign
In November 2025, the KongTuke threat actor (also referenced as LandUpdate808 or TAG-124) orchestrated a malware campaign leveraging sophisticated Traffic Distribution System (TDS) techniques. The attackers compromised legitimate websites by injecting malicious scripts that displayed fake CAPTCHA pages designed to lure victims into executing clipboard-injected PowerShell commands. Once executed, these commands downloaded a ZIP archive containing a Windows-compatible Python environment and a malicious Python script, which established persistence via scheduled tasks and generated encrypted HTTPS traffic to external infrastructure. The infection sequence was confirmed within Active Directory environments, highlighting the attacker's ability to evade detection and automate persistence. This incident underscores an increasing trend in malware distribution leveraging trusted websites as initial access vectors, blending social engineering with technical innovation. Organizations should take note of the evolving sophistication in initial lure tactics and persistence mechanisms, as such approaches complicate traditional detection methods and pose substantial risk to enterprise endpoints.
8 months ago
Kill Chain
Fortinet’s Silent Patch Leaves FortiWeb Customers Exposed to Critical Exploit in 2024
In October 2024, Fortinet faced significant criticism after a critical vulnerability (CVE-2025-64446) in its FortiWeb application firewall was exploited by attackers before the flaw was publicly disclosed or a CVE was assigned. Although a patch was silently released on October 28, public notification and technical details were delayed for over two weeks, leaving customers unaware of the immediate risk posed by the vulnerability. During this window, attackers leveraged a path-traversal bug to gain administrative command execution and persistent access, potentially compromising affected infrastructures and evading detection until after widespread exploitation was underway. This incident highlights the increasing risk that delayed vulnerability disclosures pose to organizations, as attackers can weaponize defects before defenders are informed. The event has intensified calls for timely vendor transparency and reinforced scrutiny from regulators as the cyber threat landscape evolves toward faster exploitation cycles and greater demands for coordinated defensive action.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports