Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
Nation-State Breach Hits Congressional Budget Office: 2024 Lessons
In early June 2024, the Congressional Budget Office (CBO), a key federal agency supplying budget and economic analysis to Congress, experienced a cybersecurity breach by a suspected nation-state actor. Attackers reportedly infiltrated CBO systems and may have accessed sensitive communications between lawmakers and agency researchers. Upon discovery, CBO moved quickly to contain the incident, implemented additional monitoring, and strengthened security controls. The breach echoed previous attacks on congressional entities by sophisticated threat actors aiming to compromise confidential governmental data and influence legislative processes. This incident highlights increasing targeting of government research bodies by foreign espionage groups seeking sensitive intelligence. With agencies routinely handling politically sensitive and high-value data, robust cybersecurity defenses and rapid incident response are now critical amid heightened global threat actor activity.
8 months ago
Kill Chain
Cisco's 2024 Critical UCCX Flaw Exposes Root-Level Risks
In June 2024, Cisco disclosed a critical vulnerability (CVE-2024-20253) in its Unified Contact Center Express (UCCX) software, which could allow remote attackers to execute arbitrary commands with root privileges on affected systems. The flaw, which is due to improper validation of user-supplied input, does not require user authentication and is rated 9.9 out of 10 in severity. Malicious actors exploiting this vulnerability could gain full control over the underlying infrastructure, potentially leading to data breaches, service interruptions, or lateral movement within an organization's network. Cisco has issued security patches, and there are currently no reports of exploitation in the wild. The incident underscores the urgent need for prompt patch management and reinforces the trend of attackers rapidly leveraging zero-day and critical vulnerabilities in widely deployed enterprise platforms. Organizations must prioritize vulnerability management and maintain strict network segmentation to contain similar risks in their environments.
8 months ago
Kill Chain
ClickFix Evolves: Multi-OS Malware Delivered with Social Engineering and Video Tutorials
In early 2024, cybersecurity researchers observed a sharp evolution in the ClickFix malware campaign, which began targeting users with tailored multi-operating system payloads accompanied by step-by-step video tutorials to aid self-infection. The attackers employed social engineering by pressuring victims with countdown timers and offering clear, OS-specific instructions, effectively lowering the barrier for successful compromise. Leveraging these tactics, the malware operators could achieve widespread distribution, enabling credential theft and system control on both Windows and macOS platforms, and increasing risk of lateral movement across enterprise environments. This incident highlights a broader trend of combining technical innovation with advanced social engineering, making malware delivery easier and more efficient. The streamlined, multi-OS approach and use of multimedia content signal a significant shift in attacker tactics, accelerating the threat landscape and challenging traditional security awareness programs.
8 months ago
Kill Chain
SonicWall Cloud Backup Breach: How State-Sponsored Attackers Exploited API Weaknesses in 2025
In September 2025, SonicWall confirmed that state-sponsored threat actors orchestrated a security breach targeting its cloud backup environment. The attackers exploited an API vulnerability to gain unauthorized access to firewall configuration backup files stored in a specific cloud deployment. SonicWall's investigation determined the breach was limited to the exposure of these configuration files, with no evidence of lateral movement or impact to production systems. The breach prompted immediate containment actions, disclosure to affected customers, and a global review of cloud access controls and incident response procedures. This incident underscores the increasing risk posed by sophisticated, nation-state adversaries targeting cloud environments and API endpoints. It highlights how misconfigurations and insufficient segmentation in cloud infrastructure can facilitate data exposure, driving industry-wide reassessment of cloud-native security and compliance practices.
8 months ago
Kill Chain
Malicious AI Extension Sneaks onto VS Code Marketplace in Supply Chain Breach (2024)
In early June 2024, a malicious extension possessing rudimentary ransomware functionality, allegedly built with the aid of artificial intelligence, was discovered in Microsoft's Visual Studio Code (VS Code) Marketplace. The extension leveraged VS Code's trusted distribution to sneak past safeguards and, once installed, had the capability to encrypt targeted user files and demand a ransom. This supply chain attack was detected before it could be widely abused, but it highlights how adversaries are using AI to generate and deploy sophisticated threats within software ecosystems. This incident demonstrates a growing trend where supply chain platforms, such as code repositories and marketplaces, are exploited to gain privileged entry within developer environments. The blending of AI-enabled malware automation and trusted application channels raises urgent visibility, compliance, and policy enforcement concerns for organizations.
8 months ago
Kill Chain
Curly COMrades Weaponize Hyper-V: How Linux VMs Helped Evade Detection in 2025 Breach
In October 2025, the advanced persistent threat group Curly COMrades launched a sophisticated attack campaign exploiting Windows Hyper-V virtualization to evade endpoint detection and response (EDR) solutions. By covertly enabling Hyper-V on targeted systems, attackers deployed a minimal Alpine Linux-based virtual machine (VM) hidden within Windows hosts. This VM served as an isolated enclave to execute custom malware and facilitate command-and-control activities, significantly complicating detection and forensics for defenders. Victims experienced unauthorized data access and increased potential for lateral movement, while standard EDR tools failed to monitor the malicious payloads running inside the guest VM. This attack highlights a growing trend of leveraging virtualization and container technologies to bypass security controls. As organizations increasingly adopt hybrid and multi-cloud environments, adversaries are developing novel methods to mask malicious operations from traditional detection mechanisms, underscoring the need for advanced visibility and zero trust segmentation.
8 months ago
Kill Chain
Cisco Firewall DoS Attack: How CVE-2025-20333 & CVE-2025-20362 Disrupted Critical Networks
In November 2025, Cisco disclosed a vulnerability exploitation campaign targeting its Secure Firewall ASA and Threat Defense (FTD) devices. Threat actors actively weaponized two zero-day vulnerabilities, CVE-2025-20333 and CVE-2025-20362, to force vulnerable appliances to unexpectedly reload, resulting in denial-of-service (DoS) conditions that disrupted network operations. Affected organizations saw service disruptions, increased operational risk, and potential visibility gaps, especially where patch management or segmentation was lacking. Cisco responded by recommending immediate updates, enhanced monitoring, and deployment of compensating security controls until all devices are patched. This incident underscores a continuing trend of attackers rapidly exploiting unpatched firewall vulnerabilities, threatening the network perimeter’s reliability. The rise in sophisticated DoS tactics against infrastructure devices points to an urgent need for proactive patching, segmentation, and visibility into both perimeter and east-west traffic.
8 months ago
Kill Chain
Credential Stuffing at Scale: 2 Billion Email Addresses and 1.3 Billion Passwords Exposed in 2025
In late 2025, a massive credential stuffing incident came to light when nearly 2 billion email addresses and 1.3 billion unique passwords – sourced over years from various cybercriminal forums and compromised stealer logs – were aggregated and indexed by Synthient, then processed by Have I Been Pwned (HIBP) for user notification. The dataset included credentials from countless breaches, consolidated into one of the largest exposures of its kind to date. While the original leaks stemmed from malware infections, phishing, and prior breaches, the impact was compounded by password reuse and the easy redistribution of these records in the criminal underground. HIBP took technical and privacy-preserving steps to verify and notify affected users while preventing further risk of data linkage. This incident illustrates the ongoing risks posed by credential stuffing and highlights the long lifecycle of exposed data as threat actors continuously recycle and combine compromised information. The event underscores the importance of password hygiene, multi-factor authentication, and proactive notification as recycled data fuels ongoing cyberattacks across industries.
8 months ago
Kill Chain
Phishing Attack Delivers Kalambur Backdoor via Trojanized ESET Installers in Ukraine
In May 2025, a Russia-aligned threat group tracked as InedibleOchotense conducted a spear-phishing campaign targeting Ukrainian organizations. Attackers impersonated Slovak security company ESET, delivering phishing emails and Signal messages containing malicious links to trojanized ESET installers. When unsuspecting victims executed these files, a previously undocumented backdoor named Kalambur was installed, granting attackers covert access to compromised systems and enabling persistent network reconnaissance, command execution, and data exfiltration. The impersonation of a well-known cybersecurity firm lent the campaign added credibility, elevating its success rate and risk to targeted entities. This incident is a stark illustration of evolving phishing TTPs that exploit software supply chain trust and employ realistic impersonation. The campaign highlights the enduring threat posed by nation-state actors employing sophisticated lures, and underscores the urgent need for vigilant software validation, phishing awareness, and robust protective controls across organizations operating in high-risk geopolitical regions.
8 months ago
Kill Chain
Coinbase Hit by 2024 Phishing Attack Orchestrated by Scattered Spider
In February 2024, cryptocurrency exchange Coinbase experienced a sophisticated phishing attack executed by the 0ktapus (Scattered Spider) threat actor. Attackers sent targeted SMS and email messages to select Coinbase employees, impersonating IT support and leveraging social engineering to harvest login credentials and multi-factor authentication codes. They subsequently accessed internal dashboards, potentially viewing sensitive customer data. Prompt monitoring enabled Coinbase’s security team to detect the unusual access and contain the breach before widespread damage occurred, mitigating customer impact and avoiding direct financial loss. This incident highlights the increasing sophistication of phishing campaigns targeting high-value organizations, particularly those with significant user assets like Coinbase. Advanced phishing, often enabled by multi-stage social engineering and MFA bypass techniques, is intensifying across critical sector organizations in 2024.
8 months ago
Kill Chain
Bronze Butler Exploits Zero-Day to Breach Japanese Enterprise Networks
In early 2025, Chinese state-sponsored APT group 'Bronze Butler' exploited a zero-day vulnerability (CVE-2025-61932) in a widely used endpoint management platform to penetrate several Japanese organizations. The attackers gained privileged access by leveraging the flaw for initial compromise, then established persistence and moved laterally across victims’ networks. Exfiltrated data included sensitive business documents and internal communications. The coordinated campaign went undetected for weeks, resulting in significant operational disruption and exposure of confidential assets, raising alarms about cyber-espionage threats facing Japan’s critical industries. This breach highlights the intensifying use of zero-day vulnerabilities by advanced threat actors for targeting supply chain software and trusted management tools. Similar recent attacks signal a broader trend of sophisticated, nation-state-driven intrusions against key sectors in Asia, and reinforce the urgent need for proactive patch management and stronger east-west network segmentation.
8 months ago
Kill Chain
Multiple ChatGPT Security Bugs Expose User Data in 2023 OpenAI Breach
In March 2023, OpenAI faced a significant application security incident involving multiple vulnerabilities within its flagship ChatGPT platform. Attackers exploited bugs that enabled prompt injection, retrieval of other users’ conversation histories, and potential bypassing of safety restrictions, exposing sensitive user data and proprietary prompts. These exploits, which allowed lateral movement and unauthorized data exfiltration, highlighted systemic issues in handling session tokens, API security, and isolation of user environments. The breaches forced OpenAI to temporarily take ChatGPT offline, conduct emergency patching, notify users, and engage external security review. The operational impact included reputational damage and increased regulatory scrutiny over cloud-based AI platforms’ data handling. This event underscores the growing risk as generative AI platforms become integral to business operations and personal productivity. The use of increasingly complex APIs and reliance on cloud-native architecture have introduced new attack surfaces, making timely detection and robust segmentation critical. Regulatory bodies and security practitioners now regard application-layer lateral movement and API leakage as top-tier threats, especially given AI’s centrality to enterprise workflows.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports