Industry Category

Financial Services

Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.

4282 threat reports
Page 306 of 357

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Financial Services Threat Reports

Showing 36613672 / 4282 reports
SnakeStealer: 2024's Most Prolific Infostealer and Its Impact on Data Security
Impact· medium

SnakeStealer: 2024's Most Prolific Infostealer and Its Impact on Data Security

In early 2024, cybersecurity researchers identified a widespread surge in SnakeStealer malware infections targeting individuals and organizations across multiple sectors. This sophisticated infostealer penetrates devices through malicious attachments and compromised software, rapidly harvesting valuable personal and corporate information including browser credentials, cryptocurrency wallets, and sensitive documents. Once data is collected, it is exfiltrated to attacker-controlled servers, fueling cybercrime operations and secondary attacks. The rapid spread and effectiveness of SnakeStealer has led to significant business and operational risks, such as unauthorized access, data breaches, and identity theft. This incident highlights the escalating threat posed by modern infostealers, which continue to evolve their techniques to bypass security controls and evade detection. The sustained activity of SnakeStealer, coupled with copycat variants, underscores a trend of increasingly sophisticated, financially motivated cybercrime targeting both enterprise and individual data at scale.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
North Korean Operatives Pose as IT Job Seekers to Infiltrate Western Companies
Impact· medium

North Korean Operatives Pose as IT Job Seekers to Infiltrate Western Companies

In 2023, multiple Western technology firms fell victim to a sophisticated insider threat campaign involving North Korean operatives posing as freelance IT job seekers. These actors used false identities and forged CVs to secure remote employment and gain access to sensitive corporate environments. Once inside, they leveraged their positions to siphon proprietary information, commit financial fraud, and, in some cases, facilitate broader cyber-espionage activities by collecting credentials and mapping internal systems. The impact spanned financial loss, reputation damage, and increased exposure to supply chain attacks. This incident highlights the growing trend of well-resourced nation-state actors exploiting remote work arrangements and third-party talent networks. As companies aggressively scale digital transformation and outsourcing, vigilance against social engineering and identity fraud is critical to mitigate the risk of covert infiltration and regulatory non-compliance.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Pixel KASLR Bypass: Linear Map Non-Randomization Threatens Android Kernel Security
Impact· low

Pixel KASLR Bypass: Linear Map Non-Randomization Threatens Android Kernel Security

In November 2025, security researchers from Google Project Zero disclosed a significant design flaw in the Linux kernel’s implementation of Kernel Address Space Layout Randomization (KASLR) on modern Android devices, specifically Google Pixel phones. The weakness stems from the lack of randomization in both the linear kernel mapping and the physical memory loading address of the kernel itself. As a result, attackers with an arbitrary read/write primitive could derive static kernel virtual addresses, bypassing KASLR protections without leaks—thereby making exploitation significantly easier and increasing the risk of privilege escalation and persistence. This incident underscores a broader industry challenge where operating system mitigations lag behind evolving attacker techniques. The exposure of predictable kernel virtual addresses on widely deployed Android devices highlights the urgency for stronger kernel randomization and renewed attention to memory safety for mobile platforms.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
How OAuth Device Code Phishing Targets Azure and Google: What CISOs Need to Know in 2024
Impact· low

How OAuth Device Code Phishing Targets Azure and Google: What CISOs Need to Know in 2024

In 2024, new phishing campaigns emerged that weaponize the OAuth Device Code flow against major cloud platforms, notably Azure and Google. Attackers send users to authentic device code portals, tricking them into entering codes controlled by adversaries. Once codes are entered, threat actors receive valid OAuth tokens granting extensive access to cloud services, often bypassing multi-factor authentication. Researchers noted that Azure’s device flow presented a larger attack surface than Google’s, making it a high-value target for phishing and account compromise. The result is unauthorized access to sensitive email, data, and other cloud resources, with potential for lateral movement and persistent compromise. This breach showcases a rapidly escalating attack vector exploiting weaknesses in cloud identity flows. The rise in device code phishing reflects a broader shift by threat actors toward abusing legitimate authentication processes, especially as organizations depend more heavily on cloud services and OAuth-based SSO.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Microsoft's WSUS Security Patch Disrupts Windows Server 2025 Hotpatching
Impact· medium

Microsoft's WSUS Security Patch Disrupts Windows Server 2025 Hotpatching

In June 2024, Microsoft released an out-of-band (OOB) security update to address an actively exploited vulnerability within Windows Server Update Services (WSUS). While the patch mitigates a critical security risk, it has inadvertently broken hotpatching functionality on certain Windows Server 2025 systems. Hotpatching allows for critical updates without rebooting servers, so this unintended consequence impacts business continuity and planned maintenance windows, affecting organizations relying on continuous operation. This incident highlights the ongoing challenges of patch management, especially when rapid updates for zero-day vulnerabilities disrupt core services. As threat actors increasingly target software supply chains and patch-delivery mechanisms, IT teams face growing pressure to balance security and operational stability.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Microsoft 2024: SesameOp Backdoor Hides in OpenAI Assistants API Traffic
Impact· low

Microsoft 2024: SesameOp Backdoor Hides in OpenAI Assistants API Traffic

In early 2024, Microsoft researchers identified a sophisticated cyberattack campaign leveraging the new SesameOp backdoor malware. This threat exploits the OpenAI Assistants API as a covert command-and-control (C2) channel, enabling attackers to execute commands, exfiltrate data, and maintain persistence within compromised environments while masquerading as legitimate AI-driven traffic. The campaign targets organizations by bypassing traditional detection methods, using this unique abuse of generative AI services to hide communications and evade security controls. The operational impact is significant, posing increased risk for data loss, lateral movement, and regulatory exposure due to the highly obfuscated methodology. This incident underscores a rapid evolution in attacker tradecraft, with adversaries now weaponizing mainstream AI APIs for malicious infrastructure. As organizations accelerate adoption of AI technologies, this event highlights the urgency to address emerging risks of shadow AI and sophisticated backdoors, making robust east-west traffic inspection and AI-risk governance more important than ever.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Insiders Indicted: BlackCat Ransomware Attacks Orchestrated by US Cybersecurity Experts (2023)
Impact· high

Insiders Indicted: BlackCat Ransomware Attacks Orchestrated by US Cybersecurity Experts (2023)

Between May and November 2023, three former employees of DigitalMint and Sygnia—both incident response firms—were indicted following allegations that they leveraged insider knowledge to facilitate BlackCat (ALPHV) ransomware attacks on five U.S. companies. These individuals reportedly gained unauthorized access to sensitive networks, deployed BlackCat ransomware, and demanded significant payouts, resulting in operational disruptions, data encryption, and potential data exposure for affected organizations. The attackers’ technical expertise made detection difficult, and their actions exploited gaps in internal network security, east-west monitoring, and threat detection protocols. This incident highlights the evolving threat posed by malicious insiders and the intersection of human risk with sophisticated ransomware-as-a-service operations. The case underscores the urgency for organizations to enhance identity-based segmentation, rigorous monitoring of internal activity, and to adapt cybersecurity policies to counter both external and internal threats.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Balancer DeFi Protocol Hit by $128M Crypto Heist: How the 2023 Breach Happened
Impact· high

Balancer DeFi Protocol Hit by $128M Crypto Heist: How the 2023 Breach Happened

In August 2023, the Balancer DeFi protocol suffered a sophisticated cyberattack when unidentified hackers exploited vulnerabilities in its v2 pools’ smart contract logic. By manipulating pool configurations and utilizing flash loans, attackers drained over $128 million worth of cryptocurrency assets. Balancer immediately paused affected pools, notified users, and worked to contain losses. The exploit drew industry-wide concern due to the depth and speed of the attack, which bypassed several security checks and resulted in substantial losses for protocol users and liquidity providers. This incident underscores the growing security challenges facing decentralized finance platforms, as attackers increasingly target smart contracts and protocol logic. The Balancer breach highlights the need for advanced anomaly detection, smart contract auditing, and zero trust security controls in Web3 environments as DeFi adoption accelerates.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
Fake Solidity VSCode Extension Backdoors Developers in 2024 Supply Chain Attack
Impact· medium

Fake Solidity VSCode Extension Backdoors Developers in 2024 Supply Chain Attack

In early 2024, a malicious Visual Studio Code extension impersonating the popular Solidity plugin was discovered on the Open VSX Registry, a prominent open-source extension marketplace. The extension secretly installed the SleepyDuck remote access trojan. Threat actors leveraged an Ethereum smart contract to covertly communicate with infected developer environments, establishing a covert command and control channel. Dozens of unsuspecting developers who installed the fake extension were exposed to potential source code theft, workspace compromise, and broader supply chain risk for any software subsequently produced on affected systems. This incident highlights the escalating threat posed by supply chain attacks via open-source repositories and package registries, particularly those targeting development toolchains. Increasingly, attackers are exploiting trust in popular extensions, emphasizing the urgent need for organizations to bolster code integrity controls and enforce zero trust principles for their build environments.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Kimsuky Deploys HttpTroy Backdoor in Sophisticated VPN-Phishing Attack Against South Korea
Impact· low

Kimsuky Deploys HttpTroy Backdoor in Sophisticated VPN-Phishing Attack Against South Korea

In late 2025, the North Korean advanced persistent threat (APT) group Kimsuky launched a targeted cyberattack against an organization in South Korea using a previously undocumented backdoor dubbed 'HttpTroy.' Leveraging a spear-phishing email containing a malicious ZIP file disguised as a VPN invoice, the attackers tricked the recipient into extracting and running a disguised executable. Once executed, HttpTroy enabled encrypted communication with attacker-controlled infrastructure, allowing remote data exfiltration and persistent access. This covert operation underscored the group's ongoing focus on espionage, intelligence collection, and the use of custom malware to evade detection. This incident is significant due to the rise of spear-phishing attacks deploying novel backdoors and the persistence of state-sponsored threats targeting geopolitical rivals. It highlights the necessity for vigilant endpoint monitoring, advanced traffic analysis, and robust segmentation to limit attacker lateral movement and safeguard sensitive communications.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Lazarus Group Orchestrates Major 2025 Web3 Multi-Vector Breach
Impact· medium

Lazarus Group Orchestrates Major 2025 Web3 Multi-Vector Breach

In November 2025, the Lazarus Group executed a sophisticated multi-vector attack campaign targeting several high-profile Web3 and cryptocurrency organizations. Utilizing social engineering and supply-chain attacks, the threat actors exploited newly disclosed vulnerabilities in trusted hardware (including Intel and AMD TEEs) mere hours after public disclosures. Attackers employed encrypted C2 channels, lateral movement tools, and advanced ransomware, allowing them to bypass internal segmentation and traverse east-west across internal networks. The result was significant compromise of sensitive assets, encrypted backups, and leakage of confidential data, leading to operational disruption and reputational harm to victims. This incident is especially noteworthy due to the rapid attacker adaptation to zero-day vulnerabilities, the blending of traditional and cloud-native threat techniques, and Lazarus’s evolution in targeting decentralized platforms. The attack highlights the increasing complexity and urgency of defending distributed infrastructure against agile, persistent threat actors.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
BankBot-YNRK and DeliveryRAT: Sophisticated Android Trojans Targeting Financial Data
Impact· medium

BankBot-YNRK and DeliveryRAT: Sophisticated Android Trojans Targeting Financial Data

In November 2025, cybersecurity researchers discovered the active deployment of two advanced Android trojans, BankBot-YNRK and DeliveryRAT, targeting users across multiple financial and delivery service platforms. The trojans infiltrated devices primarily through deceptive apps and phishing schemes, with BankBot-YNRK leveraging anti-analysis techniques to evade detection by testing for emulated and virtualized environments before unleashing its data theft capabilities. DeliveryRAT, meanwhile, provided attackers with remote access for layered exploitation. Both malware families are capable of harvesting sensitive personal and financial data, making banking credentials and payment details accessible to threat actors, potentially leading to significant financial losses and privacy violations for affected users and organizations. This incident highlights the evolving sophistication of Android-targeted infostealers, which increasingly combine stealth, anti-analysis, and remote access tactics. The attack underscores the urgent need for organizations and end-users to enhance mobile threat defenses and rapidly adapt to emerging malware targeting the growing mobile financial ecosystem.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports