Industry Category

Financial Services

Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.

4278 threat reports
Page 308 of 357

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless
Writing/Editing

Financial Services Threat Reports

Showing 36853696 / 4278 reports
2025 Lanscope Zero-Day: Tick APT’s Attack on Corporate Systems
Impact· low

2025 Lanscope Zero-Day: Tick APT’s Attack on Corporate Systems

In October 2025, the cyber espionage group Tick (also known as Bronze Butler), believed to be linked to China, exploited CVE-2025-61932—a critical zero-day vulnerability (CVSS 9.3) affecting Motex Lanscope Endpoint Manager. The attackers gained remote SYSTEM-level access to targeted on-premise environments, allowing them to hijack corporate systems and exfiltrate sensitive data. The attack chain involved leveraging the flaw for command execution, facilitating lateral movement and persistence within victim organizations, primarily impacting Japanese and East Asian enterprises. Authorities issued advisory alerts urging immediate remediation to prevent data loss and further intrusions. This incident underscores the growing operational risk posed by nation-state actors exploiting enterprise endpoint vulnerabilities. It highlights an escalation in zero-day weaponization and reinforces the need for robust segmentation, endpoint monitoring, and proactive patch management amid intensifying APT activity and regulatory scrutiny.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
LotL Malware Concealed in Windows Native AI Stack Exposes New Risks
Impact· low

LotL Malware Concealed in Windows Native AI Stack Exposes New Risks

In early 2024, security researchers uncovered a Living-off-the-Land (LotL) attack that leveraged Windows' native AI stack to conceal and deploy malware within trusted AI data files. Attackers exploited the inherent trust that many Windows systems grant to files used by the native AI stack, allowing the threat to bypass traditional detection methods. The malicious payloads used fileless techniques, hiding in AI models and exploiting automated processing pipelines to achieve stealthy initial access and lateral movement. The campaign resulted in significant risks of unauthorized access, data theft, and potential disruption to business operations reliant on AI-driven processes. This incident is a timely reminder of evolving threat tactics using fileless malware and trusted native components. As the adoption of AI and automation accelerates, attackers are adapting by targeting supply chains and leveraging trusted AI data flows to bypass security controls and compliance frameworks.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
When AI Agents Go Rogue: The Risk of Session Smuggling in Agent2Agent Systems
Impact· low

When AI Agents Go Rogue: The Risk of Session Smuggling in Agent2Agent Systems

In early 2024, cybersecurity researchers uncovered a novel vulnerability in agent-to-agent (A2A) AI systems, termed 'Agent Session Smuggling.' The attack allowed malicious actors to hijack sessions between AI agents, abusing trust relationships and manipulating agent behavior. Attackers leveraged weaknesses in session authentication and input validation, circumventing security controls to inject unauthorized commands and siphon sensitive data. Demonstrated through proof of concept, the exploit posed risks to organizations deploying sophisticated autonomous AI workflows and threatened the integrity of operational and business data. This incident highlights a rapidly emerging class of AI/ML security threats, where attacks exploit autonomous system intercommunication. As organizations accelerate AI adoption, understanding and mitigating these exploit techniques—especially in east-west, agent-driven environments—has become a pressing priority for security and compliance teams globally.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
LinkedIn Phishing Scam Exploits Finance Executives with Fake Board Invites
Impact· low

LinkedIn Phishing Scam Exploits Finance Executives with Fake Board Invites

In May 2024, attackers launched a highly targeted phishing campaign abusing LinkedIn’s direct messaging system to impersonate executive board invitations and target finance executives. The phishing messages enticed victims to a spoofed Microsoft authentication page designed to steal their credentials. These attacks demonstrated careful social engineering, relying on the professional trust inherent to LinkedIn. Stolen credentials could be leveraged for unauthorized access to sensitive corporate financial data or for follow-on business email compromise attacks, creating substantial business risk and potential regulatory exposure. This incident underscores an ongoing surge in sophisticated, identity-driven phishing attacks against senior business leadership. As attackers increasingly exploit trusted professional platforms and personalize their lures, organizations face mounting pressure to adopt advanced detection, multi-factor authentication, and user awareness to counter modern credential theft threats.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(low)
Read Report
CISA & NSA Issue 2024 Guidance to Harden Microsoft Exchange Servers
Impact· low

CISA & NSA Issue 2024 Guidance to Harden Microsoft Exchange Servers

In June 2024, the Cybersecurity and Infrastructure Security Agency (CISA) and the National Security Agency (NSA) issued joint guidance targeting administrators of Microsoft Exchange servers. This proactive measure follows a history of critical vulnerabilities in Exchange, which have enabled advanced threat actors and ransomware groups to access sensitive organizational email systems, often through unpatched servers and weak configurations. By outlining best practices for hardening Exchange, the agencies aim to help organizations mitigate risks from exploitation, data theft, and business disruption associated with increasingly sophisticated attack vectors seen throughout 2023 and 2024. This guidance reflects the heightened urgency around securing ubiquitous enterprise communications tools following high-profile breaches exploiting on-premise infrastructure. With persistent evolution in offensive capabilities and regulatory scrutiny increasing, consistently applying infrastructure hardening and Zero Trust controls is now critical for organizations of all sizes.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Conduent’s 2024 Data Breach: Over 10 Million Records Stolen in Major BPO Attack
Impact· high

Conduent’s 2024 Data Breach: Over 10 Million Records Stolen in Major BPO Attack

In June 2024, business process outsourcing giant Conduent confirmed a major data breach after attackers gained unauthorized access to its systems, exposing sensitive information of approximately 10.5 million individuals across the United States. The breach came to light following regulatory disclosures and was attributed to exploitation of a third-party vulnerability, allowing attackers to access personal data used in Conduent's healthcare and government services contracts. Impacted data reportedly includes names, social security numbers, addresses, and related identifiers tied to outsourced processing for public sector and healthcare organizations. This breach underscores persistent risks faced by organizations managing data at scale for critical sectors, with attackers increasingly targeting supply chain or third-party gaps. Growing regulatory scrutiny and rising consumer awareness are amplifying the urgency for improved data protection, robust access controls, and ongoing monitoring against sophisticated threat behaviors.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
CISA Orders Urgent Patch of VMware Tools Flaw Exploited by Chinese Hackers
Impact· low

CISA Orders Urgent Patch of VMware Tools Flaw Exploited by Chinese Hackers

In October 2024, Chinese state-sponsored hackers exploited a high-severity vulnerability in Broadcom’s VMware Aria Operations and VMware Tools software, targeting U.S. federal agencies through a software supply-chain attack. The attackers leveraged the unpatched flaw to gain unauthorized access, move laterally within networks, and potentially exfiltrate sensitive data. The Cybersecurity and Infrastructure Security Agency (CISA) responded by issuing an emergency directive, mandating all federal agencies to immediately patch the affected systems amid evidence of ongoing compromise. This incident underscores the persistent risks of vulnerable supply-chain components and the growing sophistication of state-sponsored adversaries. In light of increased regulatory scrutiny and rising exploitation of critical infrastructure platforms, organizations must prioritize rapid vulnerability management and layered defense strategies.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Europe Hit by Massive NFC Relay Malware Attacks Targeting Payment Cards in 2024
Impact· high

Europe Hit by Massive NFC Relay Malware Attacks Targeting Payment Cards in 2024

In early 2024, cybersecurity researchers uncovered a sweeping campaign across Eastern Europe involving over 760 malicious Android apps leveraging NFC (Near-Field Communication) relay malware. Threat actors distributed these apps through unofficial channels, targeting unsuspecting users to intercept and relay credit card information during contactless transactions. Once installed, the malware exploited device-level NFC permissions to steal payment credentials, enabling attackers to commit significant financial fraud and undermine consumer trust in mobile payments. The primary impact has been large-scale theft from compromised cards, increased banking fraud, regulatory concern, and widespread consumer exposure. This incident signals a sharp escalation in mobile payment threats and demonstrates how sophisticated cybercriminals now target embedded hardware features. Organizations face new challenges in defending against evolving mobile malware, with compliance and security standards coming under increased scrutiny.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Multi-Vector Attacks Surge: DNS Poisoning, Supply-Chain Compromise, and Rust Malware in 2025
Impact· medium

Multi-Vector Attacks Surge: DNS Poisoning, Supply-Chain Compromise, and Rust Malware in 2025

In October 2025, a major multi-vector cyberattack was uncovered leveraging DNS poisoning, a sophisticated software supply-chain compromise, and the deployment of a new strain of Rust-based malware capable of evading traditional detection mechanisms. The attackers exploited vulnerabilities in third-party supplier code to infiltrate enterprise networks, enabling lateral movement via compromised DNS servers. Shortly thereafter, remote access trojans (RATs) and other post-exploitation tools were deployed, resulting in significant data exfiltration and disruption across multiple sectors. Incident response teams collaborated internationally to isolate affected systems and assess the operational damage. This event highlights a tightening attacker focus on high-value targets and critical infrastructure, driven by advances in malware tooling, zero-day exploitation, and the mainstream use of modern programming languages like Rust for stealthy payloads. The breach exemplifies how defenders must adapt to increasingly layered threats that combine classic attack vectors with contemporary tactics.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
PhantomRaven npm Attack: 2025’s Credential-Stealing Supply Chain Breach
Impact· medium

PhantomRaven npm Attack: 2025’s Credential-Stealing Supply Chain Breach

In August 2025, cybersecurity researchers from Koi Security uncovered an extensive software supply chain attack involving over 120 malicious npm packages, collectively named "PhantomRaven." Disguised as legitimate dependencies, these packages were uploaded to the npm registry and, once installed on developers’ machines, exfiltrated sensitive assets such as GitHub authentication tokens, CI/CD secrets, and other credentials. The attacker’s use of common JavaScript project names and spellings facilitated widespread distribution before discovery. The breach triggered rapid mitigation responses across multiple organizations relying on npm in their software development lifecycles, raising concerns about dependency trust and software supply chain hygiene. The PhantomRaven campaign underscores a broader surge in supply chain attacks exploiting open-source ecosystems, with threat actors increasingly leveraging popular package managers as vectors. As the software industry’s reliance on third-party code grows, so does the urgency for proactive controls and real-time monitoring to counter sophisticated credential-stealing methods.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
New 'Brash' Chromium Exploit Exposes Enterprise Browser Risks in 2025
Impact· high

New 'Brash' Chromium Exploit Exposes Enterprise Browser Risks in 2025

In October 2025, a severe vulnerability affecting Chromium-based browsers was publicly disclosed by security researcher Jose Pino. Nicknamed "Brash," this exploit targets the Blink rendering engine by manipulating specific DOM operations, allowing any attacker to crash a victim's browser with a single specially crafted URL. The vulnerability impacted Chrome, Edge, Brave, and other browsers using Chromium, raising concerns about both service disruption and potential for more severe follow-on attacks. The flaw could be triggered in as little as 15–60 seconds, posing a high risk for denial-of-service campaigns and widespread user impact until an emergency patch was released. The Brash exploit underscores increasing risks from 'zero-click' browser attacks. As reliance on web-based applications rises, threat actors increasingly target foundational browser components. This incident highlights the need for continuous monitoring and rapid browser patching in enterprise environments to counter such fast-moving threats.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Russian Ransomware Leverages AdaptixC2: 2025's Open-Source Attack Surge
Impact· high

Russian Ransomware Leverages AdaptixC2: 2025's Open-Source Attack Surge

In mid-2025, threat intelligence sources reported that Russian ransomware groups had begun leveraging the open-source AdaptixC2 framework to orchestrate highly targeted, advanced ransomware campaigns. AdaptixC2, originally designed for penetration testing, was weaponized to facilitate command-and-control communications, enable lateral movement, and automate deployment of ransomware binaries across hybrid cloud and enterprise environments. The attackers exploited weak internal segmentation and monitoring deficiencies, achieving extensive encryption of critical systems, data exfiltration, and ransom demands that disrupted multiple sectors, including finance and healthcare. This incident reflects a broader trend: threat actors are rapidly operationalizing legitimate open-source red team tools for malicious purposes. Organizations must respond to this evolution in attacker strategies, as post-exploitation frameworks become increasingly prevalent in real-world breaches, complicating detection and increasing regulatory and operational risk.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports