Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
Salesforce 2025 Supply Chain Data Breach: An Executive Overview
In 2025, Salesforce and hundreds of its customers were targeted in two coordinated data theft campaigns by the threat group "Scattered Lapsus$ Hunters," leveraging both social engineering and stolen OAuth tokens. Attackers tricked employees into connecting malicious OAuth applications or exploited compromised Salesloft Drift tokens, gaining unauthorized access to sensitive CRM data, support tickets, credentials, and authentication tokens. The attackers subsequently attempted to extort 39 major organizations, threatening to leak up to 1.5 billion records via a dark web leak site unless sizable ransom demands were met. Salesforce publicly refused to negotiate or pay any ransom, and law enforcement actions appeared to subsequently seize the extortion domain. This incident underscores the growing sophistication of supply-chain attacks using identity-based and OAuth token compromise, highlighting the rising risk to SaaS ecosystems. The event triggered significant concerns across industries that increasingly rely on interconnected third-party platforms and further emphasizes urgent gaps in SaaS security, zero trust application governing, and lateral movement prevention.
8 months ago
Kill Chain
Google Workspace 2025 OAuth Supply Chain Breach: Lessons From the Drift Incident
In August 2025, a supply chain attack targeted Google Workspace via compromised OAuth tokens associated with the Drift email integration, impacting several organizations. Attackers leveraged stolen Drift tokens to gain unauthorized, delegated access to connected Google Workspace mailboxes, bypassing traditional security controls by exploiting trusted third-party app grants. Google rapidly responded on August 9 by revoking the affected tokens and disabling the integration. While only a small number of mailboxes were directly accessed, the incident underscored how attackers increasingly exploit SaaS interconnections rather than direct platform breaches. This incident is particularly relevant today as exploitation of OAuth tokens and third-party integrations continues to climb, representing a paradigm shift in enterprise attack surfaces. It highlights the growing need for comprehensive SaaS integration visibility, rigorous token governance, and real-time behavioral monitoring as attackers increasingly favor these stealthy, scalable techniques.
8 months ago
Kill Chain
Crimson Collective’s 2025 AWS Cloud Data Breach: Tactics, Impacts, and Security Lessons
In October 2025, the Crimson Collective threat group executed a sophisticated attack targeting Amazon Web Services (AWS) cloud instances belonging to multiple organizations, most notably Red Hat. Utilizing exposed AWS credentials discovered via open-source reconnaissance tools, the attackers escalated their privileges by creating new IAM users with administrative rights. They then enumerated and accessed sensitive resources, including databases and storage volumes, exfiltrating approximately 570 GB of data from private GitLab repositories. The Crimson Collective followed up with extortion demands, leveraging AWS's internal and external email services to apply pressure on victims and collaborating with the Scattered Lapsus$ Hunters to intensify threats. This incident underscores an escalating trend of cloud-focused threat actors exploiting credential exposures to breach critical infrastructure, bypass perimeter controls, and apply multifaceted extortion tactics. Organizations face increasing regulatory and business risk as attackers target cloud identity and API misconfigurations, requiring immediate attention to zero trust controls, egress restrictions, and anomaly detection in multi-cloud environments.
8 months ago
Kill Chain
FileFix's 2024 Cache Smuggling Attack: What CISOs Need to Know
In June 2024, a new variant of the FileFix social engineering attack was identified leveraging cache smuggling to bypass endpoint security and deliver a malicious ZIP archive onto victims' systems. Attackers enticed users with phishing emails or deceptive social engineering content, prompting them to click download links. These links abused proxy and cache server behaviors to insert a malware payload into responses that security tools would otherwise block, enabling stealthy malware infection and potential data exfiltration. The attack method proved effective at evading security controls such as endpoint protection, web proxies, and firewalls, increasing the risk to business operations and sensitive data. This incident underscores the sophisticated evolution of social engineering attacks, now boosted by technical exploits like cache smuggling. Attackers are increasingly combining human and infrastructure weaknesses to evade even advanced security defenses, making traditional filtering and sandboxing less reliable. Security operations should urgently revisit email, web proxy, and endpoint controls for these new attack chains.
8 months ago
Kill Chain
2025 Fortra GoAnywhere Breach: Medusa Ransomware Leverages Zero-Day and Key Compromise
In early 2025, Medusa ransomware operators—tracked as Storm-1175—successfully exploited a critical vulnerability (CVE-2025-10035) in the Fortra GoAnywhere Managed File Transfer (MFT) platform. The attack required access to a private key, indicating either an advanced intrusion or insider compromise. Once inside, the threat actors moved laterally to deploy ransomware payloads, seizing sensitive business data and disrupting managed file transfers for impacted organizations. Multiple enterprises suffered data theft, business downtime, and reputational damage as a result. This incident underscores an ongoing trend of targeting supply chain platforms and MFT products with ransomware via sophisticated access methods. As ransomware groups become more resourceful in exploiting zero-days and leveraging stolen keys, organizations must prioritize proactive threat detection, timely patching, and tighter access controls to counter these evolving tactics.
8 months ago
Kill Chain
Clop Ransomware Strikes Oracle: 2024 Zero-Day Breakdown
In early 2024, the Clop ransomware group leveraged a previously unknown zero-day vulnerability in Oracle E-Business Suite to infiltrate the networks of multiple Oracle customers. Exploiting this zero-day, Clop operators gained unauthorized access to critical enterprise systems by bypassing conventional security controls, moving laterally within organization environments, and ultimately deploying ransomware to encrypt sensitive business data. The attack’s vector allowed rapid compromise across industries reliant on Oracle systems, resulting in operational disruptions, potential data exposure, and ransom demands for decryption keys. Security teams across affected organizations were forced into emergency response and containment procedures. This incident highlights a disturbing trend of ransomware gangs exploiting supply-chain vulnerabilities and zero-day flaws in widely used enterprise applications. With attackers aggressively targeting business-critical platforms, the urgency for patch management, network segmentation, and advanced threat monitoring has never been higher, especially as regulatory scrutiny and financial impacts intensify.
8 months ago
Kill Chain
Breaking: 'RediShell' RCE Vulnerability Hits 300,000+ Redis Cloud Servers
In early June 2024, security experts identified a critical remote code execution (RCE) vulnerability, dubbed 'RediShell,' impacting Redis servers worldwide. This 13-year-old flaw (CVSS 10.0) enables unauthenticated attackers to execute arbitrary commands and fully compromise exposed hosts. More than 300,000 unpatched Redis instances were found publicly accessible, largely in cloud and hybrid environments, risking complete data loss, ransomware deployment, or lateral movement within enterprise networks. Attackers rapidly weaponized the exploit to automate mass scans and attacks, prompting emergency advisories and patch releases from Redis maintainers and cloud providers. This incident underscores the ongoing risks posed by old vulnerabilities in widely deployed open-source software. The scale and speed of RediShell exploitation demonstrate attackers’ preference for high-impact, low-effort weaknesses in cloud infrastructure, forcing organizations to prioritize patching, network segmentation, and modern Zero Trust models.
8 months ago
Kill Chain
FreePBX VoIP Vulnerability Exploited: CVE-2025-57819 Enables Code Execution
In August 2025, a critical SQL injection vulnerability (CVE-2025-57819) was disclosed in FreePBX, a popular open-source VoIP telephony platform. The flaw, found in the system's web-based admin interface, allowed unauthenticated attackers to inject malicious SQL queries via a vulnerable 'brand' parameter, enabling arbitrary modification of the backend database. Attackers have already been observed using this vulnerability to gain remote code execution by inserting persistent cron jobs that continuously recreate a web shell on the target server, providing full access for data exfiltration or fraudulent activities. Organizations using unpatched versions may be exposed to call fraud, impersonation, lateral movement, or further compromise of VoIP infrastructure. This breach highlights a persistent trend of attackers exploiting critical web application vulnerabilities shortly after public disclosure, underscoring the importance of proactive patching and real-time threat detection. It also illustrates attackers’ growing focus on embedded and telecom systems as entry points for broader enterprise compromise.
8 months ago
Kill Chain
EU Chat Control Law Threatens Privacy and Encryption in 2024
In 2024, the European Union considered sweeping legislation called Chat Control, aimed at mandating providers of end-to-end encrypted messaging apps to implement client-side scanning of user content for illegal material, notably child sexual abuse material (CSAM). Major privacy advocates and technology leaders, including Signal's CEO, highlighted that such a regulation would undermine privacy by requiring access to sensitive content before encryption. Technical experts warned that creating lawful access inherently weakens the entire encrypted ecosystem, exposing all users—including journalists, activists, and vulnerable groups—to potential surveillance or exploitation, and might force some encrypted messaging services to exit the EU market entirely. This proposed law has sparked an urgent debate on digital privacy, as its adoption could set a global precedent for government-mandated encryption backdoors. The current climate of rising concerns over lawful and extrajudicial surveillance, combined with persistent cyber threats, amplifies the pertinence and risks associated with such regulatory initiatives.
8 months ago
Kill Chain
Oracle Zero-Day Breach: Clop Ransomware Group Orchestrates Global Data Theft in 2024
In mid-2024, the Clop ransomware gang exploited a critical zero-day vulnerability (CVE-2025-61882) in Oracle E-Business Suite, executing a sophisticated chain of exploits for unauthorized, pre-authenticated remote code execution. Attackers infiltrated multiple enterprise and public-sector environments, stealing significant volumes of data before issuing high-dollar extortion demands—some as high as $50 million. The breaches went undetected for weeks, with Oracle disclosing the flaw only after victims began receiving ransom emails and the U.S. CISA catalogued the vulnerability as actively exploited. This incident underscores the rapid weaponization of newly discovered vulnerabilities by well-resourced threat actors. As enterprises increase reliance on complex ERP systems, threats leveraging zero-day exploits and multi-bug chains have become a pressing concern, signaling the need for enhanced threat detection, segmentation, and zero-trust controls.
8 months ago
Kill Chain
Clop Ransomware Exploits Oracle EBS Zero-Day for Massive Data Theft in 2025
In October 2025, Oracle urgently patched a critical zero-day vulnerability (CVE-2025-61882) affecting Oracle E-Business Suite (EBS) after widespread exploitation by the Clop ransomware gang. The flaw enabled unauthenticated remote code execution via the Concurrent Processing component’s BI Publisher integration, letting attackers gain unauthorized access and exfiltrate data. Threat actors, including Clop and possibly affiliated groups, used public proof-of-concept exploits—some leaked by other cybercriminals—to breach multiple organizations’ Oracle EBS servers. Victims were extorted via email, with stolen data leveraged for ransom, highlighting material operational and reputational risks. This incident underscores the persistent targeting of enterprise software zero-days by organized ransomware groups. The increased speed of exploit weaponization and the public sharing of exploit code amplify the urgency for organizations to apply patches swiftly, harden business-critical systems, and enhance detection capabilities for lateral movement and data exfiltration.
8 months ago
Kill Chain
XWorm RAT Re-emerges in 2025: Ransomware & Plugins Drive Global Malware Campaigns
In mid-2025, security researchers observed the resurgence of XWorm, a modular remote access trojan (RAT) that now features extensive plugin support and an integrated ransomware module. Originally developed by XCoder and abandoned in 2024, the latest XWorm variants (v6.0–6.5) have been widely adopted by multiple threat actors and distributed via phishing campaigns using malicious scripts and document attachments. Capable of data theft, remote desktop takeover, and file encryption, XWorm leverages over 35 plugins, including modules for browser data harvesting, keystroke logging, shell access, and ransomware deployment. The malware's rapid proliferation has led to thousands of infections globally, with major activity detected in Russia, the US, India, Ukraine, and Turkey. The reappearance of XWorm, now available on dark web forums and grouped with capabilities like AI-themed lures and social engineering, demonstrates an alarming trend: readily available commodity malware is increasingly sophisticated and multifaceted. This case underscores rising risks from plug-and-play cybercrime kits and reinforces the critical need for continuous defense, layered security, and advanced threat monitoring.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports