Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
AdaptixC2 in Real-World Attacks: Open-Source C2 Framework Alters the Threat Landscape
In early 2024, security researchers discovered that AdaptixC2, a newly released open-source command and control (C2) framework, was actively leveraged by threat actors in real-world intrusion campaigns. The attackers employed AdaptixC2 for post-exploitation activities, enabling covert command execution, lateral movement, and persistent access within targeted enterprise networks. The framework’s encrypted traffic and modular architecture allowed actors to evade traditional security controls, complicating detection and response efforts and increasing business risk. The widespread adoption of open-source C2 frameworks like AdaptixC2 underscores a shift where commodity offensive tools rapidly enter the arsenal of both sophisticated and opportunistic threat actors. This trend increases attack surface for organizations and challenges defenders to implement advanced incident detection, with regulatory bodies stressing the importance of proactive east-west and anomaly monitoring.
8 months ago
Kill Chain
Shai-Hulud Worm Breach: npm Supply Chain Attack in 2023
In November 2023, the self-replicating 'Shai-Hulud' worm orchestrated a large-scale supply chain attack targeting the npm ecosystem. The threat actor compromised hundreds of npm packages, inserting malicious code that enabled lateral propagation and potential backdoor access for anyone who installed the affected libraries. The attack illustrates how deeply embedded dependencies and trusted registries can be manipulated to impact thousands of downstream projects and potentially expose sensitive systems. Swift action from npm and security researchers helped mitigate the spread, but several organizations experienced heightened risk before remediation. This incident underscores the growing threat and frequency of software supply chain compromises, particularly targeting open-source registries. With adversaries leveraging automation and worm-like propagation, the security of development pipelines and third-party code ingestion remains an urgent focus for digital businesses.
8 months ago
Kill Chain
Scattered Spider Exposed: 2024 Ransomware Hits Critical Infrastructure and Healthcare
In September 2024, UK authorities arrested two teenagers, Thalha Jubair and Owen Flowers, for their significant roles in numerous cyberattacks attributed to the Scattered Spider gang—a notorious offshoot of The Com collective. Operating since at least May 2022, the pair leveraged social engineering techniques to infiltrate a range of organizations, including Transport for London, U.S. critical infrastructure, healthcare providers, and the federal court system. They stole and encrypted sensitive data, then demanded ransom payments, netting at least $115 million from 47 U.S. victims alone. Cryptocurrency wallets tied to the suspects were seized, totaling over $36 million, and both face serious charges on both sides of the Atlantic. This incident illustrates the growing threat from young, highly skilled ransomware groups utilizing sophisticated extortion tactics. As extortion and identity-driven ransomware evolve, organizations—especially those in critical industries—face increasing pressure to bolster defenses against lateral movement and social engineering-based breaches.
8 months ago
Kill Chain
SonicWall 2024 Breach: Firewall Backup Data Compromised in MySonicWall Attack
In June 2024, SonicWall confirmed that threat actors breached its MySonicWall portal and gained unauthorized access to a set of firewall backup configuration files. The attackers were able to obtain configuration data belonging to less than 5% of customers through this service, which could potentially reveal sensitive network information such as network structures, credentials, and policy configurations. SonicWall indicated that the breach was swiftly detected, affected accounts were notified, and the scope was limited, but details regarding the initial attack vector or threat actor remain undisclosed. This incident comes at a time of heightened targeting of network infrastructure management portals and supply chain entry points. As attackers increasingly look to exploit enterprise-grade device management platforms, organizations must reinforce segmentation, monitor lateral movements in east-west traffic, and continually validate zero trust architectures across all privileged network and cloud control panels.
8 months ago
Kill Chain
Critical Azure Entra ID Flaw Reveals Cloud IAM Security Gaps
In mid-2024, a critical cloud misconfiguration vulnerability was discovered in Microsoft Azure Entra ID, exposing severe weaknesses in the cloud provider’s identity and access management (IAM) infrastructure. The flaw allowed attackers, had it been exploited, to escalate privileges and potentially gain unauthorized access to sensitive assets across tenant environments. The vulnerability was quietly remediated by Microsoft prior to public disclosure, but security researchers noted it could have resulted in catastrophic, widespread attacks on enterprise data and operations if abused by malicious actors. This incident underscores growing concerns over cloud platform security and identity-centric attack vectors, coinciding with a broader surge in high-impact IAM misconfigurations. Organizations are increasingly urged to review cloud IAM policies and controls, as regulatory pressure intensifies and attackers shift focus to exploiting identity weaknesses within as-a-service environments.
8 months ago
Kill Chain
Synthetic Identity Fraud Surges: US Finance Faces $3.3B in Damages (2024)
In 2024, US financial institutions, particularly those in the automotive lending sector, experienced a significant surge in synthetic identity fraud, resulting in estimated damages of $3.3 billion. Cybercriminals leveraged data amassed from previous breaches to construct convincing synthetic profiles used to obtain loans and open accounts, often nurturing these fraudulent identities with legitimate activity to evade detection. Both individual and business identities were targeted, with institutions facing growing pressure to enhance detection capabilities amid an ongoing arms race with sophisticated attackers employing AI and cloud tools. This increase in synthetic identity fraud reflects an evolving threat landscape, where attackers capitalize on remote-first processes and richer data sources to outpace traditional defenses. The accelerating adoption of digital banking and lending has heightened urgency for adaptive, real-time security controls and improved identity verification as financial firms confront complex, persistent fraud schemes.
8 months ago
Kill Chain
SonicWall MySonicWall Breach Puts Firewall Backups and Credentials at Risk
In September 2025, SonicWall disclosed a security incident impacting its MySonicWall cloud platform, where firewall configuration backup files were accessed by threat actors following a series of brute-force attacks. The breach, affecting less than 5% of SonicWall firewalls, exposed configuration data that included encrypted passwords and sensitive information, potentially easing future exploitation of affected devices. SonicWall responded by disabling unauthorized access, notifying affected customers, and issuing urgent guidance to reset credentials, keys, and secrets for all related accounts and services. The vendor also coordinated with cybersecurity and law enforcement agencies as part of its investigation. This incident highlights a rising trend of attackers targeting cloud-based administrative services and configuration backups, exploiting brute-force methods and known vulnerabilities such as CVE-2024-40766. Organizations face increased pressure to secure not only device firmware but also backup repositories and credentials, underscoring the persistent threat of credential-based and configuration compromise attacks.
8 months ago
Kill Chain
Salesloft Drift Salesforce Breach 2025: OAuth Supply Chain Attack Exposes 1.5 Billion Records
In September 2025, the ShinyHunters extortion group, in collaboration with affiliates Scattered Spider and Lapsus$, claimed responsibility for a massive data breach targeting Salesforce via compromised OAuth tokens from Salesloft Drift integrations. By exploiting the tokens exposed in Salesloft's breached GitHub repository, the attackers accessed and exfiltrated approximately 1.5 billion records from 760 organizations, including sensitive CRM, support, and user data. The incident demonstrated sophisticated use of social engineering, malicious OAuth apps, and credential-harvesting across major cloud platforms, with the attackers leveraging the stolen information for extortion and potential lateral movement. This breach is emblematic of the growing threat from identity-based attacks and supply chain compromise targeting SaaS ecosystems. Attackers leveraging OAuth abuse, stolen developer secrets, and interconnected cloud services create highly scalable data theft risks, driving regulatory focus and pushing organizations to revisit zero trust and access management frameworks.
8 months ago
Kill Chain
How Social Engineering Enabled the 2024 Insight Partners Ransomware Breach
In October 2024, Insight Partners, a leading New York-based venture capital and private equity firm, suffered a significant cybersecurity incident when a threat actor used sophisticated social engineering techniques to gain network access. Following initial infiltration, attackers spent months exfiltrating sensitive information, including banking, tax, employee, and investor data, before launching ransomware on January 16, 2025 to encrypt company servers. The breach ultimately impacted approximately 12,657 individuals, with Insight Partners notifying those affected and providing credit monitoring services in accordance with regulatory requirements. This incident highlights the increasing effectiveness of social engineering in enabling multi-stage ransomware attacks that combine stealthy exfiltration with disruptive encryption. As the financial sector faces growing regulatory scrutiny and cybercriminals refine identity-driven attack vectors, organizations must address both technical vulnerabilities and human factors to maintain resilience against evolving ransomware threats.
8 months ago
Kill Chain
Google Chrome Hit by Sixth Zero-Day Exploit in 2025—Emergency Patch Released
In September 2025, Google disclosed and urgently patched a high-severity zero-day vulnerability (CVE-2025-10585) in its Chrome browser, the sixth such flaw exploited in the wild this year. The vulnerability stemmed from a type confusion issue within the V8 JavaScript engine and was reportedly leveraged by threat actors—likely government-sponsored—primarily in targeted campaigns against high-risk individuals such as journalists, activists, and political dissidents. Google’s Threat Analysis Group discovered the flaw, leading to an accelerated patch rollout for Windows, Mac, and Linux platforms to mitigate potential compromise and data theft. This incident underscores the continued escalation in zero-day exploitation, particularly against ubiquitous software. As browser-based attacks become more sophisticated and frequent, organizations face mounting pressure to adopt rapid patching cycles and proactive threat mitigation strategies to defend against emergent threats.
8 months ago
Kill Chain
Critical WatchGuard Firebox VPN Flaw Exposes Businesses to Remote Attacks in 2025
In September 2025, WatchGuard revealed a critical remote code execution vulnerability (CVE-2025-9242) affecting its Firebox firewalls running Fireware OS 11.x, 12.x, and 2025.1. The flaw, caused by an out-of-bounds write in the iked process, could let unauthenticated attackers remotely execute code by exploiting VPN configurations utilizing IKEv2, even after vulnerable settings are removed if static gateway peers remain. While no active exploitation has been observed to date, the vulnerability exposes potentially 250,000 small and mid-sized business networks globally. This incident underscores the ongoing risks faced by organizations from appliance-level vulnerabilities in edge security devices, especially as attackers increasingly target VPN and firewall platforms in their campaigns. Recent ransomware activity and mandates from regulators have heightened industry awareness around patching and vigilance for these critical network components.
8 months ago
Kill Chain
PyPI’s 2025 GhostAction Attack: Massive Token Exfiltration Exposes Supply Chain Risk
In September 2025, the Python Software Foundation discovered that the GhostAction supply chain attack led to the exfiltration of thousands of sensitive access tokens—including PyPI, npm, DockerHub, and AWS keys—from compromised GitHub repositories via malicious GitHub Actions workflows. Although attackers obtained over 3,300 secrets by modifying open-source project workflows to funnel credentials to remote servers, swift response from security teams and open-source maintainers prevented the abuse of stolen tokens on PyPI. The PyPI team proactively invalidated all impacted tokens and urged affected maintainers to adopt short-lived Trusted Publishers tokens and review account security. This incident highlights the increasing sophistication and scope of supply chain attacks targeting developer ecosystems and CI/CD pipelines, underscoring the urgent need for automated detection, better secrets management, and cross-ecosystem collaboration. The prevalence of such attacks demonstrates an evolving threat landscape exploiting automation and cloud-based tooling.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports