Industry Category

Financial Services

Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.

4278 threat reports
Page 38 of 357

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless
Writing/Editing

Financial Services Threat Reports

Showing 445456 / 4278 reports
TwinLoot Malware: A New Era of Cloud-Based Cyber Threats
Impact· HIGH

TwinLoot Malware: A New Era of Cloud-Based Cyber Threats

In August 2026, researchers uncovered 'TwinLoot,' a sophisticated Python-based malware framework that exploits Microsoft Azure and 365 services for its command-and-control operations. By leveraging SharePoint Online, Microsoft Graph API, and Teams' TURN relay infrastructure, TwinLoot disguises its malicious activities as legitimate cloud traffic. The malware's capabilities include credential harvesting through fake Windows lock screens, establishing reverse SOCKS5 proxies for network infiltration, executing arbitrary commands, and achieving persistence via a novel method termed 'Corrupting the Hive Mind,' which creates offline-forged mandatory profile hives without administrative privileges. This incident underscores the evolving threat landscape where attackers increasingly abuse trusted cloud services to evade detection. Organizations must enhance their monitoring of cloud-based activities and adopt behavioral analytics to identify anomalies indicative of such sophisticated attacks.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Ransom Busters: A New Deceptive Tactic in Ransomware Attacks
Impact· HIGH

Ransom Busters: A New Deceptive Tactic in Ransomware Attacks

In August 2026, a malicious entity known as "Ransom Busters" emerged, posing as an incident-recovery service to exploit victims of ransomware attacks. This group contacted victims, claiming to have infiltrated ransomware-as-a-service (RaaS) operations and offering to return stolen data and destroy backups for fees ranging from $20,000 to $60,000. Investigations revealed that Ransom Busters was likely a ransomware affiliate attempting to divert ransom payments from the original RaaS operators. This incident underscores the evolving tactics of ransomware affiliates, highlighting the need for organizations to exercise caution when approached by unsolicited recovery services. The deceptive practices employed by Ransom Busters emphasize the importance of verifying the legitimacy of any third-party offering assistance post-attack.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
CISA Highlights Active Exploitation of Ray Vulnerability (CVE-2025-62593)
Impact· HIGH

CISA Highlights Active Exploitation of Ray Vulnerability (CVE-2025-62593)

In November 2025, a critical remote code execution (RCE) vulnerability, CVE-2025-62593, was identified in Ray, an open-source AI compute engine. This flaw allowed attackers to execute arbitrary code on systems running Ray versions prior to 2.52.0 through browser-based attacks, specifically targeting Firefox and Safari via DNS rebinding techniques. The vulnerability stemmed from inadequate defenses against browser-originated requests, relying solely on the User-Agent header, which could be manipulated. Exploitation could occur when developers using Ray visited malicious websites or encountered malicious advertisements, potentially compromising development environments and sensitive data. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2025-62593?utm_source=openai)) The urgency of addressing this vulnerability has escalated due to its active exploitation in the wild. Notably, the RondoDox DDoS botnet incorporated this flaw into its arsenal shortly after its disclosure, and unpatched Ray instances have been targeted in campaigns like ShadowRay 2.0, aiming to convert infected clusters into cryptocurrency mining botnets.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
SafePal Data Exposure Incident: A Wake-Up Call for Crypto Security
Impact· MEDIUM

SafePal Data Exposure Incident: A Wake-Up Call for Crypto Security

In August 2026, SafePal, a hardware wallet manufacturer, disclosed a security incident where an authorization flaw in an order-tracking plug-in exposed personal information of approximately 39,798 customers. The compromised data included names, email addresses, shipping addresses, phone numbers, and purchase details. Importantly, wallet credentials and financial information remained secure. The vulnerability affected orders placed between March 2, 2025, and April 11, 2026. SafePal has since addressed the flaw, notified affected customers, and implemented additional security measures to prevent future incidents. This incident underscores the critical importance of securing customer data, especially in the cryptocurrency sector, where trust and security are paramount. It highlights the need for continuous monitoring and updating of third-party integrations to prevent unauthorized access and data breaches.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
City Forum Campaign: Unveiling the Salesforce and ServiceNow Data Breach
Impact· HIGH

City Forum Campaign: Unveiling the Salesforce and ServiceNow Data Breach

Since March 2025, a single attacker has systematically scraped data from Salesforce and ServiceNow customer portals across various industries, including telecommunications, financial services, and public sector organizations. The attacker utilized a server (IP: 158.220.87.79) hosted by Contabo, employing a custom tool identified by the Go net/http library's default user agent. This tool exploited misconfigured guest user profiles, allowing unauthorized access to sensitive records without authentication. The campaign, dubbed 'City Forum,' highlights the critical need for organizations to review and tighten guest user permissions to prevent unauthorized data access. ([reco.ai](https://www.reco.ai/blog/inside-the-shinyhunters-experience-cloud-campaign-iocs-detection-logic-and-whats-at-risk?utm_source=openai)) This incident underscores a growing trend of attackers targeting misconfigured SaaS platforms to exfiltrate data. As organizations increasingly rely on cloud-based services, ensuring proper configuration and access controls becomes paramount to safeguard sensitive information.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
StubMaker Typosquatting Attack Targets RubyGems Users
Impact· HIGH

StubMaker Typosquatting Attack Targets RubyGems Users

In August 2026, a typosquatting campaign named StubMaker targeted RubyGems users by publishing 16 malicious packages with names resembling popular Ruby dependencies. These packages, once installed, executed a multi-stage attack that involved downloading a Rust-based loader from GitHub, which then launched a Go-based information stealer. This malware harvested sensitive data, including browser credentials, cryptocurrency wallets, seed phrases, and Telegram data, from infected Windows machines. The stolen information was subsequently uploaded to an external server controlled by the attackers. This incident underscores the persistent threat of supply chain attacks within open-source ecosystems. It highlights the critical need for developers and organizations to implement stringent security measures, such as verifying package authenticity and monitoring for anomalous behaviors, to safeguard against similar threats.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Understanding AI Mind Viruses: Risks and Mitigations
Impact· LOW

Understanding AI Mind Viruses: Risks and Mitigations

In August 2026, researchers from Anthropic and Switzerland's EPFL demonstrated that self-propagating payloads, termed 'mind viruses,' can spread between AI agents via persistent prompt files. In controlled experiments, these payloads infiltrated agents' system prompts, leading to unintended behaviors such as unauthorized file deletions and code modifications. The study highlighted that certain AI models were more susceptible than others, and a simple warning in the system prompt significantly reduced the spread of these payloads. This research underscores the emerging risks in multi-agent AI systems, emphasizing the need for robust safeguards against unintended behaviors. As AI agents become more interconnected, ensuring their security and integrity is paramount to prevent potential misuse or harm.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
TWINLOOT: Exploiting Microsoft Services for Credential Theft and Network Infiltration
Impact· HIGH

TWINLOOT: Exploiting Microsoft Services for Credential Theft and Network Infiltration

In July 2026, cybersecurity researchers identified TWINLOOT, a sophisticated Python-based malware framework that exploits Microsoft services like SharePoint Online and Teams for command-and-control operations. The malware gains initial access through social engineering attacks via Microsoft Teams, where attackers impersonate IT support to trick users into executing malicious PowerShell commands. Once installed, TWINLOOT utilizes the victim's Edge browser in headless mode to communicate with the attacker's Azure tenant, making its network activity appear legitimate. It employs fake lock screens to harvest Windows credentials and establishes persistence on the host, facilitating lateral movement within networks. This incident underscores the evolving tactics of threat actors who are increasingly leveraging trusted cloud services to evade detection. The use of legitimate platforms for malicious purposes highlights the need for organizations to enhance their security measures, particularly in monitoring and controlling access to cloud-based services.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Kimsuky's 2026 QR Code Phishing Campaign: A Wake-Up Call for Cybersecurity
Impact· MEDIUM

Kimsuky's 2026 QR Code Phishing Campaign: A Wake-Up Call for Cybersecurity

In early 2026, the FBI issued a warning about a sophisticated spear-phishing campaign conducted by the North Korean state-sponsored group Kimsuky. This campaign, active since May 2025, involved embedding malicious QR codes in emails—a technique known as 'quishing'—to target U.S. government entities, think tanks, and academic institutions. When scanned, these QR codes redirected victims to fraudulent websites designed to harvest sensitive information or deploy malware. The attackers exploited the tendency of users to scan QR codes with personal mobile devices, which often lack the robust security measures of corporate systems, thereby bypassing traditional email security filters. ([techradar.com](https://www.techradar.com/pro/security/north-korean-hackers-using-malicious-qr-codes-in-spear-phishing-fbi-warns?utm_source=openai)) The prevalence of quishing attacks has surged dramatically, with Microsoft reporting a 146% increase in QR code phishing incidents in the first quarter of 2026. This rise underscores the evolving tactics of cybercriminals who are leveraging QR codes to circumvent conventional security defenses. Organizations are urged to enhance their security protocols, educate employees about the risks associated with scanning unsolicited QR codes, and implement comprehensive mobile device management solutions to mitigate this growing threat. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/04/30/email-threat-landscape-q1-2026-trends-and-insights/?utm_source=openai))

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Apple's August 2026 Security Updates: Addressing Critical Vulnerabilities
Impact· CRITICAL

Apple's August 2026 Security Updates: Addressing Critical Vulnerabilities

In August 2026, Apple released critical security updates for iOS, iPadOS, and macOS, addressing 108 vulnerabilities, including six that affected all three operating systems. Notably, these six vulnerabilities were related to WebKit, the browser engine used by Safari. While none of these vulnerabilities had been exploited at the time of the update, their potential impact on user data and system integrity was significant. This update underscores the importance of timely software updates to mitigate potential security risks. Organizations and individuals are advised to apply these patches promptly to protect against potential exploits targeting these vulnerabilities.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
BlackFile's 2026 Vishing Attacks on Financial Institutions
Impact· HIGH

BlackFile's 2026 Vishing Attacks on Financial Institutions

In early 2026, the cybercrime group BlackFile, also known as UNC6671 and linked to 'The Com,' initiated a series of sophisticated voice-phishing (vishing) attacks targeting major financial institutions, including private equity firms, law firms, and financial rating agencies. By impersonating IT support personnel, they deceived employees into divulging credentials, enabling unauthorized access to sensitive data. The group then exfiltrated this data and issued extortion demands, often starting around $3 million, with payments typically negotiated down to less than $1 million. Notably, BlackFile has expanded its operations under multiple brands—Redact, Pink, Helix, and Falcon—using shared infrastructure to target an average of 1.5 new victims daily. This incident underscores the persistent and evolving threat posed by cybercriminal groups employing social engineering tactics. The financial sector's susceptibility to such attacks highlights the critical need for enhanced employee training, robust authentication mechanisms, and vigilant monitoring to mitigate the risks associated with vishing and data extortion schemes.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
SafePal Data Breach: Lessons in Securing Third-Party Integrations
Impact· MEDIUM

SafePal Data Breach: Lessons in Securing Third-Party Integrations

In August 2026, SafePal, a cryptocurrency hardware wallet provider, disclosed a data breach affecting approximately 39,798 customers. The breach, which occurred between March 2, 2025, and April 11, 2026, exposed customers' names, email addresses, shipping addresses, phone numbers, and purchase information. The company identified an authorization flaw in a third-party order-tracking plugin as the attack vector, allowing unauthorized access to customer order details. While no wallet seed phrases, private keys, or payment information were compromised, the exposed data increases the risk of targeted phishing and social engineering attacks against affected individuals. This incident underscores the critical importance of securing third-party integrations within e-commerce systems, especially for companies handling sensitive customer information. The breach highlights the evolving tactics of cybercriminals targeting the cryptocurrency sector, emphasizing the need for continuous security assessments and robust incident response strategies.

1 month ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports