The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Financial Services

Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.

4282 threat reports
Page 82 of 357

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Financial Services Threat Reports

Showing 973984 / 4282 reports
Protect Your Crypto Assets: Understanding the 'Ill Bloom' Vulnerability
Impact· HIGH

Protect Your Crypto Assets: Understanding the 'Ill Bloom' Vulnerability

In July 2026, blockchain security firm Coinspect disclosed a critical vulnerability named 'Ill Bloom' affecting cryptocurrency wallets across multiple blockchains, including Bitcoin, Ethereum, Polygon, Rootstock, Tron, and Solana. The flaw stems from weak randomness in the generation of recovery phrases in certain software wallets, particularly lesser-known mobile applications created as early as 2018. This vulnerability has led to unauthorized access and the draining of funds, with at least $5 million stolen since May 27, 2026, including $3.1 million from 431 wallets in a coordinated attack on that date. ([crypto-economy.com](https://crypto-economy.com/coinspect-flags-ill-bloom-vulnerability/?utm_source=openai)) The 'Ill Bloom' incident underscores the critical importance of secure cryptographic practices in wallet generation. It highlights the ongoing risks associated with software wallets that may not adhere to robust security standards, emphasizing the need for users to verify the security of their wallet applications and consider using hardware wallets or reputable software wallets with strong security measures to safeguard their digital assets.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Cybersecurity Professional Sentenced for Aiding Ransomware Attacks
Impact· CRITICAL

Cybersecurity Professional Sentenced for Aiding Ransomware Attacks

In July 2026, Angelo Martino, a 41-year-old former ransomware negotiator from Florida, was sentenced to 70 months in prison for conspiring with the BlackCat ransomware group. Between April and November 2023, Martino exploited his position by leaking confidential information from five U.S. companies he was hired to protect, including cyber insurance limits and internal negotiation strategies. This betrayal enabled BlackCat to extort over $75 million from victims, including a nonprofit ($26.8M) and a financial firm ($25.6M). Additionally, Martino directly assisted in deploying ransomware attacks, demanding over $16 million and personally laundering $1.2 million in Bitcoin. Authorities seized more than $10 million in assets from him, including cryptocurrency, vehicles, and property. ([tomshardware.com](https://www.tomshardware.com/tech-industry/cyber-security/florida-man-pleads-guilty-after-leaking-victims-insurance-details-to-blackcat-hackers?utm_source=openai)) This case underscores the critical importance of trust and integrity within the cybersecurity industry. The exploitation of insider knowledge for malicious purposes highlights the need for stringent vetting processes and continuous monitoring of individuals in sensitive roles. Organizations must remain vigilant against both external threats and potential internal vulnerabilities to safeguard their operations and data.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
O-UNC-066 Exploits Microsoft Entra Passkey Enrollment in Vishing Scheme
Impact· HIGH

O-UNC-066 Exploits Microsoft Entra Passkey Enrollment in Vishing Scheme

In April 2026, a threat actor identified as O-UNC-066 initiated a sophisticated vishing campaign targeting Microsoft 365 users across multiple sectors, including food and beverage, technology, healthcare, automotive, construction, and aviation. The attackers impersonated internal security personnel, contacting employees via phone and instructing them to enroll a new Microsoft Entra passkey for enhanced security. Victims were directed to phishing websites that closely mimicked Microsoft's legitimate passkey enrollment process. Unbeknownst to the users, this process allowed the attackers to register their own passkeys, thereby gaining unauthorized access to the victims' Microsoft 365 accounts. Subsequent to gaining access, the attackers engaged in data exfiltration activities, targeting sensitive information stored in SharePoint and OneDrive. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/entra-passkey-enrollment-vishing-targets-microsoft-365-users/?utm_source=openai)) This incident underscores a concerning trend in cyber threats, where attackers exploit legitimate security features to deceive users. The abuse of Microsoft's passkey enrollment process highlights the need for organizations to implement robust user education programs and to remain vigilant against evolving social engineering tactics. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/entra-passkey-enrollment-vishing-targets-microsoft-365-users/?utm_source=openai))

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Unveiling MODBEACON: Silver Fox's Latest Encrypted C2 RAT
Impact· HIGH

Unveiling MODBEACON: Silver Fox's Latest Encrypted C2 RAT

In July 2026, the China-linked cybercrime group known as Silver Fox was identified as the operator behind a new Rust-based remote access trojan (RAT) named MODBEACON. This sophisticated malware utilizes gRPC streaming to establish encrypted command-and-control (C2) communications, effectively evading traditional network detection mechanisms. MODBEACON is distributed through counterfeit software installers, leveraging search engine optimization (SEO) poisoning techniques to lure victims into downloading the malicious payload. Once installed, the RAT enables attackers to execute commands remotely, exfiltrate sensitive data, and maintain persistent access to compromised systems. The emergence of MODBEACON underscores a growing trend among threat actors to adopt advanced encryption methods and unconventional communication protocols to obfuscate their activities. This development highlights the necessity for organizations to enhance their detection capabilities, focusing on behavioral analysis and anomaly detection to identify and mitigate such sophisticated threats.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers
Impact· HIGH

Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers

In July 2026, a critical vulnerability named XRING was disclosed in XQUIC, Alibaba's QUIC and HTTP/3 library. This flaw allows remote clients to crash HTTP/3 servers by sending approximately 260 bytes of standard QPACK traffic, without requiring authentication or malformed packets. The issue stems from improper handling of the dynamic table resizing in QPACK, leading to memory corruption and server crashes. All versions up to v1.9.4 are affected, and as of July 10, no patch has been released. This incident underscores the importance of rigorous input validation and memory management in protocol implementations. The lack of a current patch necessitates immediate mitigation measures, such as disabling QPACK's dynamic table or HTTP/3 support, to prevent potential denial-of-service attacks.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Unpatchable Vulnerability in Tangem Wallets Exposed by Laser Attack
Impact· LOW

Unpatchable Vulnerability in Tangem Wallets Exposed by Laser Attack

In July 2026, Ledger's Donjon security team disclosed a vulnerability in Tangem crypto wallet cards, revealing that a precisely timed laser pulse aimed at the card's secure element chip can reset the card's password without the original password or backup card. This allows an attacker to gain control over the wallet and transfer funds. The attack requires physical possession of the card, specialized equipment estimated at $250,000, and leaves visible damage, making it impractical for widespread exploitation. However, due to Tangem's design, which lacks firmware update capabilities, this vulnerability cannot be patched, leaving all existing cards susceptible. This incident underscores the challenges in securing hardware wallets against sophisticated physical attacks and highlights the importance of considering firmware update mechanisms in device design. While the attack's complexity limits its immediate threat, it raises concerns about the long-term security of devices that cannot receive updates to address discovered vulnerabilities.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
OpenClaw AI Assistant Vulnerabilities: A Wake-Up Call for AI Security
Impact· CRITICAL

OpenClaw AI Assistant Vulnerabilities: A Wake-Up Call for AI Security

In early 2026, multiple critical vulnerabilities were discovered in OpenClaw, a popular open-source AI assistant. These flaws, including CVE-2026-25253, CVE-2026-24763, and CVE-2026-25157, allowed attackers to execute arbitrary code, escalate privileges, and exfiltrate sensitive data. Exploitation of these vulnerabilities led to unauthorized access to over 28,000 systems worldwide, with attackers gaining full control over affected hosts. The widespread deployment of OpenClaw in enterprise environments amplified the impact, exposing numerous organizations to significant security risks. The rapid adoption of AI agents like OpenClaw underscores the urgent need for robust security measures in AI deployments. This incident highlights the importance of comprehensive vulnerability assessments, timely patch management, and stringent access controls to mitigate the risks associated with integrating AI assistants into critical systems.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Phishing Campaign Evades AI Detection with HTML Comment Padding
Impact· LOW

Phishing Campaign Evades AI Detection with HTML Comment Padding

In July 2026, a sophisticated phishing campaign was identified, utilizing oversized HTML attachments filled with extensive comment padding to evade AI-based email security filters. The phishing emails masqueraded as Microsoft Teams notifications, featuring attachments named to resemble legitimate documents. These attachments, significantly larger than typical phishing payloads, contained minimal functional content surrounded by large blocks of HTML comments, effectively diluting the malicious code and bypassing detection mechanisms. This technique underscores the evolving tactics of cybercriminals in circumventing advanced security measures. The incident highlights a growing trend where attackers exploit AI and machine learning systems' limitations by manipulating content to evade detection. As AI becomes more integral to cybersecurity defenses, adversaries are developing methods to exploit its weaknesses, necessitating continuous adaptation and enhancement of security protocols to address these sophisticated evasion techniques.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
DigitalMint Negotiator's Betrayal: A Wake-Up Call for Cybersecurity
Impact· CRITICAL

DigitalMint Negotiator's Betrayal: A Wake-Up Call for Cybersecurity

In 2023, Angelo Martino, a ransomware negotiator at DigitalMint, exploited his position by sharing confidential client information with the BlackCat/ALPHV ransomware group. This betrayal enabled the attackers to extort a total of $75.3 million from five U.S. companies. Martino's actions included disclosing victims' negotiation strategies and insurance details, thereby maximizing ransom demands. In July 2026, he was sentenced to 70 months in prison for his role in these conspiracies. This case underscores the critical importance of trust and integrity within cybersecurity roles. The incident highlights the potential risks posed by insider threats and the necessity for organizations to implement stringent oversight and monitoring mechanisms to safeguard sensitive information.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
INTERPOL's Operation First Light 2026: A Major Blow to Global Fraud Networks
Impact· HIGH

INTERPOL's Operation First Light 2026: A Major Blow to Global Fraud Networks

Between January 15 and April 30, 2026, INTERPOL coordinated 'Operation First Light 2026,' a global initiative targeting social engineering fraud and money laundering across 97 countries. The operation resulted in the arrest of 5,811 suspects, the seizure of $293 million in illicit assets, and the identification of over 142,000 victims. Authorities also blocked 31,014 bank accounts and analyzed 152,808 cases, highlighting the extensive reach of these fraudulent activities. This operation underscores the escalating threat of transnational social engineering scams, which have become increasingly sophisticated and widespread. The significant number of victims and the substantial financial impact emphasize the urgent need for enhanced international cooperation and proactive measures to combat such fraud.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Forg365: AI-Driven Phishing Platform Targets Microsoft 365 Accounts
Impact· HIGH

Forg365: AI-Driven Phishing Platform Targets Microsoft 365 Accounts

In July 2026, a new phishing-as-a-service (PhaaS) platform named Forg365 emerged, targeting Microsoft 365 accounts by combining adversary-in-the-middle (AiTM) and device code phishing techniques with AI-assisted lure generation. The platform offers a browser extension that maintains access to compromised accounts without re-authentication. Researchers at ZeroBEC identified features in Forg365 similar to those in other PhaaS platforms like Kali365 and Sneaky2FA, indicating a sophisticated operation capable of blending malicious activities into regular email traffic. The integration of AI in Forg365's dashboard allows attackers to craft and refine phishing emails efficiently, reducing the cost and complexity of developing custom phishing content. This advancement underscores the evolving threat landscape, where AI is increasingly leveraged to enhance the effectiveness and accessibility of cyberattacks, posing significant challenges to traditional security measures.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Helix Vishing Group Exploits SharePoint in Data Theft Attacks
Impact· HIGH

Helix Vishing Group Exploits SharePoint in Data Theft Attacks

In July 2026, a new data-extortion group named Helix emerged, employing sophisticated identity-focused tactics such as voice phishing (vishing), device code phishing, and multi-factor authentication (MFA) abuse to infiltrate SharePoint environments. The attackers initiated contact by impersonating managers over the phone, convincing employees to provide device codes, thereby gaining unauthorized access to their accounts. Once inside, Helix operators registered new MFA applications to maintain persistence, systematically enumerated SharePoint content, and exfiltrated sensitive files. The stolen data was then used to extort victim organizations by threatening public disclosure or selling it to other cybercriminals. This incident underscores a significant shift towards identity-based attacks targeting cloud services, highlighting the vulnerabilities in current authentication processes. The Helix group's methods bear similarities to previous tactics employed by groups like ShinyHunters and BlackFile, indicating a possible evolution or rebranding of these threat actors. Organizations must reassess and strengthen their security protocols, particularly around identity verification and access controls, to mitigate the risks posed by such sophisticated social engineering attacks.

2 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports