Tag: financial sector
63 articles

AI Cyberattacks Threaten Global Financial System Stability
The Financial Stability Board warns that AI-powered cyberattacks could spark a chain reaction of chaos in global markets, exploiting vulnerabilities in sovereign debt, private credit, and asset valuations. This threat is more than just a tech issue - it's a potentially disastrous blow to market confidence.

Financial Stability Board Warns of AI-Driven Cyber Risks
The Financial Stability Board warns that advanced artificial intelligence could revolutionize cyber threats, potentially shaking market confidence and posing a systemic risk, especially with highly concentrated third-party service providers. Its chair, Andrew Bailey, is urging the sector and authorities to prepare for this emerging threat.

Tech Giants Urge Global AI-Powered Cyber Defense Surge
The clock is ticking: over 100 tech giants, including OpenAI, Google, and Microsoft, are sounding the alarm that we must urgently boost our AI-powered cyber defenses to avoid a surge in sophisticated attacks. They're calling on us to take action now to reduce risk before it's too late.

Cyber Insurance Losses Spike as Claim Costs Soar
Cyber insurance losses are skyrocketing as claim costs surge, with non-refundable fees in large suits potentially exceeding $10m before a case is even heard, and average claim costs jumping significantly in 2025 despite a decrease in overall claims.

US Targets Iran-Linked Hackers in Sanctions Crackdown
The US is launching a fierce economic crackdown on Iran, targeting nearly 60 entities, individuals, and vessels linked to the country's nuclear, missile, oil, and cyber networks. Secretary of the Treasury Scott Bessent vows to cut off every financial lifeline sustaining the regime, leaving Tehran isolated.

ZeroTokens Phishing Platform Enables Real-Time Attack Adaptation
Meet ZeroTokens, a sneaky phishing platform that's sending shockwaves with its real-time attack adaptation capabilities, allowing live operators to steer victims through a multi-stage scam. Over 45,000 phishing messages have already been sent to 24,000 recipients across 700 organizations, making it a threat that's hard to ignore.

Apollo Breach Exposes Sensitive Data Via Social Engineering
A recent data breach at Apollo Global Management exposed sensitive personal info, including Social Security numbers, when an unauthorized user gained cloud access for just four days, from July 6 to July 10, 2026. The breach was triggered by a social engineering attack, highlighting the importance of robust security measures.

Apollo Hit by Data Breach in Financial Sector Cyberattack Wave
Apollo Global Management recently fell victim to a data breach, with hackers gaining unauthorized access to its cloud platforms between July 6 and July 10, and sensitive personal data being compromised, discovered on August 12. The company swiftly responded to the incident, notifying law enforcement and bolstering its security protocols.

US Bank Probes LockBit Ransomware Claim, Faces Data Leak Deadline
US Bank is investigating a potential cybersecurity incident after LockBit ransomware crew claimed to have breached the institution and stolen sensitive data. The bank has assured that there's currently no indication of internal system impacts or unauthorized network access.

Data Analyst Sentenced for Extorting Employer in $2.5 Million Cyber Scheme
A 27-year-old data analyst turned cyber villain, threatening to spill sensitive salary info to the SEC unless his employer paid up - in a brazen $2.5 million extortion scheme that landed him in hot water. He made his demands in chilling messages, including one that read: We will commence the process of disseminating salary information starting January 1, 2024 in phases to all employees and will report you to the SEC after for not reporting the breach.

Mobile Malware Attacks Decline, Banking Trojans Persist
Mobile malware attacks may be on the decline, but don't let your guard down - over 1.99 million mobile devices were still threatened by malware, adware, or unwanted software in the second quarter alone. Banking Trojans, in particular, remain a persistent threat, with over 93,000 malicious packages detected.

Microsoft 365 Phishing Campaign Hijacks Accounts to Gather Payroll, Finance Emails
Beware of a sneaky Microsoft 365 phishing campaign that's hijacking accounts to get its hands on sensitive payroll and finance emails. Hundreds of organizations across healthcare, education, and more have already been targeted in this financially driven attack.

Cyberattacks on Hedge Funds Tied to UNC6671 Extortion Group
Meet UNC6671, a notorious extortion group linked to a string of cyberattacks on hedge funds, operating under a web of public brands to deceive and exploit its victims. Using voice-phishing tactics, the group tricks employees into divulging sensitive info, paving the way for a potentially devastating breach.

Bitcoin Wallet Hack Exposes $89m in Ongoing Attack
If you're using a Coldcard hardware wallet, take immediate action to protect your funds - an ongoing exploit has already drained an estimated $89 million from thousands of victim addresses. Move your single-sig Coldcard funds to a safe location ASAP to avoid losses.

Coldcard Hardware Wallet Flaw Enables $70 Million Bitcoin Heist
A sneaky attacker just pulled off a massive $70 million Bitcoin heist by exploiting a flaw in a popular hardware wallet, draining 1,196 addresses in a lightning-fast 41 minutes. The thief's clever move has left experts warning of a potential vulnerability in the widely-used Coldcard wallet.

Russian Hackers Exploit Microsoft OWA Flaw to Maintain Mailbox Access
Russian hackers have found a sneaky way to keep access to Microsoft mailboxes by exploiting a flaw in Outlook Web Access, making it tough to shake them off even with a full system overhaul. Simply put, these cyber intruders can stick around unless their presence is manually erased from the Exchange server.

CAF Bank Halts Online Services Over Security Vulnerability
Thousands of charities are facing disruption to their online accounts and payroll services after CAF Bank temporarily halted its online banking services due to a newly discovered security vulnerability. The suspension, which began on July 24, will remain in place until the issue is resolved.

CAF Bank Halts Online Services Over Third-Party Software Vulnerability
CAF Bank has temporarily halted its online banking service due to a third-party software vulnerability, and customers are being supported while the issue is resolved with the help of external experts. The bank's CEO, Alison Taylor, has apologized for the disruption, assuring customers that access will be restored once the connection is secure.

CAF Bank Halts Online Services Over Third-Party Software Flaw
CAF Bank has temporarily halted its online banking service due to a third-party software flaw that led to suspicious activity on some customer accounts. The bank assures customers that core banking services remain unaffected and that no money has been lost.

Insurance Phishing Evolves Into Real-Time Account Hijacking
Insurance phishing attacks have taken a sinister turn, now using real-time account hijacking to actively engage with victims throughout the authentication process. Cybercriminals are using sponsored Google ads to launch these attacks, luring users with offers like car insurance comparisons and then diverting them into sophisticated phishing flows.

OkoBot Malware Targets Crypto Users Worldwide
Meet OkoBot, a sneaky malware framework that's got crypto users worldwide in its crosshairs, with over 20 malicious payloads and implants that can be assembled in different ways to wreak havoc. It spreads through clever tactics like ClickFix attacks and fake GitHub packages masquerading as legitimate software.

SCMBANKER Malware Targets Mexican Banking Users with ClickFix Lures
Mexican banking customers beware: a sneaky new malware campaign, dubbed REF6045, is using fake CAPTCHA pages and social tricks to install a powerful PowerShell toolkit called SCMBANKER on unsuspecting victims' devices. This stealthy attack has been targeting Mexico's financial ecosystem, putting fintech users, payment-processor clients, and cryptocurrency exchange customers at risk.

US Government Entity Pays $1 Million to Thwart Data Leak
A US government entity was forced to pay a hefty $1 million ransom to prevent a massive data leak, after a group called Kairos threatened to release 1.6 million files unless their demand was met. The payment was the culmination of a month-long negotiation that began with a $3 million opening demand.

Oracle E-Business Suite Flaw CVE-2026-46817 Sees Active Exploitation
A critical flaw in Oracle Payments, known as CVE-2026-46817, is being actively exploited by hackers, allowing them to easily take control of vulnerable Oracle E-Business Suite instances. This easily exploitable vulnerability has a near-perfect CVSS score of 9.8, making it a high-risk threat to organizations using Oracle Payments.