Tag: financial services
79 articles

Breeze Comet Exploits Brazilian Payment Systems in Hundreds of Fraudulent Transactions
Meet Breeze Comet, a financially motivated threat actor that's been wreaking havoc on Brazilian payment systems with hundreds of fraudulent transactions, exploiting customized malware and compromised websites to siphon off tens of thousands of dollars. Their tactics are evolving, and Latin American countries should beware of potential expansion.

AI Coding Tools Exacerbate Open-Source Remediation Debt
AI coding tools are speeding up development, but at a hidden cost: they can quickly introduce a flood of new open-source components that security teams struggle to keep up with, multiplying remediation debt. This creates a downstream cycle of vulnerability assessments, licensing checks, and ownership questions that can be overwhelming.

SafePal Breach Exposes 39,798 Customer Records
Good news: SafePal's recent data breach didn't compromise wallet access or funds, but 39,798 customers had their personal info exposed, including names, emails, and shipping addresses. The breach appears to be limited, with sensitive credentials like wallet seed phrases and private keys remaining secure.

ExfilSquad Breaches 13 Organizations Via Misconfigured Microsoft Power Pages
Meet ExfilSquad, a notorious data-extortion group that's made off with a whopping 27 million records and 382.64 GB of sensitive data from 13 major organizations across government, education, finance, and manufacturing. The stolen treasure trove was dumped online for all to see, courtesy of a simple misconfiguration in Microsoft Power Pages.

Cybercriminals Exploit AI Tokens for Massive Financial Gains
Cybercriminals are raking in millions by exploiting AI tokens, a technique known as token jacking, which allows them to secretly run up huge bills on unsuspecting companies using commercial AI platforms. In one shocking example, token jacking led to nearly $1 million in unauthorized charges before being caught.

Phishing Scam Exploits Bank of America Brand to Install Remote Access Malware
Stay safe from phishing scams by being cautious of email origins and link destinations - it's your first line of defense against attacks like the recent Bank of America phishing scam. Pay attention to these details to avoid falling victim to remote access malware.

CAF Bank Reopens Online Service After Fraud Attempt
Good news: CAF Bank has reopened its online banking service after a 10-day disruption caused by a fraud attempt, and customers can now access their accounts online. The bank's CEO, Alison Taylor, confirmed that essential work with technology partners is complete, and an investigation into the incident is ongoing.

CAF Bank Outage Persists, Charities Struggle with Disrupted Payments
Thousands of UK charities are still reeling from a week-long online banking outage at CAF Bank, with £1.45 billion in customer deposits stuck in limbo and no end in sight for a resolution. The disruption has left 14,000 charity customers scrambling to manage their day-to-day transactions.

Toy Ghouls Unveils GenieLocker Ransomware
Meet GenieLocker, the latest ransomware threat from the notorious Toy Ghouls group, which has been wreaking havoc on businesses since March 2026, with a particular focus on Russian industries. The attackers are using clever tactics, like infiltrating through OpenVPN connections, to gain access and spread their malicious reach.

Hackers Target Hotel Wi-Fi to Steal Microsoft 365 Accounts
Hackers are targeting hotel Wi-Fi networks to steal Microsoft 365 accounts from unsuspecting travelers, with a widespread campaign affecting various industries across multiple countries. This sneaky tactic redirects visitors to attacker-controlled sites, putting business travelers at risk of having their sensitive information compromised.

Hackers Exploit Off-Chain Infrastructure, Steal $23.7 Million from Ostium
In a shocking attack, hackers swindled $23.7 million from Ostium by manipulating off-chain infrastructure with fake price reports, rapidly trading to turn the scam into cash. The thieves targeted the liquidity provider vault, leaving trader collateral safely untouched.

Russian Hackers Target Network Devices With Exploits
Russian hackers, linked to the Federal Security Service's Center 16, have been actively targeting critical US and foreign networks across multiple sectors, including defense, energy, and healthcare, for over a decade. This ongoing threat has compromised networks in various industries, posing significant risks to national security and global stability.

EvilTokens Exposes New Blind Spot in Email Security
A shocking 75.6% of consulting firms were exposed to phishing attacks in 2026, with other industries like financial services, manufacturing, and tech also falling prey to these threats. EvilTokens' ghost phishing campaign uses a sneaky Microsoft Device Code Phishing tactic to trick victims into giving hackers access to their Microsoft 365 accounts.

The Gentlemen Ransomware Gang Exposes Advanced Tactics
Meet The Gentlemen, a notorious ransomware gang that's made a name for itself with sophisticated tactics, ranking among the top 10 ransomware actors in just a few months. Since February 2026, they've been wreaking havoc across industries and geographies, with a strong presence in Brazil, China, Indonesia, Taiwan, and Thailand.

Hackers Inject Malicious Script in Polymarket Supply-Chain Attack
Polymarket has pledged to fully reimburse customers who lost around $3 million in a shocking supply-chain attack that injected malicious JavaScript into the platform's frontend via a third-party vendor breach. The incident highlights the vulnerability of even major players to these types of attacks.

North Korea Targets Developers with 250 Fake Job Offers in Credential Heist
In a sneaky credential heist, hackers sent over 250 fake job offers to developers at nearly 100 US organizations, disguising phishing attempts as recruitment messages. The six-week scam targeted professionals in tech, education, and finance.

Mandiant Exposes UNC3753's US Law Firm Data Heist Tactics
Beware of UNC3753, a notorious group that's been stealing sensitive data from US law firms and other professional services, using clever vishing tactics and lightning-fast intrusions to extort their victims. In some cases, they can go from initial contact to data theft in under an hour.

Lloyds Banking Group Unveils Hands-On Approach to Securing Agentic AI
Lloyds Banking Group is taking a proactive approach to securing agentic AI, recognizing that understanding AI itself is crucial to embedding security into its adoption. The bank has made security a top priority, framing it as a deliberate technical strategy that spans the entire AI lifecycle.

Banks' Annual Testing Model Leaves 345 Days of Unvalidated Exposure
Imagine having 345 days of potential vulnerability, with hackers free to exploit your defenses while you wait for your annual security test. That's the harsh reality of the traditional annual testing model, which leaves your business exposed for nearly 11 months of the year.

Robinhood's AI Trading Push Raises Accountability, Security Risks
As Robinhood rolls out AI-powered trading and credit card features, experts are sounding the alarm on potential accountability and security risks - but the company claims it's prioritizing safety with built-in controls. Can AI agents truly be trusted to make trades and purchases on our behalf?

Apple Foils $11 Billion in App Store Fraud Over Six Years
Apple's vigilant efforts have paid off, blocking a whopping $11 billion in App Store fraud over the past six years, with a staggering $2.2 billion foiled in 2025 alone. The tech giant's winning combination of human review and cutting-edge tech has kept scammers at bay.

Agentic AI Turbo Boosts Mobile App Attacks
The alarming rise of mobile app attacks is no longer looming on the horizon - it's here, with a staggering 87% of monitored apps facing threats in 2026, a drastic jump from 55% in 2022, fueled by the rapid adoption of AI models. This explosive growth in attacks is a wake-up call for businesses to bolster their mobile app security.

UK Regulators Warn Financial Firms on Frontier AI Cybersecurity Risks
UK regulators are sounding the alarm: as frontier AI models advance, financial firms must urgently bolster their cyber defences to avoid catastrophic threats to safety, customers, and financial stability. The warning comes as AI capabilities increasingly outpace human expertise, offering malicious actors unprecedented speed, scale, and low-cost opportunities to wreak havoc.

Banks Face Growing Pressure to Justify Fraud Losses
As the Federal Reserve expands FedNow to handle higher-value transactions, banks face a daunting challenge: making split-second decisions to prevent fraud and money laundering, with transactions becoming irreversible in mere seconds. This heightened risk demands innovative solutions to safeguard against losses.