Skip to main content

Tag: financial services

79 articles

Retail checkout terminal with card reader and receipt printer in busy shopping area.

Breeze Comet Exploits Brazilian Payment Systems in Hundreds of Fraudulent Transactions

Meet Breeze Comet, a financially motivated threat actor that's been wreaking havoc on Brazilian payment systems with hundreds of fraudulent transactions, exploiting customized malware and compromised websites to siphon off tens of thousands of dollars. Their tactics are evolving, and Latin American countries should beware of potential expansion.

Analyst 207
Cluttered developer workstation with code on laptop, notes, and documentation in a naturally lit office setting.

AI Coding Tools Exacerbate Open-Source Remediation Debt

AI coding tools are speeding up development, but at a hidden cost: they can quickly introduce a flood of new open-source components that security teams struggle to keep up with, multiplying remediation debt. This creates a downstream cycle of vulnerability assessments, licensing checks, and ownership questions that can be overwhelming.

Analyst 207
A shipping box on a conveyor belt in a brightly-lit logistics facility with industrial equipment and shelving units.

SafePal Breach Exposes 39,798 Customer Records

Good news: SafePal's recent data breach didn't compromise wallet access or funds, but 39,798 customers had their personal info exposed, including names, emails, and shipping addresses. The breach appears to be limited, with sensitive credentials like wallet seed phrases and private keys remaining secure.

Analyst 207
Modern office equipment sits amidst scattered papers outside a brightly-lit office building or data center.

ExfilSquad Breaches 13 Organizations Via Misconfigured Microsoft Power Pages

Meet ExfilSquad, a notorious data-extortion group that's made off with a whopping 27 million records and 382.64 GB of sensitive data from 13 major organizations across government, education, finance, and manufacturing. The stolen treasure trove was dumped online for all to see, courtesy of a simple misconfiguration in Microsoft Power Pages.

Analyst 207
Rows of computer racks and monitors in a brightly-lit server room, with a single terminal screen blurred in focus.

Cybercriminals Exploit AI Tokens for Massive Financial Gains

Cybercriminals are raking in millions by exploiting AI tokens, a technique known as token jacking, which allows them to secretly run up huge bills on unsuspecting companies using commercial AI platforms. In one shocking example, token jacking led to nearly $1 million in unauthorized charges before being caught.

Analyst 207
Person looks concerned while viewing a laptop screen in a home office setting.

Phishing Scam Exploits Bank of America Brand to Install Remote Access Malware

Stay safe from phishing scams by being cautious of email origins and link destinations - it's your first line of defense against attacks like the recent Bank of America phishing scam. Pay attention to these details to avoid falling victim to remote access malware.

Analyst 207
Bank interior with people waiting, laptop on counter in foreground.

CAF Bank Reopens Online Service After Fraud Attempt

Good news: CAF Bank has reopened its online banking service after a 10-day disruption caused by a fraud attempt, and customers can now access their accounts online. The bank's CEO, Alison Taylor, confirmed that essential work with technology partners is complete, and an investigation into the incident is ongoing.

Analyst 207
Charity office staff work amidst scattered papers and concerned expressions.

CAF Bank Outage Persists, Charities Struggle with Disrupted Payments

Thousands of UK charities are still reeling from a week-long online banking outage at CAF Bank, with £1.45 billion in customer deposits stuck in limbo and no end in sight for a resolution. The disruption has left 14,000 charity customers scrambling to manage their day-to-day transactions.

Analyst 207
Industrial facility interior with equipment and computer workstations.

Toy Ghouls Unveils GenieLocker Ransomware

Meet GenieLocker, the latest ransomware threat from the notorious Toy Ghouls group, which has been wreaking havoc on businesses since March 2026, with a particular focus on Russian industries. The attackers are using clever tactics, like infiltrating through OpenVPN connections, to gain access and spread their malicious reach.

Analyst 207
Wi-Fi router on a table in a hotel lobby, surrounded by blurred travelers.

Hackers Target Hotel Wi-Fi to Steal Microsoft 365 Accounts

Hackers are targeting hotel Wi-Fi networks to steal Microsoft 365 accounts from unsuspecting travelers, with a widespread campaign affecting various industries across multiple countries. This sneaky tactic redirects visitors to attacker-controlled sites, putting business travelers at risk of having their sensitive information compromised.

Analyst 207
Brightly-lit trading floor with computer screens and financial data displays.

Hackers Exploit Off-Chain Infrastructure, Steal $23.7 Million from Ostium

In a shocking attack, hackers swindled $23.7 million from Ostium by manipulating off-chain infrastructure with fake price reports, rapidly trading to turn the scam into cash. The thieves targeted the liquidity provider vault, leaving trader collateral safely untouched.

Analyst 207
Technicians monitor rows of networking equipment with blinking lights in a dimly lit control room.

Russian Hackers Target Network Devices With Exploits

Russian hackers, linked to the Federal Security Service's Center 16, have been actively targeting critical US and foreign networks across multiple sectors, including defense, energy, and healthcare, for over a decade. This ongoing threat has compromised networks in various industries, posing significant risks to national security and global stability.

Analyst 207
Office workstation with laptop and printer in background.

EvilTokens Exposes New Blind Spot in Email Security

A shocking 75.6% of consulting firms were exposed to phishing attacks in 2026, with other industries like financial services, manufacturing, and tech also falling prey to these threats. EvilTokens' ghost phishing campaign uses a sneaky Microsoft Device Code Phishing tactic to trick victims into giving hackers access to their Microsoft 365 accounts.

Analyst 207
Brightly-lit industrial setting shows subtle signs of disruption.

The Gentlemen Ransomware Gang Exposes Advanced Tactics

Meet The Gentlemen, a notorious ransomware gang that's made a name for itself with sophisticated tactics, ranking among the top 10 ransomware actors in just a few months. Since February 2026, they've been wreaking havoc across industries and geographies, with a strong presence in Brazil, China, Indonesia, Taiwan, and Thailand.

Analyst 207
Brightly-lit office with rows of computer servers and a large screen displaying a blurred image.

Hackers Inject Malicious Script in Polymarket Supply-Chain Attack

Polymarket has pledged to fully reimburse customers who lost around $3 million in a shocking supply-chain attack that injected malicious JavaScript into the platform's frontend via a third-party vendor breach. The incident highlights the vulnerability of even major players to these types of attacks.

Analyst 207
Professional workspace with laptop, papers, and office supplies, blurred email inbox in background.

North Korea Targets Developers with 250 Fake Job Offers in Credential Heist

In a sneaky credential heist, hackers sent over 250 fake job offers to developers at nearly 100 US organizations, disguising phishing attempts as recruitment messages. The six-week scam targeted professionals in tech, education, and finance.

Analyst 207
Blurred computer workstation and file cabinet in a brightly-lit office interior, with a cityscape visible through the window.

Mandiant Exposes UNC3753's US Law Firm Data Heist Tactics

Beware of UNC3753, a notorious group that's been stealing sensitive data from US law firms and other professional services, using clever vishing tactics and lightning-fast intrusions to extort their victims. In some cases, they can go from initial contact to data theft in under an hour.

Analyst 207
Banking professional stands in modern office surrounded by AI-related devices.

Lloyds Banking Group Unveils Hands-On Approach to Securing Agentic AI

Lloyds Banking Group is taking a proactive approach to securing agentic AI, recognizing that understanding AI itself is crucial to embedding security into its adoption. The bank has made security a top priority, framing it as a deliberate technical strategy that spans the entire AI lifecycle.

Analyst 207
Bank lobby with a subtle hint of vulnerability on a computer screen.

Banks' Annual Testing Model Leaves 345 Days of Unvalidated Exposure

Imagine having 345 days of potential vulnerability, with hackers free to exploit your defenses while you wait for your annual security test. That's the harsh reality of the traditional annual testing model, which leaves your business exposed for nearly 11 months of the year.

Analyst 207
Smartphone displays trading interface on modern office desk with cityscape background.

Robinhood's AI Trading Push Raises Accountability, Security Risks

As Robinhood rolls out AI-powered trading and credit card features, experts are sounding the alarm on potential accountability and security risks - but the company claims it's prioritizing safety with built-in controls. Can AI agents truly be trusted to make trades and purchases on our behalf?

Analyst 207
Sleek, modern tech headquarters interior with cityscape view through large window.

Apple Foils $11 Billion in App Store Fraud Over Six Years

Apple's vigilant efforts have paid off, blocking a whopping $11 billion in App Store fraud over the past six years, with a staggering $2.2 billion foiled in 2025 alone. The tech giant's winning combination of human review and cutting-edge tech has kept scammers at bay.

Analyst 207
Mobile app development environment with smartphone on cluttered desk and cityscape in background.

Agentic AI Turbo Boosts Mobile App Attacks

The alarming rise of mobile app attacks is no longer looming on the horizon - it's here, with a staggering 87% of monitored apps facing threats in 2026, a drastic jump from 55% in 2022, fueled by the rapid adoption of AI models. This explosive growth in attacks is a wake-up call for businesses to bolster their mobile app security.

Analyst 207
Technicians in a dimly lit server room with rows of humming computer servers and storage systems.

UK Regulators Warn Financial Firms on Frontier AI Cybersecurity Risks

UK regulators are sounding the alarm: as frontier AI models advance, financial firms must urgently bolster their cyber defences to avoid catastrophic threats to safety, customers, and financial stability. The warning comes as AI capabilities increasingly outpace human expertise, offering malicious actors unprecedented speed, scale, and low-cost opportunities to wreak havoc.

Analyst 207
Bank employee under scrutiny at desk with laptop and papers amidst financial equipment.

Banks Face Growing Pressure to Justify Fraud Losses

As the Federal Reserve expands FedNow to handle higher-value transactions, banks face a daunting challenge: making split-second decisions to prevent fraud and money laundering, with transactions becoming irreversible in mere seconds. This heightened risk demands innovative solutions to safeguard against losses.

Analyst 207