Financial Services — Cyber Threat Activity
Threat actors, incidents and malware targeting the Financial Services sector — 953 recorded incidents and 250 tracked groups.
- Recorded incidents: 953
- Incidents, trailing 180 days: 224
- Tracked threat actors: 250
- Malware families: 239
Recent incidents
- Bloom Financials 2026-08-06
- Rodschinson Investment 2026-08-05
- albanybank.com 2026-08-05
- JK Capital Management Limited 2026-08-04
- Preferred Financial Group 2026-08-04
- TopMark Funding 2026-08-04
- Bjs Insurance & Financial 2026-08-04
- Freedom Claims Management 2026-08-03
- www.buzztrading104.co.za 2026-08-02
- Philippine Savings Bank 2026-08-01
- CFS 2026-07-31
- Premier Fiduciary 2026-07-31
- KUVEYT TURK 2026-07-31
- FINANSBANK 2026-07-31
- ANADOLUBANK 2026-07-31
- ANADOLU SİGORTA 2026-07-31
- Affinity Capital 2026-07-30
- Prelys Courtage 2026-07-28
- Accesso 2026-07-28
- Bright Star Partners Insurance 2026-07-27
Threat actors targeting Financial Services
- Qilin 115 incidents
- Akira 74 incidents
- RansomHub 39 incidents
- Play Ransomware 35 incidents
- KillSec 33 incidents
- LockBit 31 incidents
- INC Ransom 30 incidents
- DragonForce 25 incidents
- BianLian 24 incidents
- The Gentlemen 22 incidents
- Medusa Ransomware 22 incidents
- ShinyHunters 19 incidents
- Lynx Ransomware 18 incidents
- Cl0p 17 incidents
- Hunters International 15 incidents
- SafePay 14 incidents
- FunkSec 12 incidents
- NightSpire 10 incidents
- Black Basta 8 incidents
- RansomHouse 7 incidents
- Meow 7 incidents
- CRPxO 7 incidents
- Everest 7 incidents
- Rhysida 7 incidents
Where these victims are
- United States 586
- United Kingdom 36
- Canada 29
- India 17
- Australia 15
- Germany 12
- Indonesia 11
- South Korea 11
- Hong Kong 10
- Brazil 9
- Switzerland 9
- South Africa 8
Malware used against Financial Services
Families used by the threat actors that target this sector, derived from actor tooling rather than observed in these incidents directly.
- Agent Tesla Malware
- Akira Malware
- Black Basta Malware
- BlackCat Malware
- Clop Malware
- Cobalt Strike Malware
- Conti Malware
- Emotet Malware
- Impacket Tool
- Mimikatz Tool
- PlugX Malware
- PsExec Tool
Coverage. 76.7% of incidents in our log carry a sector classification; the remainder name a victim we have not placed in an industry. Counts here are a floor, not a total, and are not comparable between sectors of different sizes.