Financial Services — Cyber Threat Activity
Financial services is the most heavily defended sector in this dataset, and its numbers should be read in that light: more than 950 recorded incidents across 85 countries, over 230 in the trailing 180 days, with 74 groups attributed at least one claim. Qilin (116), Akira (75), RansomHub (39), Play (36) and KillSec (33) lead, and the volume concentrates on credit unions, brokerages, insurers-adjacent processors and regional banks rather than on the largest institutions, which are the hardest targets and the best at absorbing an incident quietly. Elastic's analysis of a South Asian financial-services intrusion illustrates the common shape: entry through an exposed database service, rapid credential and account creation, tooling side-loaded inside legitimate software, then bulk exfiltration to cloud storage and log wiping, all executed as a smash-and-grab rather than a long occupation. The sector also carries the heaviest state-sponsored overlay outside government. Our graph records 257 groups in total once profile-level research associations are included, and it is the one commercial sector where a nation-state may attack for revenue rather than intelligence: North Korean units have pursued banks and payment infrastructure as a funding stream, not an espionage objective. Recorded geography is dominated by the United States at 599 claims, then the United Kingdom, Canada, India, Australia and Germany. Because regulated institutions disclose under supervisory obligation and rarely appear on leak sites, the visible population here under-represents the sector's true incident rate more than any other in this dataset; a low claim count for a bank is evidence about disclosure behaviour, not about whether it was attacked.
- Recorded incidents: 1,104
- Incidents, trailing 180 days: 276
- Tracked threat actors: 260
- Malware families: 289
Recent incidents
- GSAC Auto Financing 2026-09-03
- Chicago Partners Wealth Advisors 2026-09-03
- Macquarrie 2026-09-03
- Marlborough Partners 2026-09-02
- cfsnow.com 2026-08-31
- Gale Credit Union 2026-08-31
- cimbsecurities.com 2026-08-31
- Susquehanna Valley Federal Credit Union 2026-08-31
- FE CREDIT 2026-08-30
- cutlercapital 2026-08-29
- Jack Henry & Associates 2026-08-28
- DAB Investments 2026-08-27
- Providence Investments 2026-08-27
- Northern Leasing Systems 2026-08-26
- Finodaya Capital Private Limited 2026-08-26
- STRUCTURED SETTLEMENT CAPITAL LLC 2026-08-25
- Country-Wide Insurance 2026-08-24
- Brookview Financial 2026-08-24
- Consultores de Seguros 2026-08-24
- The Cecilian Bank 2026-08-23
Threat actors targeting Financial Services
- Qilin 131 incidents
- Akira 76 incidents
- RansomHub 40 incidents
- KillSec 39 incidents
- Play Ransomware 37 incidents
- LockBit 37 incidents
- INC Ransom 34 incidents
- DragonForce 29 incidents
- The Gentlemen 26 incidents
- BianLian 25 incidents
- Medusa Ransomware 24 incidents
- Cl0p 23 incidents
- ShinyHunters 22 incidents
- Lynx Ransomware 21 incidents
- Hunters International 15 incidents
- SafePay 15 incidents
- FunkSec 13 incidents
- NightSpire 11 incidents
- Coinbase Cartel 10 incidents
- RansomHouse 9 incidents
- Black Basta 8 incidents
- Everest 8 incidents
- Storm 8 incidents
- Meow 7 incidents
Where these victims are
- United States 635
- United Kingdom 42
- Canada 36
- India 20
- Australia 17
- South Korea 14
- Indonesia 13
- Hong Kong 12
- Germany 11
- Brazil 9
- France 9
- Spain 9
Malware used against Financial Services
Families used by the threat actors that target this sector, derived from actor tooling rather than observed in these incidents directly.
- Agent Tesla Malware
- Akira Malware
- Black Basta Malware
- BlackCat Malware
- Clop Malware
- Cobalt Strike Malware
- Conti Malware
- Emotet Malware
- Impacket Tool
- Lumma Stealer Malware
- Metasploit Tool
- Mimikatz Tool
Coverage. 95.5% of incidents in our log carry a sector classification; the remainder name a victim we have not placed in an industry. Counts here are a floor, not a total, and are not comparable between sectors of different sizes.