Tag: finance
-
Topsy-Turvy Data Breach Reality: Incidents Up, Victims Down
Most Compromises Trace to Financial Services, Healthcare, Professional Services. Data breaches rage on. In the first half of this year, the Identity Theft Resource Center counted 1,732 total data breaches affecting 166 million people, marking a rise in data breaches but a decline in victims, likely due to a drop in mega-breaches. First seen on…
-
H2Miner Targets Linux, Windows, and Containers to Illicitly Mine Monero
FortiGuard Labs researchers have uncovered a sophisticated cryptomining campaign where the H2Miner botnet, active since late 2019, has expanded its operations to target Linux, Windows, and containerized environments simultaneously. The campaign represents a significant evolution in cross-platform cryptocurrency mining attacks, with threat actors leveraging updated scripts and infrastructure to maximize financial gains from compromised systems.…
-
Chinese State-Sponsored Hackers Target Semiconductor Industry with Weaponized Cobalt Strike
Proofpoint Threat Research has identified a sophisticated multi-pronged cyberespionage campaign targeting Taiwan’s semiconductor industry between March and June 2025. Three distinct Chinese state-sponsored threat actors, designated as UNK_FistBump, UNK_DropPitch, and UNK_SparkyCarp, conducted coordinated phishing operations against organizations spanning semiconductor manufacturing, design, testing, supply chain entities, and financial investment analysts specializing in the Taiwanese semiconductor market.…
-
China-linked hackers target Taiwan chip firms in a coordinated espionage campaign
Tags: access, ai, attack, china, compliance, control, credentials, cyber, cybersecurity, detection, email, espionage, exploit, finance, framework, government, group, hacker, intelligence, international, login, monitoring, network, phishing, software, supply-chain, technology, threat, warfareInvestment banks in the crosshairs: A second group, UNK_DropPitch, targeted the financial ecosystem surrounding Taiwan’s semiconductor industry. This group conducted phishing campaigns against investment banks, focusing on individuals specializing in Taiwanese semiconductor analysis. The phishing emails purported to come from fictitious financial firms seeking collaboration opportunities.The third group, UNK_SparkyCarp, focused on credential harvesting through sophisticated…
-
Chinese Hackers Target Taiwan’s Semiconductor Sector with Cobalt Strike, Custom Backdoors
The Taiwanese semiconductor industry has become the target of spear-phishing campaigns undertaken by three Chinese state-sponsored threat actors.”Targets of these campaigns ranged from organizations involved in the manufacturing, design, and testing of semiconductors and integrated circuits, wider equipment and services supply chain entities within this sector, as well as financial investment First seen on thehackernews.com…
-
Most European Financial Firms Still Lagging on DORA Compliance
A Veeam survey found that 96% of financial services organizations believe their current levels of data resilience falls short of DORA compliance, citing major challenges First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/european-financial-dora-compliance/
-
How AI is changing the GRC strategy
Tags: access, ai, best-practice, breach, business, ciso, compliance, control, data, detection, finance, framework, fraud, governance, grc, guide, law, monitoring, network, nist, privacy, regulation, risk, risk-analysis, risk-management, strategy, threat, toolAdapting existing frameworks with AI risk controls: AI risks include data safety, misuse of AI tools, privacy considerations, shadow AI, bias and ethical considerations, hallucinations and validating results, legal and reputational issues, and model governance to name a few.AI-related risks should be established as a distinct category within the organization’s risk portfolio by integrating into…
-
SquidLoader Deploys Stealthy Malware with Near-Zero Detection to Evade Security Measures
A fresh variant of SquidLoader malware has surfaced, actively entering Hong Kong institutions with previously unheard-of stealth, which is alarming for the financial industry. This sophisticated loader achieves near-zero detection rates on platforms like VirusTotal, leveraging intricate anti-analysis, anti-sandbox, and anti-debugging mechanisms to deploy Cobalt Strike Beacons for remote access. The malware’s attack chain begins…
-
SquidLoader Malware Campaign Targets Hong Kong Financial Sector
A new malware campaign targeting Hong Kong finance has been identified, featuring SquidLoader to deploy Cobalt Strike Beacon First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/squidloader-malware-targets-hong/
-
Securing the Budget: Demonstrating Cybersecurity’s Return
By tying security investments to measurable outcomes, like reduced breach likelihood and financial impact, CISOs can align internal stakeholders and justify spending based on real-world risk. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/securing-budget-cybersecurity-return
-
Co-op boss admits all 6.5m members had data stolen in cyber-attack
CEO Shirine Khoury-Haq says hackers stole contact details of all members but not financial data such as card numbers The chief executive of the Co-op has apologised to its customers after admitting that all 6.5 million of the mutual’s members had their data stolen in a recent cyber-attack.Shirine Khoury-Haq told the BBC she was “incredibly…
-
Unbefugter Zugriff bei einer Bank auf den Seychellen
Seychelles Commercial Bank Confirms Customer Data Breach First seen on bankinfosecurity.com Jump to article: www.bankinfosecurity.com/seychelles-commercial-bank-confirms-customer-data-breach-a-28972
-
Seychelles Commercial Bank Confirms Customer Data Breach
Hacker Claims to Have Exploited Flaw in Oracle WebLogic Server, Sold Stolen Data. Seychelles Commercial Bank is warning customers that a hacker stole their personal information – but no money – from their accounts after breaching its systems. The hacker involved claims to have stolen and sold two gigabytes of customer data from the bank,…
-
New AI-Powered PayPal Scam Tricks You Into Calling a Fake Support Line
PayPal warns of a new AI-powered scam tricking users into calling fake support lines. Learn how to protect yourself. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/news/ai-powered-paypal-scam/
-
MITRE Launches New Framework to Tackle Crypto Risks
MITRE has introduced AADAPT framework, a new cybersecurity framework aimed at mitigating risks in digital financial systems like cryptocurrency First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/mitre-launches-new-framework/
-
Louis Vuitton says customers in Turkey, South Korea and UK impacted by data breaches
A statement from Louis Vuitton South Korea said the breach involved names, contact information and other data provided by customers. No financial information was included in the breach. First seen on therecord.media Jump to article: therecord.media/louis-vuitton-says-customers-impacted-by-data-breaches
-
MITRE Launches AADAPT Framework for Financial Systems
The new framework is modeled after and meant to complement the MITRE ATT&CK framework, and it is aimed at detecting and responding to cyberattacks on cryptocurrency assets and other financial targets. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/mitre-aadapt-framework-financial-systems
-
Securing Agentic AI: How to Protect the Invisible Identity Access
AI agents promise to automate everything from financial reconciliations to incident response. Yet every time an AI agent spins up a workflow, it has to authenticate somewhere; often with a high-privilege API key, OAuth token, or service account that defenders can’t easily see. These “invisible” non-human identities (NHIs) now outnumber human accounts in most cloud…
-
How defenders use the dark web
Tags: access, antivirus, attack, breach, corporate, credit-card, crypto, cyber, cybercrime, dark-web, data, data-breach, email, extortion, finance, fraud, government, group, hacker, healthcare, identity, incident, insurance, intelligence, Internet, interpol, law, leak, lockbit, mail, malware, monitoring, network, phishing, ransom, ransomware, service, software, theft, threat, tool, usa, vpnAttributing attacks to threat actors: When organizations suffer from data breaches and cyber incidents, the dark web becomes a crucial tool for defenders, including the impacted businesses, their legal teams, and negotiators.Threat actors such as ransomware groups often attack organizations to encrypt and steal their data so they can extort them for money, in exchange…
-
Hacker Returns $42 Million in Stolen Crypto in Exchange for $5 Million Bounty
A security flaw in the GMX V1 software was made public, causing a significant upheaval in the decentralized finance (DeFi) ecosystem and forcing immediate action to protect user assets. GMX, a prominent perpetual futures trading platform built on blockchain technology, relies on its V1 protocol for liquidity provision through its GLP (GMX Liquidity Provider) token.…
-
Factoring Cybersecurity Into Finance’s Digital Strategy
As financial institutions continue to embrace digital transformation, their success will depend on their ability to establish and maintain robust and responsible cybersecurity practices. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/factoring-cybersecurity-finances-digital-strategy
-
Louis Vuitton says UK customer data stolen in cyber-attack
Lead brand of French luxury group LVMH reassures customers financial data such as bank details were not takenLouis Vuitton has said the data of some UK customers has been stolen as it became the <a href=”https://www.theguardian.com/uk-news/2025/jul/10/four-arrested-over-cyber-attacks-marks-and-spencer-co-op-harrods#:~:text=Those%20arrested%20were%20a%2017,old%20British%20woman%20from%20Staffordshire.”>latest retailer targeted by cyber hackers.The retailer, the leading brand of the French luxury group LVMH, said an unauthorised third…
-
Over Half of “Finfluencer” Victims Have Lost Money, Says TSB
Tags: financeBritish bank TSB warns of rise of “finfluencers” who dispense dubious financial advice online First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/finfluencer-victims-tsb/
-
Financial firms are locking the front door but leaving the back open
Financial institutions are building stronger defenses against direct cyberattacks, but they may be overlooking a growing problem: their vendors. According to Black Kite’s new … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2025/07/11/financial-firms-third-party-cyber-risk/
-
How a Former CIO Transformed Treasury IT, Slowly: Part 1
USDT’s Ex-CIO Tony Arcadi on Incremental IT, Oversight, Public Sector Modernization. There’s no place for moonshots when you’re responsible for one of the world’s largest financial institutions, said Tony Arcadi, former CIO at the U.S. Department of the Treasury. In Part 1 of this two-part interview series, Arcadi reflected on his 15-year journey within the…
-
US Sanctions Key Threat Actors Tied to North Korea’s Remote IT Worker Scheme
The Office of Foreign Assets Control (OFAC) of the U.S. Department of the Treasury has taken a strong stance against cyber-enabled financial schemes that support North Korea’s illicit weapons programs by imposing sanctions on Song Kum Hyok, a malevolent cyber actor connected to the hacking group Andariel of the Democratic People’s Republic of Korea (DPRK).…
-
ServiceNow Platform Vulnerability Enables Attackers to Exfiltrate Sensitive Data
Security researchers have identified a critical vulnerability in ServiceNow’s widely-used enterprise platform that could enable attackers to extract sensitive data including personally identifiable information (PII), credentials, and financial records. The flaw, dubbed >>Count(er) Strike
-
Most Cryptocurrency Stocks Are Rising. Join ALR MINER And Earn $8,700 In BTC Every Day
Now, many global cryptocurrency investors view Bitcoin as a financial product for long-term investment rather than a simple speculative product. At the same time, the continued rise in Bitcoin prices reflects the shift in market sentiment and the recent important victory of the Stablecoin Act, which marks a more favorable regulatory environment for cryptocurrencies. Now,…
-
Server with Rockerbox Tax Firm Data Exposed 286GB of Records
Cybersecurity researcher Jeremiah Fowler uncovered a massive 286GB data exposure at Texas-based Rockerbox, a tax credit consultancy. Exposed data includes SSNs, DD214s, and financial details, raising serious identity theft and fraud concerns. First seen on hackread.com Jump to article: hackread.com/rockerbox-server-tax-firm-exposed-sensitive-records/

