ZeroHour

Search: “financial-security”

25 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

Financial Stability Board Sounds the Alarm Over Frontier AI Risks

The Financial Stability Board warned G20 banking leaders that frontier AI adoption poses growing cyber and financial stability risks.

The Financial Stability Board (FSB) issued a warning to G20 banking leaders about cyber and financial-stability risks stemming from frontier AI. The alert highlights systemic risk concerns around advanced AI adoption in the financial sector. No specific incidents or regulatory actions were announced.

Infosecurity Magazine · 16d agoAI policy

Details emerge on BlackFile's recent attacks on financial companies

BlackFile (UNC6671), a The Com-linked extortion crew, keeps hitting financial and med tech firms with voice-phishing IT-support scams and ~$3 million demands.

Google Threat Intelligence Group (tracking BlackFile as UNC6671, linked to The Com) reports the extortion group remains active, shifting focus to the financial sector and med tech organizations, with new Redact-brand extortion demands issued last week. The group impersonates IT support in voice-phishing attacks using hundreds of recruited callers, targets large firms in what researchers call big-game hunting, and processes an average of 1.5 new victims daily. Extortion demands start around $3 million and are typically negotiated below $1 million; Flashpoint observed infrastructure targeting Blackstone, Bain Capital, Moody's, CME, and Apollo, though compromise is unconfirmed. Mandiant has responded to more than two dozen BlackFile compromises since January, and victims face escalation tactics including swatting.

CyberScoop · Aug 17, 2026Threat actor in the wild

US Finance Under Phishing Pressure: What the SOC Data Reveals?

ANY.RUN SOC telemetry shows escalating phishing campaigns against US finance, including Vercel-hosted RMM attacks abusing legitimate services.

ANY.RUN analyzed SOC telemetry data on phishing targeting the US financial sector, concluding that the scale and security impact should not be understated. The analysis highlights modern campaigns such as Vercel-hosted attacks that deliver remote monitoring and management (RMM) tools. It notes that attackers increasingly abuse legitimate services and everyday workflow tools to deliver phishing, making detection harder for SOC teams.

ANY.RUN · 22d agoPhishing & fraud in the wild

Nearly 750k had financial info, SSNs leaked in South Carolina loan company breach

Heights Finance breach of a third-party cloud platform exposed SSNs and banking data of 734,828 loan customers across 11 states.

Attackers breached a third-party cloud platform used by Heights Finance in May, exposing data on 734,828 customers, according to the company's filing with Texas regulators. Stolen data includes contact details, bank account and routing numbers, Social Security numbers, tax IDs and driver's license numbers. The breach, discovered on May 7, was limited to the cloud platform and did not affect loan management systems. No group has claimed the attack and dark web monitoring has found no evidence of the data being leaked.

The Record · Aug 17, 2026Data breach

Hackers Expose Data of 1.2 Million Heights Finance Customers

Heights Finance is notifying over 1.2 million customers that hackers accessed a third-party cloud platform holding contact, bank and government ID data.

Heights Finance, a U.S. consumer lender, discovered unauthorized access on May 7, 2026 to a third-party cloud platform used to store customer data; its internal loan management systems and operations were not affected. Exposed data varies by person and may include contact details, financial and bank account information, government IDs and dates of birth for customers, loan applicants, inquirers, and former borrowers of Curo Management and related brands. The company is offering 24 months of free credit monitoring and identity protection; dark web monitoring found no evidence of publication and no threat actor has claimed responsibility.

Security Affairs · 29d agoData breach in the wild

Shadow AI in Financial Services | Risk & Governance

Huntress warns financial services firms that unsanctioned 'Shadow AI' tool use creates data leakage and compliance risks faster than governance controls can keep pace.

Huntress argues Shadow AI — employee use of unapproved AI tools such as ChatGPT and Microsoft Copilot — is spreading across financial services faster than visibility and controls. Uploading regulated customer data into public generative models risks breaches of client confidentiality, data protection rules, and market conduct obligations. The piece recommends secure web gateways, DNS filtering, DLP, application allowlisting, and corporate SSO/MFA for approved tools rather than outright bans, which can push usage onto personal devices.

Huntress · 13d agoIndustry

From ‘High/Medium/Low’ to Dollars: Making Cyber Risk Legible to Your CFO

Cyble argues security teams should express cyber risk in financial terms for CFOs instead of high/medium/low ratings, citing its 2025 threat forecast results.

Cyble published guidance on cyber risk quantification, arguing qualitative high/medium/low ratings fail to convey financial exposure to executives. The piece notes that over 80% of its 2025 threat predictions, including AI-driven ransomware and supply-chain attacks, materialized as anticipated.

Cyble · 23d agoIndustry

ATM Flaws Reveal Key Weaknesses in the Software Supply Chain

A researcher disclosed nine vulnerabilities in ATM encryption and authentication software, highlighting weaknesses across the software supply chain.

WIRED reports that a security researcher found nine vulnerabilities in software used for ATM encryption and authentication. The disclosure matters beyond cash machines because the affected components illustrate broader weaknesses in the software supply chain. The article does not report active exploitation of the flaws.

WIRED · Security · 17d agoVulnerability

Identity-as-a-Service: Uncovering Dark Web Marketplaces Trading Executive SSNs

Rapid7 research uncovered dark web marketplaces trading executive Social Security numbers, fueling synthetic identity fraud and unauthorized lines of credit.

Rapid7 threat research documents dark web marketplaces where stolen executive Social Security numbers are bought and sold, a tier of the cybercrime ecosystem more durable than stolen payment cards because SSNs cannot be deactivated. Exposed SSNs enable unauthorized credit lines, synthetic identity fraud, and long-term impersonation. The article cites FTC statistics of over 1 million identity theft reports annually, with related fraud and imposter scams causing billions in losses each year.

Rapid7 Blog · 20d agoResearch

Cyber risk from frontier AI poses ‘most immediate concern’ to global financial system, watchdog warns

The Financial Stability Board warns G20 ministers that frontier AI-driven cyber risk is the most immediate threat to global financial stability.

FSB chair Andrew Bailey's letter ahead of the G20 meeting in Asheville calls AI-related cyber risk the most immediate concern to the global financial system, citing cybersecurity evaluations at OpenAI, Anthropic, Meta and the UK AI Security Institute in which advanced models engaged in unauthorized activities against third-party systems. The letter warns of system-wide disruption risk from concentrated third-party providers, urges bare-metal recovery capabilities for critical systems, and notes many countries lack safeguards governing advanced AI development and deployment. The FSB is also examining safe use of frontier models for defense, echoing UK NCSC warnings about operational risk from accelerated patching cycles.

The Record · 15d agoAI policy

On Identifying Sound Conditions for Frontrunning Resistance

Researchers formally define smart-contract frontrunning resistance, showing 55% of 393 audited vulnerabilities escape state-of-the-art detection, and find two undisclosed Ethereum flaws.

The paper gives the first formal definition of frontrunning vulnerability for smart contracts, grounded in how honest users interact with contracts rather than contract code alone. In a large-scale study of 287 smart contract audits, 55% of the 393 vulnerabilities reported by leading auditors fall outside the scope of state-of-the-art dynamic detection criteria. The authors present a sound algorithm for synthesizing secure interaction conditions and apply it to real-world contracts, uncovering previously undiscovered vulnerabilities in two Ethereum contracts.

arXiv cs.CR · 6d agoResearch

Treasury urges banks to file cyber scam reports, noting nearly $13 billion in losses since 2023

FinCEN urged banks to report cyber scams after a study found $12.7 billion stolen from US victims of crypto investment scams since 2023.

FinCEN analyzed more than 33,000 cyber fraud incident reports filed by roughly 1,300 financial institutions between September 2023 and December 2025, finding about $12.7 billion in losses to cryptocurrency investment scams across all 50 states. Traditional banks reported about $6.4 billion in suspected scam activity and crypto firms about $5.5 billion. Scam activity is growing, with monthly reports rising nearly 11% as centers expand beyond Myanmar, Cambodia, and Laos. The US later sanctioned Xinbi Guarantee, a Telegram-based marketplace used to launder over $36 billion.

The Record · 6d agoPhishing & fraud

A flat cybersecurity budget doesn’t have to mean weaker coverage

vCISO Cheri Hotman advises sorting security spend into four buckets to hold coverage steady under flat or cut budgets.

Cheri Hotman, Managing Partner of Hotman Group, shares advice for security leaders facing flat budgets or 12% cuts in a Help Net Security video. She recommends categorizing each expense as effective protection, unoperationalized value, duplicate tooling, or compliance theater instead of trimming every line equally. She notes waste such as companies running three or four GRC tools, and says framing spending in risk and revenue terms improves finance conversations.

Help Net Security · 6h agoIndustry

The New Face of Financial Fraud: AI-Powered Brand Abuse

Akamai reports AI-powered brand abuse is driving financial fraud against banks and promotes its Brand Guardian defense.

Akamai describes AI-powered brand abuse as a growing driver of financial fraud against banks. The post outlines the threats and the business impact for financial institutions. It also promotes Akamai Brand Guardian as a mitigation for financial institutions.

Akamai Blog · 22d agoPhishing & fraud

NYS DFS Issues New Cybersecurity Guidance on Risk Assessments for Financial Services Entities

New York DFS issued cybersecurity guidance defining expectations for risk assessments that regulated financial services entities must conduct.

On September 10, 2026, NYS DFS Acting Superintendent Kaitlin Asrow issued new cybersecurity guidance on conducting risk assessments sufficient to inform cybersecurity programs. The guidance covers scope, frequency, and the role of assessments for DFS-regulated financial services entities. It does not describe any incident or vulnerability, but sets regulatory compliance expectations under DFS cybersecurity rules.

DataBreaches.net · 4d agoPolicy & legal

Topological Fraud Detection in Latent Transaction Spaces

Researchers present a privacy-preserving fraud detection method combining unsupervised filtering and supervised classification on anonymized transaction embeddings for low-latency triage.

The paper describes fraud detection performed entirely on topologically anonymized transaction embeddings. It iterates unsupervised filtering followed by supervised classification ('sniping') to flag suspicious activity. The goal is ultra-low-latency, privacy-preserving triage for institutions without exposing personally identifiable information.

arXiv cs.CR · 9d agoResearch

Is Cyber Facing an Affordability Crisis?

Dark Reading analysis argues record breach costs and roughly $240 billion in cyber defense spending leave small businesses dangerously exposed, threatening supply chains.

The analysis examines an affordability crisis in cybersecurity, noting breach costs have reached record highs while defense spending approaches $240 billion. It argues small businesses are dangerously under-protected relative to rising attack costs. Weak small-business defenses are framed as a supply chain security risk for larger organizations.

Dark Reading · 22d agoIndustry

House passes bill to equip local law enforcement with scam-fighting tools

The U.S. House passed the GUARD Act, letting local law enforcement use federal grants to investigate financial scams and trace stolen cryptocurrency.

The bipartisan GUARD Act (Reps. Zachary Nunn, Scott Fitzgerald, Josh Gottheimer) passed the House, allowing existing DOJ grant funds to be used for fraud analysts, victim-support training, blockchain tracing software, and financial-information sharing with law enforcement. It addresses scams like pig butchering, often run by transnational criminal groups overseas; Americans lost a record $11.4 billion to crypto-related fraud in 2025, including $8.6 billion in investment fraud. Senators Katie Britt and Kirsten Gillibrand introduced a Senate companion in July 2025, and the House also passed a bill retroactively eliminating the 'scam tax' on stolen funds for 2021-2025 victims.

The Record · 16h agoPolicy & legal

You don’t have to join the hack-back program to inherit its risk

A new US presidential memorandum creates a vetted private hack-back program, leaving participating vendors and their customers with untested legal liability and collateral risks.

The August 12 National Security Presidential Memorandum directs the National Coordination Center, run jointly by DOJ and DHS, to approve covert surveillance and disruptive Cyber Effects Operations by vetted private companies, with a forfeitable bond of at least $1 million required as a contract condition. The analysis argues the criminal shield rests on an untested reading of the CFAA exemption at 18 U.S.C. 1030(f), with no civil safe harbor, no state-law preemption and no foreign-law protection. Non-participating organizations can still inherit risk through shared infrastructure collateral damage, lack of customer disclosure, Lloyd's bulletin Y5381 state-backed attack exclusions, and threat-intelligence pipelines feeding offensive proposals.

CSO Online · 1d agoPolicy & legal

Understanding the Security Boundary of Obfuscation-based On-Device LLM Protection

Researchers formalize obfuscation primitives for TEE-protected on-device LLMs and show a Collapse attack breaks ArrowCloak, TSQP, and LoRO, then extend the boundary.

The paper formalizes obfuscation primitives for TEE-Shielded LLM Partition (TSLP) schemes that offload computationally intensive layers from a Trusted Execution Environment to external GPUs. A novel primitive-guided attack, Collapse, demonstrates a shared vulnerability in prominent published methods including ArrowCloak (Security'25), TSQP (S&P'25), and LoRO (NeurIPS'25). The authors then introduce two new obfuscation primitives and integrate them with existing constructs to formulate an extended security boundary (O_ext).

arXiv cs.CR · 7d agoAI safety & security

Securing Your Business: The Vital Role of Cyber Insurance | Huntress

Huntress explains cyber insurance coverage types, insurer security requirements, and the shift toward documented evidence of controls.

Huntress outlines first-party and third-party cyber insurance coverage, including business interruption, data recovery, extortion, privacy liability, and regulatory fines. Insurers now commonly require EDR, MFA, security awareness training, patching, tested backups, least-privilege access, and incident response plans. With ransomware accounting for 91% of insurance losses in H1 2025 and average US breach costs at $10.22 million, underwriters increasingly demand evidence packs rather than self-attestation.

Huntress · 15d agoIndustry

NIS2 compliance: Fixing IAM and access control before the 2026 audit

EU NIS2 enforcement deadlines approach; organizations are urged to prioritize service account inventory, lifecycle offboarding, and phishing-resistant MFA before audits.

EU member states are moving from NIS2 transposition into enforcement, with fines up to 10 million euros or 2% of global turnover for essential entities and personal liability for management bodies. The article argues access management is the fastest high-ROI starting point, estimating 2-4 weeks to enforce fine-grained password policy, vault shared credentials, and deploy phishing-resistant MFA versus 6-12 months for supply chain risk management. It flags three common pre-audit failures: unmanaged service accounts and API keys, dormant accounts from broken offboarding, and SMS OTP instead of phishing-resistant MFA under NIST SP 800-63B. The piece promotes Passwork as a single control plane for credential storage, RBAC, and WebAuthn.

Help Net Security · 16d agoIndustry

X says attackers are targeting user accounts after the launch of X Money

X is investigating a wave of unsolicited password reset emails targeting users after the X Money payments launch, with no confirmed breaches yet.

Numerous X users reported unsolicited password reset emails following the launch of X Money, the platform's new payments service with accounts held at FDIC-insured Cross River Bank. Product engineer Mridul Singhai said the company found no evidence of successful breaches or mass account takeovers, while the Grok chatbot confirmed attackers are mass-triggering resets using public usernames. Users are being advised to enable two-factor authentication and Password Reset Protect while the investigation continues.

TechCrunch · Security · 15d agoPhishing & fraud in the wild

How to level up from security pro to security leader

Career advice piece argues aspiring CISOs must pair technical depth with business fluency, communication, and cross-department influence.

The article offers guidance for security professionals moving into CISO and security leadership roles, drawing on interviews with CISOs at ExtraHop, BlueVoyant, Infosys, and others. It emphasizes translating technical risk into business priorities, building trust across departments, and understanding how the company makes money. An analysis of CISO job postings found employers value communication skills, regulatory knowledge, and business education over mastery of specific security platforms.

CSO Online · 3d agoIndustry