An AI voice agent posing as your bank's IT desk. Stolen identities packaged with financial profiles. Document forgery services with mules to complete verification. And a $1.5 billion crypto heist carried out by a nation-state threat group. These are driving today's threats against the financial sector as geopolitical flashpoints turn hacktivist ideology into disruptive campaigns and data extortion groups keep finding cracks in even the most heavily defended networks.
Our latest report, Follow the Money: Cyber Threats to the Financial Sector, reveals what that threat activity looks like from inside the underground communities where it's planned, sold, and discussed. This provides security and fraud teams with a deeper look into named threat actors, specific incidents, malware capabilities, and the underground marketplaces actively selling access to financial institutions and services enabling financial fraud.
We look at major threats to enterprises in the sector and the separate category of underground services that drive consumer-facing threats such as payment fraud, automated carding attacks, banking trojans, phishing-as-a-service offerings, AI-enabled document forgery and verification bypass, and identity theft.
The report contains Intel 471’s monitoring of closed-access forums, data leak sites, marketplaces and Telegram groups and research into the cybercriminal underground backed by insights from the Adversary Intelligence team’s human intelligence (HUMINT) engagements between January 2025 and June 2026.
Enterprise Threats
The highly regulated financial services sector has invested in advanced, multilayered cybersecurity defenses, but it is not impenetrable. Exposure to key third parties, supply chain compromises, sophisticated credential phishing attacks and the credential and access market provided a way in for data extortion actors.
- In April 2026, the Everest data extortion-as-a-service (DEaaS) program operator claimed to compromise two U.S.-based banks. Both banks confirmed the breaches originated from a third-party vendor rather than from direct unauthorized access to their own networks.
- In early 2026, the BlackFile group allegedly carried out multiple voice phishing (vishing) and data extortion campaigns targeting U.S.-based hedge funds and other investment management organizations. The actors impersonated IT support personnel and directed employees to customized phishing pages that imitated Okta or Microsoft 365 authentication portals. These pages were designed to capture credentials, session tokens and MFA codes, enabling the actors to access cloud services and steal sensitive corporate data for extortion.
- On Jan. 21, 2026, the CLOP ransomware and data extortion group claimed to compromise a U.K.-based payments and commerce services company. In the past, CLOP has exploited vulnerabilities in widely deployed, centralized enterprise products, creating a supply-chain-like concentration effect across downstream customers.
Our data revealed extortion groups targeted 340 victims in 74 countries in the financial services sector during the period, with the U.S., U.K., and Canada bearing the brunt of it. The most prevalent groups were Qilin, Akira, and The Gentlemen, and the most impacted within the sector were insurance, investment management and banking and securities.
Image: Ransomware and data extortion attacks on the financial services sector between January 2025 and June 2026.
Initial access brokers, which specialize in gaining unauthorized access, provide another entry point. These brokers advertised unauthorized access impacting 159 financial services entities over the period. We observed actors offering to sell unauthorized access via compromised virtual private network (VPN) credentials to the networks of about 60 companies and an offer to sell remote desktop protocol (RDP) and shell access for a South Africa-based financial institution.
Hacktivists are a persistent threat to critical infrastructure, including financial sector entities. We tracked 562 DDoS attacks claimed against the financial sector in the reporting window, led by NoName057(16) and Dark Storm Team. Hacktivist campaigns map closely to real-world flashpoints such as the Russia-Ukraine conflict and tensions in the Middle East, with groups explicitly framing bank disruptions as blows against the countries they oppose. For example, in June 2026, the Iranian group GORZ ROSTAM announced it would launch DDoS attacks against banks in Bahrain and United Arab Emirates (UAE) in response to Israeli military activities. The campaign was initially intended to target a range of Israel-based organizations, but was later expanded beyond Israel by threatening financial institutions in Gulf countries that it accused of supporting Israel and the U.S.
Multiple nation-state groups are targeting the financial sector. The Intel 471 Geopolitical Intelligence team’s reporting informed our analysis of advanced persistent threat (APT) groups that have targeted the financial sector, including the Russian APT groups Ghost Blizzard and Cadet Blizzard and the Chinese APT group Salt Typhoon. We look back at North Korean APT group Lazarus’ hacks over the past decade that have helped the regime skirt sanctions and generate revenue. In February 2025, the group compromised the source code of Safe Wallet — multi-signature software used by the Dubai-based exchange Bybit — to intercept a transfer and siphon US $1.5 billion in Ethereum tokens, becoming the largest cryptocurrency heist in history.
Insiders are an underrated threat. We provide multiple examples demonstrating three distinct patterns of insider involvement: threat actors actively recruiting employees for collaboration, insiders proactively offering their access for sale, and insiders being used to directly facilitate ongoing operations. Each of these represents a different risk profile and a different set of controls needed to catch it.
A Closer Look at Identity, AI and Verification
User-facing threats target customer-accessible applications, user accounts and personal customer data. They also encompass deceptive tactics leveraging social engineering, identity theft and techniques to bypass know-your-customer (KYC) verification.
Identity theft remains a persistent cyber threat, where full identity packages aka “fullz” — including stolen personal credentials and financial profiles — are packaged, traded and monetized across underground marketplaces. In the financial services sector, cybercriminals leverage this stolen data to carry out ATO, synthetic identity fraud, fraudulent loan applications and subscriber identity module (SIM) swapping operations to bypass multifactor authentication (MFA).
KYC controls increasingly rely on selfie and liveness checks to reduce fraud, and a parallel underground industry has grown up to defeat them. A common strategy involves AI-generated selfies, face swapped or deepfake video, camera spoofing and virtual camera tools, and mules completing verification on behalf of an account’s eventual controller.
Part of this ecosystem is document forgery services. In one standout example, an actor in May 2026 advertised a bundle of image manipulation, deepfake, and document forgery services — offering face-swapping, lip-syncing and thousands of customizable document templates, as well as printing services complete with holograms and lamination. The actor also claimed to have a network of mules who could complete identity verification steps in person on a buyer's behalf. In other cases, actors offered services that utilize forged documents and fake selfies to register financial accounts, bypass security measures or unfreeze compromised cryptocurrency wallets.
AI is automating social engineering to bypass MFA. The report details Astaroth, a subscription service that used an AI voice agent to impersonate financial-institution staff and talk victims out of their one-time passcodes. Buyers got pre-made, multi-language scripts targeting customers of specific platforms, the option to upload custom text-to-speech audio, and calls reportedly lasting just one to four minutes — enough time to phish a code and enter it before it expired.
What's above is only a slice of what we found. The full Follow the Money report goes deeper into named threat actors, specific incidents, malware capabilities, and the underground marketplaces actively selling access to financial institutions right now.
How Intel 471 Can Help
Threats like these often start in a forum listing, a Telegram channel, or a marketplace thread — long before they show up as an incident on a network. Intel 471 helps customers close this gap, providing visibility into where these threats take shape.
Our Adversary Intelligence team combines technical collection with human intelligence (HUMINT) engagements with the actors themselves, so your security and fraud teams can see planned operations and emerging tactics while they're still forming underground. And because we track individual actors, tools, and infrastructure, we can often connect today's marketplace listing and forum discussion to emerging operations.
That intelligence powers Verity471, our AI-driven cyber intelligence platform, through three connected capabilities:
- Exposure maps your external attack surface, surfacing the assets, relationships, and weaknesses adversaries are most likely to go after.
- Intelligence tracks the actors, campaigns, vulnerabilities, and compromised credentials most relevant to your organization and its supply chain, so your team can prioritize what actually matters.
- Hunt turns what we've learned about adversary behavior into more than 800 ready-to-use hunt packages, helping your defenders catch malicious activity sooner and cut dwell time.
Want to see what this looks like for your organization? Download the full report, or reach out to our team at sales@intel471.com to talk through what Verity471 can do for you.
