With modern campaigns such as Vercel-hosted RMM attacks, the scale and security impact of phishing in US finance should not be understated. As threats get increasingly harder to detect, the phishing challenge raises the stakes in the industry.
Legitimate services and tools used in daily workflows across corporate America are increasingly abused to deliver phishing attacks or disguise malicious activity. Identity-based attacks let threat actors spread across an organization from a single, barely detectable entry point.
At the same time, malware itself is only part of the problem. Operational gaps inside SOCs also contribute to the issue.
ANY.RUN investigation data shows how several cybersecurity pressures come together for financial-sector security teams, leading to higher phishing exposure and heavier workloads for individual analysts.
From these challenges also come the solutions security leaders should consider for malware & phishing resilience.
Key Takeaways
- Phishing remains a major risk for US finance, with campaigns becoming more scalable and harder to detect.
- Modern phishing techniques challenge traditional defenses, increasing the need for deeper behavioral and threat visibility.
- ANY.RUN combines real-time analysis with fresh threat intelligence to help SOCs detect malicious activity earlier and investigate with greater context.
- Threat data from 16K+ organizations helps financial security teams expand visibility into emerging threats and reduce risk exposure.
Why Phishing Puts Financial SOCs Under Particular Pressure
The finance sector is saturated with high-value identities, transactions, and sensitive financial data. At the same time, email-heavy workflows create a large attack surface for phishing.
This is reflected in what financial organizations investigate. According to ANY.RUN, 58% of submissions from finance companies are emails, and 14.8% of those emails are malicious.
Phishing exposure in finance is also higher than the overall benchmark. As per ANY.RUN research, 72.7% of finance companies’ investigations involve phishing.
For SOC teams, this increased exposure translates into investigation volume, contributing to heightened analyst pressure. Based on ANY.RUN’s 2026 investigation data across financial organizations, workload per analyst in finance is 24% higher than the global median.
Analysts also face additional pressure when it comes to the evolving, ever-changing nature of modern malware and phishing threats.
For instance, credential compromise can be mitigated comparatively easy through established authentication controls, credential resets, and account remediation. But session compromise, a method increasingly present in modern phishing campaigns like Mirage2FA, creates a challenge at a more serious scale. Attackers can hijack an already authenticated session, making malicious activity harder to detect and contain.
An extra layer of pressure comes from financial organizations operating under strict compliance and investigation requirements. This makes additionalinvestigation overhead particularly costly.
Combined, these operational challenges have a very direct financial dimension. According to the FBI, business email compromise alone generated more than $55 billion in reported exposed losses globally between October 2013 and December 2023.
The US Factor: Higher Stakes for Financial Organizations
The US phishing landscape overall comes with significant financial stakes. In 2025, the FBI recorded 191,561 phishing and spoofing complaints, while business email compromise (BEC) generated more than $3 billion in reported losses.
The threat activity observed across financial organizations helps put this scale into context. Phishing kits such as Tycoon2FA, Sneaky2FA, EvilProxy, ClickFix, and Eviltokens are 5 of the most common threats seen in ANY.RUN investigations. In 2026 alone, leading phishing kits appeared in samples submitted for analysis by 883 financial-sector organizations using ANY.RUN globally.
| Malware Family | Prevalence |
|---|---|
| Tycoon2FA | 18.7% |
| Sneaky2FA | 17.1% |
| EvilProxy | 13.5% |
| ClickFix | 11.8% |
| EvilTokens | 10.5% |
For US SOCs in particular, phishing pressure is also linked to local business and financial flows. Attackers adapt lures to events such as the US tax season, using fake tax forms, IRS-related communications, and other time-sensitive financial documents when employees are more likely to expect them. This adds another layer of credibility to attacks already designed to blend into legitimate workflows.
The same principle extends to the tools and brands employees trust every day. Attackers abuse Microsoft 365, Adobe, cloud infrastructure, document-sharing services, and other legitimate services to make malicious activity harder to separate from normal business traffic.
The result is a particularly costly combination: high phishing and BEC impact at the national level, while the threats financial SOCs investigate are becoming increasingly difficult to separate from legitimate activity.
Top Solutions for SOC Challenges in Finance
A total of 1,811 financial industry businesses use ANY.RUN products to investigate threats and strengthen their security operations. Their success stories demonstrate measurable improvements across key SOC workflows, driven by solutions to some of the sector’s most persistent security challenges:
1. Detecting Threats Before They Spread
As phishing infrastructure and attack techniques change rapidly, making reactive defense strategy less efficient, early detection gives security teams more time to act.
ANY.RUN combines real-time behavioral analysis with fresh threat intelligence to help analysts identify malicious activity before an initial compromise develops into a larger incident. This allows SOC teams to contain threats earlier and reduce their potential operational and financial impact.
2. Catching More Evasive Threats
Modern phishing increasingly abuses legitimate services and tools and relies on evasion techniques that make malicious activity harder to recognize.
Interactive analysis exposes redirects, network connections, processes, payloads, and other behavior behind suspicious emails, URLs, and files, helping analysts uncover threats other detection may miss.
3. Reducing Investigation Time
In finance, slow investigations can leave more time for identity compromise, data exposure, and financial impact.
ANY.RUN gives analysts behavioral context and threat intelligence in one investigation workflow, reducing dwell time and manual work required to understand an attack and reach a reliable decision.
To learn about the latest supply chain attacks early, SOC teams also rely on ANY.RUN’s TI Reports that provide overviews of emerging threats. Curated by an expert team of threat intelligence analysts, these reports offer actionable indicators along with recommendations on how to detect new malware strains.
4. Handling Higher Workloads with Fewer Escalations
With workload per analyst 24% higher in finance than the global median, making better use of existing SOC capacity is critical.
Detailed threat context helps Tier 1 analysts validate and resolve more cases independently, keeping senior analysts focused on incidents that require deeper investigation.
5. Turning Every Investigation Into Broader Threat Visibility
A phishing investigation can provide value well beyond the initial verdict.
With Threat Intelligence Feeds, ANY.RUN extracts IOCs and connects them with behavioral and threat context, providing them with intelligence to be reusedacross threat hunting, detection engineering, SIEM workflows, and future investigations.
Using Threat Intelligence Lookup, your team can also track threats by industry and region. To browse US-submitted malware samples across financial organizations, use this TI Lookup query:
submissionCountry:”US” AND industry:”finance”
This allows you to take the upper hand in the race against threat actors and collect live threat intelligence from 16K+ SOCs and 700K+ security experts to strengthen proactive defense against modern phishing.
Conclusion
American SOC teams across finance sector operate in a high-risk environment where sophisticated threats, growing alert volumes, strict security requirements, and pressure to respond quickly all converge.
ANY.RUN helps close these gaps without increasing the amount of manual investigation required by combining interactive analysis with actionable threat intelligence. It provides analysts with opportunity to:
- Validate suspicious activity with real-time behavioral analysis in the Interactive Sandbox
- Uncover full attack behavior with process, network, and system activity visibility
- Enrich IOCs with context using Threat Intelligence Lookup
- Identify related infrastructure by pivoting across connected URLs, domains, IPs, files, and analyses
For financial organizations, this translates into stronger threat visibility, faster and more confident investigations, and less operational pressure on SOC teams.
With threat data continuously generated across 16K+ organizations and an average MTTD of 14 seconds, ANY.RUN helps security teams detect threats earlier, reduce exposure, and protect critical financial systems and customer data.
About ANY.RUN
ANY.RUN is a leading provider of interactive malware analysis and threat intelligence solutions, helping organizations investigate threats faster and make informed response decisions based on clear behavioral evidence.
Its solutions include the Interactive Sandbox for enterprise-scale malware and phishing analysis, as well as Threat Intelligence products powered by investigation data from more than 16,000 organizations. This intelligence enables security teams to enrich alerts, identify emerging threats earlier, and bring relevant context into detection, investigation, and response workflows.
ANY.RUN is SOC 2 Type II attested, reflecting its commitment to robust security controls and customer data protection. For SOCs, MSSPs, and enterprise security teams, ANY.RUN helps reduce investigation uncertainty, speed up triage, and turn threat analysis into actionable security decisions.
0 comments
