Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking & Finance Review®

Global Banking & Finance Review® - Subscribe to our newsletter

Company

    GBAF Logo
    • About Us
    • Advertising and Sponsorship
    • Profile & Readership
    • Contact Us
    • Latest News
    • Privacy & Cookies Policies
    • Terms of Use
    • Advertising Terms
    • Issue 81
    • Issue 80
    • Issue 79
    • Issue 78
    • Issue 77
    • Issue 76
    • Issue 75
    • Issue 74
    • Issue 73
    • Issue 72
    • Issue 71
    • Issue 70
    • View All
    • About the Awards
    • Awards Timetable
    • Awards Winners
    • Submit Nominations
    • Testimonials
    • Media Room
    • FAQ
    • Asset Management Awards
    • Brand of the Year Awards
    • Business Awards
    • Cash Management Banking Awards
    • Banking Technology Awards
    • CEO Awards
    • Customer Service Awards
    • CSR Awards
    • Deal of the Year Awards
    • Corporate Governance Awards
    • Corporate Banking Awards
    • Digital Transformation Awards
    • Fintech Awards
    • Education & Training Awards
    • ESG & Sustainability Awards
    • ESG Awards
    • Forex Banking Awards
    • Innovation Awards
    • Insurance & Takaful Awards
    • Investment Banking Awards
    • Investor Relations Awards
    • Leadership Awards
    • Islamic Banking Awards
    • Real Estate Awards
    • Project Finance Awards
    • Process & Product Awards
    • Telecommunication Awards
    • HR & Recruitment Awards
    • Trade Finance Awards
    • The Next 100 Global Awards
    • Wealth Management Awards
    • Travel Awards
    • Years of Excellence Awards
    • Publishing Principles
    • Ownership & Funding
    • Corrections Policy
    • Editorial Code of Ethics
    • Diversity & Inclusion Policy
    • Fact Checking Policy
    Original content: Global Banking and Finance Review - https://www.globalbankingandfinance.com

    A global financial intelligence and recognition platform delivering authoritative insights, data-driven analysis, and institutional benchmarking across Banking, Capital Markets, Investment, Technology, and Financial Infrastructure.

    Copyright © 2010-2026 - All Rights Reserved. | Sitemap | Tags

    Editorial & Advertiser disclosure

    Global Banking & Finance Review® is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    1. Home
    2. >Technology
    3. >Financial Sector Cyber-Attacks: The Ever-Evolving Threat
    Technology

    Financial Sector Cyber-Attacks: The Ever-Evolving Threat

    Published by linker 5

    Posted on February 11, 2021

    6 min read

    Last updated: January 21, 2026

    Add as preferred source on Google
    Cybersecurity in financial services
    Why waste money on news and opinion when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    By Paul Prudhomme, Cyber Threat Intelligence Advisor at  IntSights.

    The banking and financial services industry is under increasing threat from cyber-attacks, particularly from North Korean state-sponsored threat actors and sophisticated Russian criminals. Set against a backdrop of constantly evolving techniques, financial firms must stay ahead of the game,

    The impact of a cyber-attack on a financial sector organisation can be devastating. Take the example of Equifax, the firm breached in 2017 in one of the largest cyber-attacks of all time. The cyber-assault saw hackers steal sensitive data including social security numbers, hitting Equifax’s reputation and resulting in hefty regulatory fines and class action lawsuits.

    The data stored by financial organisations – including bank account and credit card numbers – is extremely valuable. It’s therefore no surprise that this sector is an increasing target for cyber criminals, including Russia, which has some of the most sophisticated criminals, and North Korea, whose government is unique in sponsoring criminal attacks on banks as a source of revenue.

    State-sponsored adversaries may also target the financial sector because, like oil and gas companies and utilities, these institutions are a part of a country’s critical national infrastructure. If hackers can halt the stock exchange – as they did in New Zealand in 2020  – they can create the chaos and fear that fuels their ultimate hybrid warfare aims.  State-sponsored Iranian threat actors also disrupted the websites of U.S. banks in a distributed denial of service (DDoS) campaign in 2012-2013 in retaliation for the implementation of sanctions against the Iranian financial sector due to Iran’s nuclear program.

    In response to this growing threat, the financial sector is creating proactive measures such as security protocols to thwart attempted cyber attacks. Yet all too often, the volume and velocity with which threat actors are developing new tactics, techniques, and procedures (TTPs) still allows them to succeed in their attacks.

    The cyber threat landscape of the banking sector is in constant flux. So, what are the most common attack vectors and methods deployed by cyber-criminals against banks and other financial institutions today?

    Fraud on a grand scale

    Cyber criminals historically focused on fraudulent transactions via stolen payment card information or online banking credentials purchased in underground black markets.

    But attackers are now growing more sophisticated, targeting the bank networks themselves in order to enable fraud on a grand scale. Their goal: To breach bank networks and move laterally to gain access to systems, such as SWIFT terminals or servers that support ATMs.

    One of the most prevalent adversaries in this area is state-sponsored North Korean Lazarus Group. The group, whose aim is to raise revenue for the financially isolated North Korean government, was a pioneer of this more ambitious approach in its fraudulent use of compromised SWIFT access.

    Other cyber criminals including sophisticated Russian-speaking hackers have followed suit and targeted different internal banking systems in a bid to enable large-scale fraud in other ways.

    Paul Prudhomme

    Paul Prudhomme

    For example, MoneyTaker targeted the Automated Workstation Client of the Central Bank of Russia (AWS CBR), a SWIFT-like interbank payment system, in a similar manner.

    MoneyTaker also targeted card processing systems within banks to enable fraudulent card transactions that the attackers controlled by changing or removing withdrawal and overdraft limits.

    Online payment card fraud is another area of growth. This type of attack replaces in-person fraud following the 2015 introduction of EMV chips in the US to prevent the cloning of compromised cards.

    Digital card skimmers

    Digital card skimmers have become an increasing avenue of attack, taking aim at online commerce rather than the physical point of sale systems more commonly targeted in the past.

    Ticketmaster and British Airways are just two of the firms that have fallen victim to the now infamous Magecart hackers, who planted malicious code in the companies’ payment pages to steal customer details, including card CVVs.

    The risk of online based cyber attacks has increased further during Covid-19 as people rely on e-commerce rather than high street shopping.

    New banking Trojans

    Banking Trojans have been around for a while, but they are becoming more sophisticated to inflict more damage upon victims via new functionality beyond their primary purpose.

    For example, two of the most prolific Windows banking Trojans in recent years Emotet and TrickBot, expanded their functionality to the point that the compromise of online banking credentials was arguably no longer their core function.  In fact, Emotet and TrickBot have often served as downloaders for other types of criminal malware, particularly ransomware. This type of malware, which locks systems in exchange for a ransom, is sometimes deployed by attackers after they have collected online banking credentials and other information they can monetise.  Emotet was the target of a recent international law enforcement operation to take down its infrastructure, which could lead to its demise in the long-term.

    Mobile banking Trojans have become important for two reasons. First, the widespread adoption of banking apps makes mobile devices an equally, or even more important target for attackers that seek to compromise online banking credentials.

    Secondly, adversaries are looking to take advantage of the fact that two-factor authentication (2FA) for online banking logins relies on mobile devices, via either SMS or authentication apps.

    Compromising mobile devices with banking Trojans can therefore facilitate attacks on online banking credentials by enabling 2FA bypasses. Indeed, SMS intercept functionality is typical of mobile banking Trojans, and some even have the ability to collect 2FA codes from authentication apps.

    A proactive approach

    As the threat to the financial sector increases, with North Korean and Russian adversaries operating with impunity, it’s often said that security is a constant game of cat and mouse. That is why it’s integral to take a proactive approach to threat detection and prevention.

    Financial sector attacks focus on lateral movement within bank networks to the most sensitive systems that can enable large-scale fraud, such as SWIFT terminals, ATM servers, and card processing systems.

    It is with this in mind that network defenders should aim to reduce opportunities for lateral movement within their networks. This can be done through network segmentation and heightened security measures for the most financially sensitive systems.

    As part of this, firms need to apply stringent authentication for financially sensitive systems and tools that could enable large-scale fraud in the event of a compromise.

    Another key factor in staying ahead of attackers is cyber threat intelligence – knowing your enemy and its TTPs – which equips security practitioners with the knowledge they need to protect their organisations.

    Threat intelligence works because it’s sector-specific and based on data unique to organisations and the vertical at large. This empowers financial sector institutions to act swiftly in response to emerging threats and shut them down before they evolve into fully-fledged cyber attacks.

    More from Technology

    Explore more articles in the Technology category

    Image for Showcasing Digital Leadership – Best Bank for Social Media 2026
    Showcasing Digital Leadership – Best Bank for Social Media 2026
    Image for Innovation Through Partnership: The Role of External Tech Teams
    Innovation Through Partnership: The Role of External Tech Teams
    Image for Nominations Open for Technology Awards 2026
    Nominations Open for Technology Awards 2026
    Image for Nominations Open for Innovation Awards 2026
    Nominations Open for Innovation Awards 2026
    Image for Archie earns industry recognition across G2, Capterra, and SoftwareReviews
    Archie Earns Industry Recognition Across G2, Capterra, and SoftwareReviews
    Image for The Bankaool Transformation: How a Regional Mexican Bank Became a Fintech Disruptor
    The Bankaool Transformation: How a Regional Mexican Bank Became a FinTech Disruptor
    Image for Submit Your Entry Today for Digital Banking Awards 2026
    Submit Your Entry Today for Digital Banking Awards 2026
    Image for Behavioral AI in Financial Services: Moving Beyond Automation Toward Human Understanding
    Behavioral AI in Financial Services: Moving Beyond Automation Toward Human Understanding
    Image for Submit Your Entry for Brand of the Year Awards Technology Bahrain 2026
    Submit Your Entry for Brand of the Year Awards Technology Bahrain 2026
    Image for Entries Now Open for Best Islamic Open Banking Burkina Faso APIs 2026
    Entries Now Open for Best Islamic Open Banking Burkina Faso APIs 2026
    Image for Entrepreneurial Discipline in the AI Economy: Insights from Dmytro Lavryniuk
    Entrepreneurial Discipline in the AI Economy: Insights From Dmytro Lavryniuk
    Image for Entries Now Open for Best New Digital Wallet Innovation Award 2026
    Entries Now Open for Best New Digital Wallet Innovation Award 2026
    View All Technology Posts
    Previous Technology Post2021 Will Be a Landmark Year for Open Banking Technology
    Next Technology PostAI Offers a Galaxy of Opportunities for Firms With High Volume Document Handling Workloads