Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking and Finance Review

Global Banking & Finance Review

Company

    GBAF Logo
    • About Us
    • Profile
    • Privacy & Cookie Policy
    • Terms of Use
    • Contact Us
    • Advertising
    • Submit Post
    • Latest News
    • Research Reports
    • Press Release
    • Awards▾
      • About the Awards
      • Awards TimeTable
      • Submit Nominations
      • Testimonials
      • Media Room
      • Award Winners
      • FAQ
    • Magazines▾
      • Global Banking & Finance Review Magazine Issue 79
      • Global Banking & Finance Review Magazine Issue 78
      • Global Banking & Finance Review Magazine Issue 77
      • Global Banking & Finance Review Magazine Issue 76
      • Global Banking & Finance Review Magazine Issue 75
      • Global Banking & Finance Review Magazine Issue 73
      • Global Banking & Finance Review Magazine Issue 71
      • Global Banking & Finance Review Magazine Issue 70
      • Global Banking & Finance Review Magazine Issue 69
      • Global Banking & Finance Review Magazine Issue 66
    Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

    Global Banking & Finance Review® is a leading financial portal and online magazine offering News, Analysis, Opinion, Reviews, Interviews & Videos from the world of Banking, Finance, Business, Trading, Technology, Investing, Brokerage, Foreign Exchange, Tax & Legal, Islamic Finance, Asset & Wealth Management.
    Copyright © 2010-2025 GBAF Publications Ltd - All Rights Reserved.

    Editorial & Advertiser disclosure

    Global Banking and Finance Review is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    Home > Finance > Why should the financial sector care about the dark web?
    Finance

    Why should the financial sector care about the dark web?

    Why should the financial sector care about the dark web?

    Published by Jessica Weisman-Pitts

    Posted on September 18, 2023

    Featured image for article about Finance

    Why should the financial sector care about the dark web?

    Dr Gareth Owenson, Co-Founder and CTO, Searchlight Cyber

    The financial sector has a deserved reputation for taking cyber security seriously, but that hasn’t stopped cyber criminals keeping the industry in their cross hairs. In fact, with highly sensitive data and huge sums of money as the potential reward – the average cost of a data breach in the financial sector is $5.9 million – threat actors are constantly evolving their methods of attack. With so much at stake, it is vital organisations equip themselves with the intelligence and capability to defend themselves against impending attacks.

    Many of these cyberattacks originate on the dark web – this secretive corner of the internet where company data is sought and sold to the highest bidder. This is where the foundations are laid by criminals to create the next generation of cyberattacks. Targets are named, malware is bought and sold, and weak spots to attack are identified.

    Shining a light on the dark web

    To combat cybercriminals operating on the dark web, it is important to understand how it works. The dark web cannot be accessed by conventional browsers and does not show up in typical search engine searches. The dark web requires specialist software to gain access to, and provides a high level of anonymity to users. Combined with the anonymity of cryptocurrency, cybercriminals use the dark web to buy and sell sensitive information, exploits, and cybercriminal tools in the belief they can act with impunity.

    However, it is possible for security teams to monitor activity across the dark web’s ecosystem of forums, marketplaces, and websites. This turns it from a shadowy world of unknowns into a source of intelligence for early warning of imminent cyberattacks and, ultimately, can help organisations to prevent their network being breached.

    So, how are cybercriminals on the dark web targeting the financial sector? And how can knowledge of this activity be used to an organisation’s advantage?

    The rise of the Initial Access Broker

    The majority of dark web activity against financial institutions involves posts from what are called ‘Initial Access Brokers’. These are people who use hacking forums like Exploit, XSS, and BreachForums to sell access to company infrastructure via exploits like remote network access or SQL injections. Other criminals, like ransomware groups, then use this access as the starting point for their attacks. Below is an example of an Initial Access Broker post, and the type of information cybercriminals provide:

    Monitoring for this activity can provide invaluable pre-attack intelligence and alert organisations to when cybercriminals are targeting them. If they match the profile of the Initial Access Broker advert, they can launch an investigation to see if their internal technology – which the cybercriminal lists – is compromised.

    Recruiting employees

    Dark web messaging forums are also where cyber criminals look to recruit people from within an organisation to commit malicious activity. Often, when posting, they will relinquish information about the target organisation and type of data or access they are looking for.

    This information can be used to identify insider threat activity within your own organisation and keeping track of all aliases associated with a specific poster can also help determine their capabilities and any potential risk.

    Infrastructure reconnaissance

    Infrastructure reconnaissance is when attackers gather information on a potential victim organisation – for instance, on the network topology, operating systems and applications, and user accounts. It is their way of trying to pinpoint a potential weak spot and way in.

    The discussion of this reconnaissance is another dark web activity that, if spotted at an early stage, can help security teams stop a breach before it happens. Organisations can take the data shared by cybercriminals in the planning stage, and use it to their advantage: for example, to patch systems that have been called out as vulnerabilities.

    Supply chains

    It is all well and good having a robust cyber security policy in-house. But if your suppliers and partners have not invested the same time and money – and are identified on the dark web because of these vulnerabilities – it leaves you open to attack. 62% of system intrusions in 2022 involved the supply chain. And, recent research shows that only 28% of CISOs in the finance industry currently collecting dark web data are using it to monitor for their suppliers being targeted on the dark web.

    This lack of visibility can leave organisation exposed, especially given the complex supply chain ecosystem within the financial sector. Monitoring when details of key suppliers appear on the dark web can identity when a supplier (and, as a result, you) are under threat. This allows to inform the supplier to take action and, ultimately, close off a potential avenue for attack in your supply chain.

    Leveraging dark web intelligence

    Given the type of activity taking place there, incorporating dark web threat intelligence into threat modelling allows businesses to be better protected and crack down on cyber threats when they’re still in their preliminary stages. Greater insights into dark web activity can quantify potential threats and determine where to allocate time, money, and attention.

    Threat models leveraging dark web insights can help financial sector organisations:

    • Identify assets that could be targeted.
    • Analyse weaknesses and countermeasures against threat actors.
    • Understand trigger events that may lead to an attack.
    • Create a comprehensive view of their threat landscape.

    Turning the unknown into the known

    The dark web has become the go-to place for cyber criminals and malicious insiders to lay the groundwork for cyber attacks against organisations in the financial industry.

    But it can be turned from a challenge into an opportunity. Organisations can harness its power to stay one step ahead. Monitoring dark web forums, marketplaces and sites can shine a light on Initial Access Brokers, cybercriminals targeting employees, and infrastructure reconnaissance to help organisations take a proactive approach to securing their assets and data.

    The financial sector has long pursued top-class cyber security measures but to ensure defences are capable of withstanding the evolving threat landscape, organisations must remain vigilant and innovate.

    Related Posts
    Global shares hover near record highs; gold, silver scale new highs
    Global shares hover near record highs; gold, silver scale new highs
    FTSE 100 ticks lower in shortened Christmas Eve session
    FTSE 100 ticks lower in shortened Christmas Eve session
    Analysis - Chinese tariffs on EU dairy to help 'bleeding' domestic industry, send message abroad
    Analysis - Chinese tariffs on EU dairy to help 'bleeding' domestic industry, send message abroad
    Sterling steady near multi-month highs, BoE caution still top of mind
    Sterling steady near multi-month highs, BoE caution still top of mind
    Russian attacks on Ukrainian ports cause drop in food exports
    Russian attacks on Ukrainian ports cause drop in food exports
    French President Macron slams U.S. visa ban on Thierry Breton and others
    French President Macron slams U.S. visa ban on Thierry Breton and others
    EU says it strongly condemns U.S. visa ban on European individuals
    EU says it strongly condemns U.S. visa ban on European individuals
    Zelenskiy seeks meeting with Trump to hammer out issue of territory
    Zelenskiy seeks meeting with Trump to hammer out issue of territory
    Italy watchdog orders Meta to halt WhatsApp terms barring rival AI chatbots
    Italy watchdog orders Meta to halt WhatsApp terms barring rival AI chatbots
    Russia plans a nuclear power plant on the moon within a decade
    Russia plans a nuclear power plant on the moon within a decade
    EU, France, Germany slam US visa bans as 'censorship' row deepens
    EU, France, Germany slam US visa bans as 'censorship' row deepens
    Libya army chief of staff killed in jet crash near Ankara after fault reported, Turkish official says
    Libya army chief of staff killed in jet crash near Ankara after fault reported, Turkish official says

    Why waste money on news and opinions when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    More from Finance

    Explore more articles in the Finance category

    BP to sell 65% stake in Castrol to Stonepeak for $6 billion

    BP to sell 65% stake in Castrol to Stonepeak for $6 billion

    Gold, silver and platinum extend record streak  

    Gold, silver and platinum extend record streak  

    Dollar set for worst year since 2017, yen still in focus 

    Dollar set for worst year since 2017, yen still in focus 

    Oil rises for sixth session on US data, geopolitical tension

    Oil rises for sixth session on US data, geopolitical tension

    Australia cancels British man's visa after charges of displaying Nazi symbol

    Australia cancels British man's visa after charges of displaying Nazi symbol

    Lilly, Novo lock horns in India's obesity drug race

    Lilly, Novo lock horns in India's obesity drug race

    US targets former EU commissioner, activists with visa bans over alleged censorship

    US targets former EU commissioner, activists with visa bans over alleged censorship

    London’s FTSE 100 edges higher as miners rally on record copper prices

    London’s FTSE 100 edges higher as miners rally on record copper prices

    Equities rise after strong US data, yen firms on currency warnings

    Equities rise after strong US data, yen firms on currency warnings

    UK police say comedian Russell Brand charged with two more sex offences

    UK police say comedian Russell Brand charged with two more sex offences

    RTX unit Raytheon lands $1.7 billion deal to supply Patriot systems to Spain

    RTX unit Raytheon lands $1.7 billion deal to supply Patriot systems to Spain

    CSG will supply trucks to Slovak army under framework deal worth up to $1.2 billion

    CSG will supply trucks to Slovak army under framework deal worth up to $1.2 billion

    View All Finance Posts
    Previous Finance PostHow the LEI Can Help Financial Institutions ‘Address’ a Growing Challenge in ISO 20022
    Next Finance PostLehman 15 years on: margin rules have reduced risk, but increased complexity