Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking & Finance Review®

Global Banking & Finance Review® - Subscribe to our newsletter

Company

    GBAF Logo
    • About Us
    • Advertising and Sponsorship
    • Profile & Readership
    • Contact Us
    • Latest News
    • Privacy & Cookies Policies
    • Terms of Use
    • Advertising Terms
    • Issue 81
    • Issue 80
    • Issue 79
    • Issue 78
    • Issue 77
    • Issue 76
    • Issue 75
    • Issue 74
    • Issue 73
    • Issue 72
    • Issue 71
    • Issue 70
    • View All
    • About the Awards
    • Awards Timetable
    • Awards Winners
    • Submit Nominations
    • Testimonials
    • Media Room
    • FAQ
    • Asset Management Awards
    • Brand of the Year Awards
    • Business Awards
    • Cash Management Banking Awards
    • Banking Technology Awards
    • CEO Awards
    • Customer Service Awards
    • CSR Awards
    • Deal of the Year Awards
    • Corporate Governance Awards
    • Corporate Banking Awards
    • Digital Transformation Awards
    • Fintech Awards
    • Education & Training Awards
    • ESG & Sustainability Awards
    • ESG Awards
    • Forex Banking Awards
    • Innovation Awards
    • Insurance & Takaful Awards
    • Investment Banking Awards
    • Investor Relations Awards
    • Leadership Awards
    • Islamic Banking Awards
    • Real Estate Awards
    • Project Finance Awards
    • Process & Product Awards
    • Telecommunication Awards
    • HR & Recruitment Awards
    • Trade Finance Awards
    • The Next 100 Global Awards
    • Wealth Management Awards
    • Travel Awards
    • Years of Excellence Awards
    • Publishing Principles
    • Ownership & Funding
    • Corrections Policy
    • Editorial Code of Ethics
    • Diversity & Inclusion Policy
    • Fact Checking Policy
    Original content: Global Banking and Finance Review - https://www.globalbankingandfinance.com

    A global financial intelligence and recognition platform delivering authoritative insights, data-driven analysis, and institutional benchmarking across Banking, Capital Markets, Investment, Technology, and Financial Infrastructure.

    Copyright © 2010-2026 - All Rights Reserved. | Sitemap | Tags

    Editorial & Advertiser disclosure

    Global Banking & Finance Review® is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    1. Home
    2. >Finance
    3. >Why should the financial sector care about the dark web?
    Finance

    Why Should the Financial Sector Care About the Dark Web?

    Published by Jessica Weisman-Pitts

    Posted on September 18, 2023

    6 min read

    Last updated: January 31, 2026

    Add as preferred source on Google
    An illustration depicting the dark web's influence on cyber threats in finance, highlighting the need for vigilance against data breaches and cybercrime.
    Visual representation of dark web activity impacting the financial sector - Global Banking & Finance Review
    Why waste money on news and opinion when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    Tags:cybersecurityfinancial sectordata breachdark webcyber threats

    Why should the financial sector care about the dark web?

    Dr Gareth Owenson, Co-Founder and CTO, Searchlight Cyber

    The financial sector has a deserved reputation for taking cyber security seriously, but that hasn’t stopped cyber criminals keeping the industry in their cross hairs. In fact, with highly sensitive data and huge sums of money as the potential reward – the average cost of a data breach in the financial sector is $5.9 million – threat actors are constantly evolving their methods of attack. With so much at stake, it is vital organisations equip themselves with the intelligence and capability to defend themselves against impending attacks.

    Many of these cyberattacks originate on the dark web – this secretive corner of the internet where company data is sought and sold to the highest bidder. This is where the foundations are laid by criminals to create the next generation of cyberattacks. Targets are named, malware is bought and sold, and weak spots to attack are identified.

    Shining a light on the dark web

    To combat cybercriminals operating on the dark web, it is important to understand how it works. The dark web cannot be accessed by conventional browsers and does not show up in typical search engine searches. The dark web requires specialist software to gain access to, and provides a high level of anonymity to users. Combined with the anonymity of cryptocurrency, cybercriminals use the dark web to buy and sell sensitive information, exploits, and cybercriminal tools in the belief they can act with impunity.

    However, it is possible for security teams to monitor activity across the dark web’s ecosystem of forums, marketplaces, and websites. This turns it from a shadowy world of unknowns into a source of intelligence for early warning of imminent cyberattacks and, ultimately, can help organisations to prevent their network being breached.

    So, how are cybercriminals on the dark web targeting the financial sector? And how can knowledge of this activity be used to an organisation’s advantage?

    The rise of the Initial Access Broker

    The majority of dark web activity against financial institutions involves posts from what are called ‘Initial Access Brokers’. These are people who use hacking forums like Exploit, XSS, and BreachForums to sell access to company infrastructure via exploits like remote network access or SQL injections. Other criminals, like ransomware groups, then use this access as the starting point for their attacks. Below is an example of an Initial Access Broker post, and the type of information cybercriminals provide:

    Monitoring for this activity can provide invaluable pre-attack intelligence and alert organisations to when cybercriminals are targeting them. If they match the profile of the Initial Access Broker advert, they can launch an investigation to see if their internal technology – which the cybercriminal lists – is compromised.

    Recruiting employees

    Dark web messaging forums are also where cyber criminals look to recruit people from within an organisation to commit malicious activity. Often, when posting, they will relinquish information about the target organisation and type of data or access they are looking for.

    This information can be used to identify insider threat activity within your own organisation and keeping track of all aliases associated with a specific poster can also help determine their capabilities and any potential risk.

    Infrastructure reconnaissance

    Infrastructure reconnaissance is when attackers gather information on a potential victim organisation – for instance, on the network topology, operating systems and applications, and user accounts. It is their way of trying to pinpoint a potential weak spot and way in.

    The discussion of this reconnaissance is another dark web activity that, if spotted at an early stage, can help security teams stop a breach before it happens. Organisations can take the data shared by cybercriminals in the planning stage, and use it to their advantage: for example, to patch systems that have been called out as vulnerabilities.

    Supply chains

    It is all well and good having a robust cyber security policy in-house. But if your suppliers and partners have not invested the same time and money – and are identified on the dark web because of these vulnerabilities – it leaves you open to attack. 62% of system intrusions in 2022 involved the supply chain. And, recent research shows that only 28% of CISOs in the finance industry currently collecting dark web data are using it to monitor for their suppliers being targeted on the dark web.

    This lack of visibility can leave organisation exposed, especially given the complex supply chain ecosystem within the financial sector. Monitoring when details of key suppliers appear on the dark web can identity when a supplier (and, as a result, you) are under threat. This allows to inform the supplier to take action and, ultimately, close off a potential avenue for attack in your supply chain.

    Leveraging dark web intelligence

    Given the type of activity taking place there, incorporating dark web threat intelligence into threat modelling allows businesses to be better protected and crack down on cyber threats when they’re still in their preliminary stages. Greater insights into dark web activity can quantify potential threats and determine where to allocate time, money, and attention.

    Threat models leveraging dark web insights can help financial sector organisations:

    • Identify assets that could be targeted.
    • Analyse weaknesses and countermeasures against threat actors.
    • Understand trigger events that may lead to an attack.
    • Create a comprehensive view of their threat landscape.

    Turning the unknown into the known

    The dark web has become the go-to place for cyber criminals and malicious insiders to lay the groundwork for cyber attacks against organisations in the financial industry.

    But it can be turned from a challenge into an opportunity. Organisations can harness its power to stay one step ahead. Monitoring dark web forums, marketplaces and sites can shine a light on Initial Access Brokers, cybercriminals targeting employees, and infrastructure reconnaissance to help organisations take a proactive approach to securing their assets and data.

    The financial sector has long pursued top-class cyber security measures but to ensure defences are capable of withstanding the evolving threat landscape, organisations must remain vigilant and innovate.

    Table of Contents

    • Shining a light on the dark web
    • The rise of the Initial Access Broker
    • Recruiting employees

    Frequently Asked Questions about Why should the financial sector care about the dark web?

    1What is the dark web?

    The dark web is a part of the internet that is not indexed by traditional search engines and requires special software to access, providing anonymity to users.

    2What is an Initial Access Broker?

    An Initial Access Broker is a cybercriminal who sells access to compromised networks, often using hacking forums to advertise their services.

    Infrastructure reconnaissance
  • Supply chains
  • Leveraging dark web intelligence
  • Turning the unknown into the known
  • 3What is a data breach?

    A data breach occurs when unauthorized individuals gain access to sensitive data, potentially leading to financial loss and reputational damage for organizations.

    4What is cybersecurity?

    Cybersecurity refers to the practices and technologies used to protect computers, networks, and data from unauthorized access, attacks, or damage.

    5What is infrastructure reconnaissance?

    Infrastructure reconnaissance is the process by which attackers gather information about a target's network and systems to identify vulnerabilities for exploitation.

    More from Finance

    Explore more articles in the Finance category

    Image for Blaze at Russia's Baltic Sea port of Ust-Luga after major Ukrainian drone attack
    Blaze at Russia's Baltic Sea Port of Ust-Luga After Major Ukrainian Drone Attack
    Image for Morning Bid: Deal, or no deal?
    Morning Bid: Deal, or No Deal?
    Image for Labubu maker Pop Mart meets 2025 revenue expectations
    Labubu Maker Pop Mart Meets 2025 Revenue Expectations
    Image for Israel strikes Tehran as Trump says US negotiating to end war
    Israel Strikes Tehran as Trump Says US Negotiating to End War
    Image for South Korea, Germany exposed to rare earths shortage, Australia's Arafura says
    South Korea, Germany Exposed to Rare Earths Shortage, Australia's Arafura Says
    Image for Currency markets drift as traders sceptical of US efforts to end Iran war
    Currency Markets Drift as Traders Sceptical of US Efforts to End Iran War
    Image for Stocks bounce and oil retreats on Mideast ceasefire reports
    Stocks Bounce and Oil Retreats on Mideast Ceasefire Reports
    Image for Equinor CEO says EU unlikely to increase Russian gas imports
    Equinor CEO Says EU Unlikely to Increase Russian Gas Imports
    Image for Openreach taps Google AI to speed fibre rollout, cut emissions
    Openreach Taps Google AI to Speed Fibre Rollout, Cut Emissions
    Image for UK consumer sentiment falls as Iran war rages, KPMG says
    UK Consumer Sentiment Falls as Iran War Rages, Kpmg Says
    Image for US oil prices fall on prospect of Middle East ceasefire easing supply disruption
    US Oil Prices Fall on Prospect of Middle East Ceasefire Easing Supply Disruption
    Image for Lamborghinis stranded in Sri Lanka as war disrupts Asia's used-car trade 
    Lamborghinis Stranded in Sri Lanka as War Disrupts Asia's Used-Car Trade 
    View All Finance Posts
    Previous Finance PostHow the Lei Can Help Financial Institutions ‘Address’ a Growing Challenge in Iso 20022
    Next Finance PostLehman 15 Years On: Margin Rules Have Reduced Risk, but Increased Complexity