Recent Financial Services Cyber Attacks

Phishing, vishing, and social engineering attacks on banks, insurers, fintechs, and payment providers, and the customers they serve. Each entry is broken down with an original video explainer, key findings, and the red flags your team should watch for. How we produce these.

Revolut Smishing Uses Fake Identity Check

Revolut Smishing Uses Fake Identity Check

Following a Revolut data breach, scammers sent text messages that appeared to come from the same message thread as legitimate Revolut texts. The texts pushed victims to click a link for a fake identity “liveness check,” request camera access, and then capture passwords, information that could be…

September 21, 2026
Fake Job Interview Repo Tricks DevOps Into Malware

Fake Job Interview Repo Tricks DevOps Into Malware

North Korea–linked "Jade Sleet" used job interview-style coding projects to trick developers into running malicious infrastructure code. The lure involved GitHub repositories that contained a weaponized Terraform file, leading to downloads from attacker-controlled domains and installation of macOS…

September 21, 2026
Revolut Fooled by Govt Impersonation Email

Revolut Fooled by Govt Impersonation Email

A person posing as a government agency used an email address on that agency’s real domain to obtain sensitive customer records from Revolut. The same weekly roundup also describes a fake antivirus renewal web page impersonating Avast, telling victims their subscription renewed for €129.99 and…

September 20, 2026
Brevo Breach Spread Malware via ‘Prove You’re Human’

Brevo Breach Spread Malware via ‘Prove You’re Human’

Attackers breached Brevo and used a stolen Cloudflare API key to inject malicious code into Brevo-hosted scripts that thousands of customer websites load. Visitors saw a fake “prove you’re human” prompt meant to trick them into running a command, and logged-in WordPress admins risked having a…

September 18, 2026
Trusted Channels Hijacked for Phishing and Malware

Trusted Channels Hijacked for Phishing and Malware

The article describes multiple real-world social engineering operations this week, including phishing sent from a legitimate Trezor newsletter channel and malware pushed through a verified HBO Max Reddit ad account. It also highlights a large-scale network of fake online stores impersonating real…

September 18, 2026
RatHat Smishing Lure Pushes Android Sideloading

RatHat Smishing Lure Pushes Android Sideloading

Researchers described an Android Trojan (“RatHat”) that starts with scam texts or malicious ads and tricks people into installing a fake app from a bogus download page. After installation, it pressures victims to grant Accessibility permissions using fake excuses or incentives, then uses those…

September 18, 2026
Malicious Calendar Invites Surge With Malware Links

Malicious Calendar Invites Surge With Malware Links

Attackers are sending fake calendar meeting invites that can be automatically added to a victim’s calendar, even if the email is blocked. A documented example used a Google Calendar invite with a financial “invoice credit” lure to drive victims to a hosted webpage and download a malicious…

September 18, 2026
Revolut Tricked by Spoofed Government Email

Revolut Tricked by Spoofed Government Email

Revolut confirmed a customer data breach after attackers used a compromised government agency domain to submit fake “official” requests for customer information. Revolut provided sensitive details (including IDs like passports and driver’s licenses) based on those email requests, raising questions…

September 18, 2026
Abandoned CDN Domain Hijack Risks Web Users

Abandoned CDN Domain Hijack Risks Web Users

A previously abandoned CDN domain was re-registered, and thousands of websites still reference hostnames under it, meaning a new, unknown owner can control what those sites load without any change on the sites themselves. The article also describes a real, recent “ClickFix” social-engineering…

September 18, 2026
AI Voice Agents Fuel New Phone Fraud Wave

AI Voice Agents Fuel New Phone Fraud Wave

The article describes real-world cases where AI agents interacted with banks and contact centers, including an investment agent that nearly wired out a customer’s funds after encountering a scam offer. It also highlights AI voice agents calling enterprises at high volume, sometimes lying about…

September 18, 2026
RatHat Lures Users to Install Fake Android Apps

RatHat Lures Users to Install Fake Android Apps

Researchers describe RatHat, an Android trojan linked to China-based operators, that spreads via smishing, malvertising, and fake app stores to trick people into installing a malicious APK. Once installed, it pushes for Accessibility permissions and then uses that access to take deep control of the…

September 18, 2026
Revolut Tricked by Stolen Govt Email

Revolut Tricked by Stolen Govt Email

Attackers used a compromised government email account to pose as authorities and request customer records from Revolut. Employees believed the requests were legitimate and voluntarily sent sensitive customer information, exposing data for nearly 700 people. The incident highlights how “trusted”…

September 18, 2026
Revolut Users Hit With SMS Phish After Breach

Revolut Users Hit With SMS Phish After Breach

Days after Revolut disclosed that customer records were shared with an unauthorized party, some customers reported receiving phishing texts that appeared in the same SMS thread as real Revolut messages. The link led to a fake site that asked for camera access to mimic Revolut’s identity “liveness”…

September 17, 2026
Revolut Tricked by Fake Govt Requests for Months

Revolut Tricked by Fake Govt Requests for Months

Attackers allegedly stole Revolut customer data by sending fraudulent “government” legal requests for roughly five months. The requests appeared legitimate because they came from a compromised government employee email account, leading Revolut to comply and disclose sensitive personal and financial…

September 17, 2026
Fake AI Trading Bot Steals Crypto Wallet Passwords

Fake AI Trading Bot Steals Crypto Wallet Passwords

Researchers observed real campaigns where a fake “AI crypto trading agent” website tricked victims into downloading malware that silently replaces browser wallet extensions and steals the wallet password when it’s typed. The same reporting also describes invoice emails using QR codes to push…

September 17, 2026
Fake Helpdesk Passkey Setup Steals Cloud Access

Fake Helpdesk Passkey Setup Steals Cloud Access

The article describes real intrusions where attackers impersonate a company helpdesk and lure employees into "passkey, MFA, or SSO setup" steps. Victims are sent links via text (often to personal phones), leading to account takeover through adversary-in-the-middle phishing or device-code…

September 16, 2026
Fake Police Emails Tricked Revolut Into Sharing Data

Fake Police Emails Tricked Revolut Into Sharing Data

Threat actors allegedly used a compromised Italian government PEC email account to impersonate law enforcement and send fraudulent information requests to Revolut. Revolut says its systems were not breached, but it received requests that appeared to come from a legitimate government domain and…

September 16, 2026
Ukraine Targets Fraud Call Centers With New Law

Ukraine Targets Fraud Call Centers With New Law

Ukraine’s parliament approved tougher penalties targeting fraudulent call centers that manipulate victims into sending money, making fake investments, or giving access to bank accounts. The move follows an alleged corruption scandal where officials were accused of taking bribes to shield scam…

September 16, 2026
AI Assistant Tricked Into Leaking GitHub Repos

AI Assistant Tricked Into Leaking GitHub Repos

A Mandiant assessment showed an internal AI assistant could be socially engineered into abusing its legitimate access. Testers convinced the agent it was part of an authorized security test and gave it a GitHub token, leading it to clone sensitive internal repositories and push them to an external…

September 16, 2026
Black Axe Romance Scam Scripts Exposed

Black Axe Romance Scam Scripts Exposed

US prosecutors say alleged Black Axe leaders ran long-running romance scams that used social media and dating sites to build trust with victims, then demanded money using a consistent “working in South Africa” story. When victims hesitated, the group allegedly threatened to leak sensitive photos to…

September 15, 2026
Try Mirage

Mirage simulates attacks like these against your own team, live and safely, so you can measure how your people actually respond.

Get a demo