Index live· 1,284 files · 148 editions
ForensicPost

Search the index

68 results
Try
Results for “Finance”Newest first
26-0807
File

Bank of Baroda Confirms Leak After Employee Email Compromise, With 700GB Claimed

A dispute about volume is a dispute about the wrong axis. Ask instead which fields can be reissued.

UnattributedCompromised employee mailboxFinanceVerification
Sev 4TargetBank of BarodaActorUnattributedIndia
26-0722
File

Three Quarters of the Year’s Stolen Crypto, One Government

76% of the year’s crypto theft value attributed to one state. On a public ledger, attribution is tractable in a way network telemetry never is.

DPRK-linkedMultipleFinanceFinance
Sev 5TargetCryptocurrency platformsActorDPRK-linked
26-0713
File

The Support Ticket Is the Breach

A compromise at a third-party ticketing platform used by EY’s IT staff. Ticket attachments hold whatever was needed to reproduce the problem.

UnattributedThird-party platformFinanceThird party
Sev 3TargetErnst & YoungActorUnattributed
26-0712
File

Deepfakes Reported in 40% of Business Email Compromise Incidents

BEC was already the costliest category using plain text and patience. Synthesis removed the last verification step people actually used.

MultipleBEC with synthetic mediaFinanceFraud
Sev 4TargetCorporate payment processesActorMultiple
26-0614
File

The Laundering Service Is the Part That Has to Touch a Bank

Two arrests at a laundering service. Intrusion capability is replaceable; banking relationships that move criminal proceeds are not.

MultipleEnforcement actionFinanceEnforcement
Sev 3TargetAudiA6 laundering serviceActorMultiple
26-0603
File

Ransom Payments Fell 44%, and Claims Rose 40%

Payments down 44%, claims up 40%. An ecosystem earning less per victim has an obvious incentive to increase volume.

MultipleRansomwareFinanceInsurance
Sev 3TargetCyber insurance marketActorMultiple
26-0519
File

M&A and Litigation Documents Identified as a Distinct Extortion Target Class

Deal documents are worth a fortune for days and nothing after. There is no ransom note, because publication destroys the value.

MultipleTargeted accessFinanceLegal
Sev 4TargetLegal document estatesActorMultiple
26-0511
File

A Quarter of the Claims, Half the Money

Ransomware is 28% of claims and 52% of the money. BEC is the most frequent and among the cheapest. They need separate budgets.

MultipleVariousFinanceInsurance
Sev 3TargetCyber insurance claimantsActorMultiple
26-0510
File

FBI Recorded 1,008,597 Fraud Complaints and $20.9 Billion in Losses for 2025

AI-referencing complaints are ~4% of reported losses. The other 96% is the story — and the AI share is undercounted by construction.

MultipleVariousFinanceFraud
Sev 3TargetReported fraud, USActorMultipleUSA
26-0422
File

Attorney-client Privilege Offers No Protection Against an Intruder Copying Files

Privilege stops a court compelling disclosure. It says nothing about an intruder copying the file, and the gap is filled by IT controls.

MultipleVariousFinanceLegal
Sev 4TargetPrivileged communicationsActorMultiple
26-0421
File

Voice Cloning Now Standard in Executive Impersonation Fraud

The unwritten backstop was that someone would ring the executive and recognise them. The seniority that makes impersonation work is what makes the voice public.

MultipleVoice cloningFinanceFraud
Sev 4TargetCorporate finance functionsActorMultiple
26-0417
File

Two Hundred and Ninety-Two Million, and No Perimeter to Breach

A reported $292 million protocol exploit. No credential, no dwell time, no log — and no ability to disconnect while you investigate.

DPRK-linkedProtocol exploitFinanceFinance
Sev 4TargetKelp DAOActorDPRK-linked
26-0416
File

Control Failures Are the Most Common Ground for Cyber Insurance Disputes

The exempted system is the one attackers find and the one that voids the policy. The exemption register is now a financial document.

UnattributedCoverage disputeFinanceInsurance
Sev 3TargetInsured organisationsActorUnattributed
26-0403
File

US Public Companies Must Disclose Material Cyber Incidents Within Four Days

Four business days from a materiality determination the company itself makes. The clock and the investigation run on incompatible timescales.

UnattributedDisclosure regimeFinanceMethod
Sev 3TargetUS public companiesActorUnattributedUSA
26-0313
File

The Client Portal Is Where the Documents and the Weak Authentication Meet

Strong authentication on the firm’s staff, optional for the client’s. The obstacle is that the person who would insist is also selling to them.

MultipleWeak authenticationFinanceLegal
Sev 4TargetLaw firm client portalsActorMultiple
26-0309
File

Two in Five Law Firms Were Breached, and Most Exposed Client Data

39% breached, most exposing client data. Firms hold the material clients assembled precisely because it was too sensitive to handle alone.

MultipleVariousFinanceLegal
Sev 4TargetLaw firmsActorMultiple
26-0303
File

Financial Services AI Agent Disclosed Internal Pricing for Three Weeks

No anomalous login, no unusual volume, no malformed input — just a grammatical question, for three weeks.

UnattributedPrompt injectionFinanceAI agents
Sev 3TargetFinancial services AI agentActorUnattributed
26-0227
File

youX Breach Affected 444,500 Borrowers and 229,200 Driver's Licence Records

229,200 driver’s licences at a lending platform, plus data for 797 broker firms. The licence is the KYC document other institutions trust.

UnattributedUnder reviewFinanceIdentity
Sev 4TargetyouXActorUnattributed
26-0224
File

Employee Compromise at Figure Technology Solutions Affected 967,000 Accounts

967,000 accounts at a lending platform. Underwriting assembles identity, income and obligations — including for people who were declined.

ShinyHuntersEmployee social engineeringFinanceIdentity
Sev 4TargetFigure Technology SolutionsActorShinyHunters
26-0223
File

Premiums Fell for the First Time, and the Bill Is Going Up

Aggregate premium fell while individual quotes rose 15–20%. The correction lands hardest on those least able to fund controls.

UnattributedMarket pricingFinanceInsurance
Sev 3TargetCyber insurance marketActorUnattributed
26-0219
File

Three Billion Identity Records, and No Attacker Required

Around three billion records in an unsecured database, including a billion KYC entries. No intrusion, no actor, and no way to say who read it.

ExposureUnsecured databaseFinanceExposure
Sev 4TargetIDMeritActorExposure
26-0208
File

Coinbase Support Contractor Improperly Accessed Data for 30 Customers

Authentication, authorisation and monitoring all worked. The difference between a legitimate lookup and this one is intent, and intent is not a field.

Insider — contractorImproper accessFinanceInsider
Sev 2TargetCoinbaseActorInsider — contractor
26-0203
File

Unauthorised Activity Hit PayPal Working Capital Accounts Over Six Months

A six-month window on a small-business lending product, in one of the most heavily monitored environments in commercial technology.

UnattributedAccount compromiseFinanceFinance
Sev 3TargetPayPal Working CapitalActorUnattributed
26-0127
File

Sixty Institutions, One Technology Provider

Sixty institutions down through one provider. Pooling technology is what lets small member-owned banks exist, and it concentrates the risk.

UnattributedRansomwareFinanceThird party
Sev 4TargetCredit union technology providerActorUnattributed
26-0124
File

Digital-only Banking Removed the Fallback That Made Outages Survivable

Every sector that survived an outage this year did it on a manual fallback inherited from an earlier era. Digital-only removed it on purpose.

UnattributedContinuity gapFinanceFinance
Sev 3TargetDigital-only financial servicesActorUnattributed
26-0112
File

Team 313 Outage Left 20,000 Chime Users Unable to Access Accounts

20,000 people unable to reach their money, with no branch to visit and frequently no second account.

Team 313Service disruptionFinanceFinance
Sev 3TargetChimeActorTeam 313
26-0102
File

Commercial Counterparties Increasingly Litigate Supplier Security Failures Directly

A commercial claimant holds the contract, can quantify the loss and can fund discovery — which is where security practice actually gets examined.

UnattributedLitigationFinanceThird party
Sev 3TargetSupplier security obligationsActorUnattributed
25-1210
File

Crypto Losses Reached $3.4 Billion Across More Than 300 Incidents in 2025

The signature schemes held. The hash functions held. The losses came from signing workflows and outsourced support.

MultipleVariousFinanceAnalysis
Sev 4TargetDigital asset platformsActorMultiple
25-1129
File

Lazarus Group Took $30.4 Million From Upbit, South Korean Authorities Say

Espionage-grade capability applied to straightforward theft, against a target with no reversal and no deterrent.

Lazarus GroupFinanceGeopolitics
Sev 4TargetUpbitActorLazarus GroupSouth Korea
25-1126b
File

A Regulator Told the Market

The mechanism works. Its scope is defined by the wrong boundary — these incidents are not sector-shaped.

RegulatorFinanceRegulation
Sev 2TargetSecurities firmsActorRegulator
25-1124b
File

Accounting Records and Legal Agreements Trigger Nothing

Notification law exists to protect people who cannot protect themselves, and JPMorgan Chase is not that.

UnattributedFinanceAccountability
Sev 3TargetClient institutionsActorUnattributed
25-1112b
File

SitusAMC Attack Exposed Client Records Including JPMorgan Agreements

Vendor assessment at its most rigorous did not prevent this. The instrument measures whether a framework exists, not whether it operates.

UnattributedFinanceThird party
Sev 4TargetSitusAMCActorUnattributed
25-1111b
File

Qilin Branded South Korean Asset Manager Victims as Korean Leaks

An operator optimising for revenue keeps negotiations separate. Branding them together does the reverse.

QilinMSP compromiseFinanceExtortion
Sev 4TargetSouth Korean asset managersActorQilinSouth Korea
25-1110b
File

One Provider, Twenty Asset Managers

You can discover who your competitors bank with more readily than who runs their servers.

QilinMSP compromiseFinanceThird party
Sev 5TargetSouth Korean asset managersActorQilinSouth Korea
25-1105
File

Prosper Marketplace Breach Affected More Than 10 Million Customers

A credit application is the densest identity document an ordinary person produces. Most of the people in the database were declined.

UnattributedFinanceFinance
Sev 4TargetProsper MarketplaceActorUnattributed
25-1027
File

Discovered the Same Day, Told the Clients Ten Weeks Later

Nobody broke the rules. The rules have no term for the gap between a vendor knowing and a controller knowing, so two compliant clocks can sum to anything.

AkiraUnpatched edge deviceFinanceAccountability
Sev 3TargetMarquis client institutionsActorAkira
25-1019
File

Nigeria Reported 23.2 Million Attempted Cyberattacks in 2025

Its precision is an artefact of counting, not evidence of accuracy. The buried sentence is the reliable part.

MultipleVariousFinanceInternational
Sev 3TargetNigerian organisationsActorMultipleNigeria
25-1013b
File

A Bank Said Its Clients’ Data May Have Been Exposed by Somebody Else

A client reads that their bank has had a breach. The bank’s systems were not compromised. Both are true.

UnattributedThird partyFinanceFinance
Sev 3TargetGoldman Sachs clientsActorUnattributed
25-1012
File

A University’s Finance System, 1.3 Terabytes, and a Leak-Site Listing

A university ERP holds staff, students, alumni donors and grant administration. One flaw reached all of it.

Cl0pCVE-2025-61882EducationEducation
Sev 4TargetHarvard UniversityActorCl0p
25-0814
File

Marquis Software Compromise Reached Customers of at Least 74 Banks

Seventy-four independent due-diligence processes, all compliant, none of which established whether the vendor patched its own front door.

AkiraUnpatched edge deviceFinanceFinance
Sev 4TargetMarquis SoftwareActorAkira
25-0728
File

A Seventy-Five Million Dollar Payment, and What It Tells the Market

Payments become known; refusals do not. The observable signal is biased towards paying, and it is the observable signal that sets expectations.

MultipleRansomwareFinanceAnalysis
Sev 4TargetFinancial sectorActorMultiple
25-0727
File

TransUnion Reports 4.4 Million Affected After Salesforce Database Reached

The bureau’s customers are lenders. The people in the database are its product.

ShinyHuntersThird-party platformFinanceFinance
Sev 4TargetTransUnionActorShinyHunters
25-0713
File

Gulf Financial Institutions Reported Ransomware Disruptions Through 2025

The sector best measured in one jurisdiction is thinly recorded in another — a statement about supervisory publication, not about the banks.

MultipleRansomwareFinanceFinance
Sev 3TargetGulf financial institutionsActorMultiple
25-0617
File

Nobitex Breach Reported as Connected to Regional Conflict, Not Profit

A financially motivated attacker must launder, must avoid attention, must be able to convert. An attacker who wants to cause damage has none of those constraints.

UnattributedFinanceGeopolitics
Sev 3TargetNobitexActorUnattributed
25-0616
File

The Most Expensive Sector to Be Breached In

A retailer and a bank suffering identical intrusions produce very different invoices, and the difference is regulation rather than damage.

MultipleVariousFinanceAnalysis
Sev 3TargetFinancial sectorActorMultiple
25-0613
File

Chain IQ Breach Exposed 130,000 Employee Records Across 19 Clients

A function nobody considers sensitive — buying things — accumulated the staff directories of nineteen client organisations.

UnattributedFinanceThird party
Sev 3TargetChain IQ Group AGActorUnattributed
25-0530
File

Coinbase Put Reimbursement at $180 Million to $400 Million for 69,500 People

Between $2,600 and $5,700 per person, against a sector norm of twenty dollars of credit monitoring. The difference is not generosity.

UnattributedInsider recruitmentFinanceAccountability
Sev 3TargetCoinbase customersActorUnattributed
25-0523
File

Attackers Drained Cetus Protocol Liquidity Using Spoof Tokens

No credential stolen, no server compromised, no employee deceived. The contract executed exactly as published — the specification and the intent diverged.

UnattributedContract logic manipulationFinanceProtocol
Sev 3TargetCetus ProtocolActorUnattributed
25-0514
File

Coinbase Says Attackers Bribed Overseas Support Agents for Customer Data

No vulnerability. Authorised employees performing lookups they were entitled to perform. The security model was not defeated — it was rented.

UnattributedInsider recruitmentFinanceInsider
Sev 4TargetCoinbaseActorUnattributed
25-0320
File

Account Takeover Quadrupled at Mexican Banks

The closest thing in this database to a measured downstream consequence — and it still is not the proof.

MultipleAccount takeoverFinanceInternational
Sev 3TargetMexican banksActorMultipleMexico
25-0221
File

Bybit Lost $1.447 Billion in the Largest Cryptocurrency Theft Recorded

$1.447 billion in one theft — around 7% of a full year of all reported US cyber-fraud losses. A state revenue event, not a crime statistic.

TraderTraitor / LazarusFinanceFinance
Sev 5TargetBybitActorTraderTraitor / LazarusUSA
25-0214
File

The File-Transfer Product Is the Bank’s Weakest Wall

Internet-facing, authentication-heavy, holding the files too sensitive for email. Managed file transfer keeps producing portfolios of victims.

UnattributedZero-day exploitationFinanceFinance
Sev 3TargetWestern Alliance BankActorUnattributed
25-0117
File

The Rule That Made a Bank Answerable for Its Suppliers

The first instrument in this corpus that reaches the organisation the customer has never heard of — and it regulates availability, not just data.

RegulatorFinanceRegulation
Sev 2TargetEU financial entitiesActorRegulator
24-1120
File

Finastra Breach of a Support File Platform Reached 888,627 People

Support systems accumulate whatever customers attach to tickets. Nobody plans for that.

UnattributedFinancial servicesFinance
Sev 4TargetFinastraActorUnattributedUnited Kingdom
24-0702
File

Wise and Affirm Customers Exposed by a Breach at a Firm They Never Chose

The partnership had ended the year before the intrusion. The records had not.

LockBitFinanceConcentration
Sev 4TargetFintech customersActorLockBitUSA
24-0626
File

Seven Point Six Million, From a Bank Most of Them Had Not Heard Of

The usual version is a supplier the affected person has never heard of. Here it is a bank they were arguably banking with without knowing.

LockBitMalicious linkFinanceFinance
Sev 5TargetEvolve Bank & TrustActorLockBitUSA
24-0623
File

LockBit Claimed 33TB From the Federal Reserve; the Data Was Evolve Bank's

It had the data, it could read the data, and it still named the wrong institution.

LockBitFinanceVerification
Sev 4TargetEvolve Bank & TrustActorLockBitUSA
24-0514
File

Santander Customer Data Listed for Sale After Third-Party Access

A customer can change bank. An employee handed the details over as a condition of the job.

UnattributedThird-party database accessFinancial servicesFinance
Sev 4TargetSantanderActorUnattributedSpain
23-1119
File

Fidelity National Financial Blocked Its Own Systems and House Sales Stopped

Containment converts an unbounded loss into a bounded one, and moves it onto whoever needed the service that week.

UnattributedCredential compromiseFinanceAvailability
Sev 4TargetFidelity National FinancialActorUnattributedUSA
23-1108
File

ICBC’s US Unit Could Not Clear Treasury Trades After LockBit Attack

Settlement data proposed by USB stick, between two of the largest financial institutions on earth.

LockBitRansomwareFinanceFinance
Sev 5TargetICBC Financial ServicesActorLockBitUSA
23-1031
File

Mr Cooper Breach Exposed 14.7 Million Current and Former Customers

Someone who paid off their mortgage in 2016 had no account, no login, and full exposure.

UnattributedFinancial servicesFinance
Sev 5TargetMr CooperActorUnattributedUSA
23-0316
File

Latitude Financial Breach Grew From 328,000 Records to 14 Million

A reader comparing incidents by their first published figure is comparing almost nothing.

UnattributedStolen credentialsFinanceIdentity
Sev 5TargetLatitude FinancialActorUnattributedAustralia
22-0801
File

Nomad Bridge Lost $190 Million as Hundreds of Addresses Copied One Transaction

The working exploit was published by its own execution, in a block anyone could read.

UnattributedFaulty upgrade — proof validationFinancial servicesFinance
Sev 4TargetNomad bridgeActorUnattributedUSA
22-0617
File

Flagstar Bank Told 1,547,169 Customers Six Months After a Two-Day Intrusion

The count is exact to the person. The explanation is a two-day window and nothing else.

UnattributedFinancial servicesFinance
Sev 4TargetFlagstar BankActorUnattributedUSA
22-0417
File

Beanstalk Farms Lost $182 Million to a Flash-Loan Governance Takeover

A voter who wrecks the protocol wrecks their own holding — unless the holding lasts one transaction.

UnattributedFlash loan governance captureFinancial servicesFinance
Sev 4TargetBeanstalk FarmsActorUnattributedUSA
22-0323
File

Ronin Bridge Lost $620 Million and Nobody Noticed for Six Days

A quorum counts signatures. Security depends on the independence behind them, and code enforces only one.

Lazarus GroupValidator key compromiseFinancial servicesFinance
Sev 5TargetRonin bridgeActorLazarus GroupUSA
22-0202
File

Wormhole Bridge Lost $320 Million, Covered by Parent Company Jump Crypto

No insurance, no reserve fund, no protocol mechanism. The guarantee was a company deciding to pay.

UnattributedSignature verification flawFinancial servicesFinance
Sev 4TargetWormhole bridgeActorUnattributedUSA
22-0117
File

Crypto.com Says $34 Million Left 483 Accounts With the Second Factor Never Entered

A control the server can be persuaded to skip is not a second factor. It is a convention.

UnattributedTwo-factor authentication bypassFinancial servicesFinance
Sev 3TargetCrypto.comActorUnattributedSingapore
© 2026 ForensicPost Media · the desk · newsletterGlossaryNo search logging