Skip to content

💰 Financial Services

Banking, insurance, fintech, payments, asset management · a shareable slice of the daily brief for stakeholders who only care about this industry · RSS feed

Victims L30D5▼ −1
Prior 30D6
Active actor L90DQilin · 5
Active actor L90DThe Gentlemen · 5
Active actor L90DClop · 2

Today — 12 Sep 2026

No industry-tagged items in today's briefing — see recent activity below.

Last 14 days

Oracle's Q1 FY2027 earnings — the specific watched event this desk's AI-infrastructure-concentration signal has tracked since December — landed with a beat-then-fade-then-recover pattern that is itself the story: strong fundamentals, a market still pricing concentration risk in real time.MediumTechnology & SoftwareFinancial ServicesRevenue beat consensus ($19.3B vs. $19.14B expected) and cloud infrastructure revenue grew 121%, yet shares fell 5.4% intraday before reversing to a 4.3% after-hours gain. That volatility, on genuinely strong results, is consistent with a market that has not resolved whether Oracle's $300B-plus OpenAI-linked compute commitments are an asset or a liability — the same tension behind the Ellison-backstopped, Oracle-share-collateralized Warner Bros. Discovery financing this signal has tracked since December. Cybersecurity growth-stage valuations have moved with this sentiment all year; a genuinely clean resolution either direction would be worth a fresh look at portfolio companies with Oracle or OpenAI dependency. Investing.com
No new cybersecurity M&A deals announced in the Sep 9–10 window.MediumCybersecurityFinancial ServicesBack-filling one deal found during research: Socure's Aug 27 acquisition of agentic AI fraud-investigation startup Fravity, announced alongside a $156M strategic growth round (Summit Partners) valuing Socure at $5.2B; Fravity becomes RiskOS_Agents inside Socure's orchestration platform. Filed under its true Aug 27 announcement date, not today's window. Crunchbase News · BankInfoSecurity
Oracle reports Q1 FY2027 earnings after market close today (Sep 10) — the specific watched event BlueSec's AI-infrastructure-concentration signal has been tracking since December.HighTechnology & SoftwareFinancial ServicesConsensus expects $19.1B revenue and 58–64% cloud-revenue growth; options markets are pricing an 11% move. The result matters beyond Oracle's own stock: RPO backlog trajectory and any change in customer-payment language bear directly on the Ellison-backstopped, Oracle-share-collateralized Warner Bros. Discovery financing and on cybersecurity-sector valuation sentiment more broadly, since growth-stage cyber multiples have moved with AI-infrastructure sentiment all year. Results land after this briefing's research cutoff; watch tomorrow's run for the reaction. IG UK
Trezor's shipping-vendor breach expands to 81,000 customers after ShipMonk failed to delete data it had contractually promised to removeHighTechnology & SoftwareFinancial ServicesTrezor disclosed Aug 13 that ~14,000 customers' names, addresses, emails, and phone numbers were exposed via its shipping provider ShipMonk; the count has since grown to 81,000, including 67,000 additional US customers who ordered between November 2019 and August 2021. Trezor says it repeatedly asked ShipMonk to delete the data and received written assurances it had been — assurances that proved false. For hardware-wallet customers specifically, a shipping address tied to a known crypto-asset purchase is a physical-security risk (the "wrench attack" scenario the crypto-security community tracks), not just a phishing one. BleepingComputer · Bloomberg
Trezor's ShipMonk failure and Manchester Airports Group's exposed API keys are the same governance failure wearing different clothes: third-party vendors holding data past their mandate, discovered only after attackers find it first.MediumFinancial ServicesTechnology & SoftwareNeither Trezor nor Manchester Airports Group was breached through their own primary systems — both were exposed through a vendor's mismanagement (a fulfillment partner that didn't delete data as promised; a marketing platform's API credentials left in public-facing JavaScript). As data-protection regulators in the EU and UK increasingly hold data controllers liable for processor failures, portfolio companies should treat vendor data-retention audits as a recurring compliance line item, not a one-time contract clause — the economic exposure now sits with the company whose name is on the breach notification, not the vendor that caused it. BleepingComputer
The IDScan.net breach is structurally different from a credential or PII leak: it places biometric-quality identity documentation for 153 million North Americans in criminal and state-actor hands, and it may have been ongoing for over a year before discovery.CriticalFinancial ServicesGovernment & Public SectorDriver's license images with infrared and UV scans are the exact materials used by government border agencies and financial institutions for identity verification. A state actor possessing this dataset can fabricate credentialed personas at scale, defeating document-based identity assurance in travel, financial services, and physical access systems. The breach's undiscovered duration — the seller claimed ongoing access for "over a year" — means the complete scope is unknown. The FBI investigation is the operative response action; until IDScan.net confirms the breach's full timeline and current access status, its verification pipeline should be treated as untrusted by clients. Krebs on Security · CSO Online
Munich Re's $575M acquisition of At-Bay and AXA XL's full acquisition of S-RM in the same August window signal that global (re)insurance capital is now pricing cybersecurity consultancy and MDR capability as core insurance infrastructure, not add-on advisory.HighFinancial ServicesCybersecurityBoth deals move insurers from passive underwriting into active prevention and response. At-Bay's MDR+insurance hybrid model has been validated at SME scale; Munich Re's HSB integration extends it to their specialty insurance book. AXA XL's S-RM integration (140-country incident response, geopolitical intelligence, integrity due diligence) gives an insurer direct forensics and threat-intelligence capacity. The structural signal for the PE/portfolio-holder: cyber insurance economics are shifting from claims-and-reserve models toward prevention-as-profit-center, and the acquirers are willing to pay platform multiples for consultancy capabilities that compress claim frequency. Munich Re PR · AXA XL PR

Signals touching this industry

Recent victim claims

Newest first, mapped to this industry from the victim database. Most are leak-site claims — verify before acting.

September 2026

Sep 04 Occidental Gunra Ransomware · insurance · Venezuela Venezuelan insurance company (~$157M revenue); Gunra DLS claim Sep 4; no data scope or operational impact disclosed; 🟥 DLS claim only; verify before treating as a breach · Sources: https://ransomware.live/id/T2NjaWRlbnRhbEBndW5yYQ== · https://www.redpacketsecurity.com/gunra-ransomware-victim-occidental/

August 2026

Aug 27 Providence Investments Qilin Ransomware · Financial Services · USA DLS posting Aug 27; no data volume or proof of exfiltration provided; 🟥 unverified claim · Sources: https://www.redpacketsecurity.com/qilin-ransomware-victim-providence-investments/ · https://ransomware.live/group/qilin
Aug 22 BOK Financial ShinyHunters Extortion · Financial Services · USA ShinyHunters DLS claim Aug 22 2026; BOK Financial is a major US financial holding company (NASDAQ: BOKF, ~$50B assets, Tulsa OK); ransom deadline August 24; data scope not disclosed; 🟥 unverified DLS claim · Sources: DEXpose · RansomLook
Aug 21 Apollo Global Management Falcon/Helix/Pink/Redact Ransomware · Financial Services · USA Social engineering attack July 6-10 2026; SSNs, names, DOBs, home addresses compromised from cloud systems; part of wider wave targeting major financial firms including Blackstone, Bridgewater, Bain Capital; disclosed Aug 21 / notified California AG Aug 20 · Sources: https://techcrunch.com/2026/08/21/private-equity-firm-apollo-confirms-data-breach-amid-hacking-wave-targeting-financial-giants/
Aug 19 Senvest Capital The Gentlemen Ransomware · Financial Services · USA TheGentlemen ransomware group DLS claim Aug 19 2026 against international hedge fund and investment firm; data theft threatened; Senvest manages billions in public equities, private markets, and real estate; no public confirmation from Senvest · Sources: https://www.dexpose.io/thegentlemen-ransomware-targets-senvest-capital/
Aug 12 Fiserv Clop Extortion · Financial Technology · US Clop DLS claim August 12, 2026 against Fiserv (global fintech/payments processor); scope unconfirmed; first appeared in tracker August 14. · Sources: https://www.bleepingcomputer.com/news/security/
Aug 06 TechVentures Bank S.A. RansomHouse Ransomware · Financial Services · Unknown RansomHouse DLS listing Aug 6 2026; double extortion · Sources: https://www.ransomware.live/group/ransomhouse
Aug 05 FIS Global Clop Extortion · Financial Technology / Payment Infrastructure · USA Clop listed FIS Global (one of the world's largest financial technology providers, serving thousands of financial institutions) on its DLS on Aug 5, claiming 874GB of exfiltrated data including project files, CAD files, and Windchill-related engineering data — consistent with the PTC Windchill/FlexPLM campaign (CVE-2026-12569) that also hit Shell, GE, Philips, and Fiserv. FIS has not confirmed breach. DLS claim only — unverified. · Sources: https://malware.news/t/clop-ransomware-targets-fis-global/124620
Aug 01 Philippine Savings Bank The Gentlemen Ransomware · Finance · PH TheGentlemen claim on DLS August 1 2026; separate from January 2026 Qilin listing (different group, independent claim). No statement from PSBank; no data published. · Sources: https://www.redpacketsecurity.com/thegentlemen-ransomware-victim-philippine-savings-bank/

July 2026

Jul 31 Kuveyt Turk / Finansbank / Anadolubank / Turkish Airlines (THY) CRPxO Ransomware · Finance / Aviation · Turkey CRPxO ransomware posted wave of Turkish targets July 31: Kuveyt Turk (0.8 GB), Finansbank (2.3 GB), Anadolubank (0.4 GB), Turkish Airlines/THY (4.2 GB); also claimed Johnson & Johnson, Dogan Holding, Anadolu Sigorta, Hyundai · Sources: https://www.ransomware.live/
Jul 24 Bank of Baroda Triple X Ransomware · banking · India Triple X DLS claim July 24; ~1 TB data alleged exfiltrated; estimated attack date May 12, 2026; government-owned second-largest public-sector bank in India. Unverified DLS claim. · Sources: https://www.ransomware.live/
Jul 10 Eurodefi Qilin Ransomware · financial services · EU Qilin DLS claim July 10, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jul 10 Finance Yorkshire CMD Ransomware · financial services · UK UK regional finance provider supporting business growth across Yorkshire and the Humber; CMD DLS claim July 10, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/cmdorganization · Sources: [ransomware.live]
Jul 06 Arabia Falcon Insurance Company The Gentlemen Ransomware · insurance · Oman The Gentlemen DLS claim July 6, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/thegentlemen · Sources: [ransomware.live]
Jul 04 TQ Financial Services Qilin Ransomware · financial services · unknown Qilin DLS claim July 3–4, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jul 04 Silvestri & Associates Insurance Play Ransomware · financial services · insurance/US Play DLS claim July 4, 2026; data leak threatened; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/play-ransomware-targets-silvestri-associates-insurance/ · Sources: [DeXpose]
Jul 04 Deutsche Bank UnSafe Ransomware · banking · financial services/Germany UnSafe DLS claim July 4–6, 2026; Deutsche Bank is Germany's largest bank by assets; UnSafe is a brand-new group with no established track record or prior leak history; data scope, attack vector, and impact entirely unconfirmed; 🟥 EXTREMELY LOW CONFIDENCE — verify through Deutsche Bank communications only before treating as breach · https://www.ransomware.live/ · Sources: [ransomware.live]
Jul 03 CUI Agency The Gentlemen Ransomware · insurance · US US insurance agency based in Utah; The Gentlemen DLS claim July 3, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/ · Sources: [DeXpose]
Jul 01 Roundshield Partners LLP INC Ransom Ransomware · financial services · private equity/UK UK-based private equity firm focused on special situations and credit investments; INC Ransom DLS claim July 1, 2026; 400 GB exfiltrated claimed; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/ · Sources: [DeXpose]
Jul 01 Marquis Software Unknown Ransomware · Financial Services / Software · US Financial software company serving community banks; ransomware attack compromised data for 670,000+ individuals across dozens of bank customers including Artisans Bank and VeraBank; no ransomware group claimed credit publicly (suggesting possible payment); attack date not precisely specified · Sources: https://therecord.media/marquis-bank-vendor-data-breach

June 2026

Jun 30 Aflac Life Insurance Japan Ltd. Scattered Spider Extortion · insurance · Japan unauthorized access June 15–25, 2026; 4.38M customer records exposed (names, addresses, phone numbers; bank account details for ~230K); access vector undisclosed; actor officially unattributed but TTPs consistent with Scattered Spider per industry analysis; Aflac disclosed June 30, 2026; Japan FSA and police notified; no misuse confirmed at disclosure; 🟥 unverified attribution · https://www.securityweek.com/aflac-japan-data-breach-impacts-4-38-million/ · https://www.bleepingcomputer.com/news/security/insurance-giant-aflac-discloses-data-breach-after-subsidiary-hack/ · https://www.japantimes.co.jp/business/2026/06/30/aflac-hack-4-million/ · Sources: [SecurityWeek] · [BleepingComputer] · [Japan Times]
Jun 30 Abans Group BlackNevas Ransomware · financial services · multinational diversified global financial services conglomerate; BlackNevas DLS claim June 30, 2026; estimated attack date June 29, 2026; data scope and impact unconfirmed; 🟥 unverified · https://ransomware.live/id/QWJhbnMgR3JvdXBAYmxhY2tuZXZhcw== · https://www.breachsense.com/breaches/2026/june/ · Sources: [ransomware.live] · [Breachsense]
Jun 28 FCCI Insurance Group REDACT Ransomware · insurance · financial services/US specialty commercial insurance company; REDACT DLS claim June 28, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/redact · https://www.redpacketsecurity.com/redact-ransomware-victim-fcci-insurance-group/ · Sources: [ransomware.live] · [RedPacket Security]
Jun 26 Payload Corporation Payload Ransomware · fintech · payments/US B2B automated payment processing platform serving real estate, legal, insurance, and SaaS sectors (founded 2019; co-founders Ian Halpern and Ryan Rybolt); Payload DLS claim June 26, 2026; data scope unconfirmed; 🟥 unverified — no victim statement · https://www.dexpose.io/payload-ransomware-breach-at-payload-corporation/ · https://www.ransomware.live/group/payload · Sources: [DeXpose] · [ransomware.live]
Jun 26 MagMutual Insurance Company LeakNet Ransomware · insurance · US mutual insurance company focused on healthcare professionals; LeakNet DLS claim June 26, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.breachsense.com/breaches/2026/june/ · Sources: [Breachsense]
Jun 24 Cash Canada Qilin Ransomware · financial services · Canada DLS claim June 24, 2026; data scope and impact unconfirmed · https://www.redpacketsecurity.com/qilin-ransomware-victim-cash-canada/ · https://www.ransomware.live/group/qilin · Sources: [RedPacket Security] · [ransomware.live]
Jun 23 Belpointe Asset Management INC Ransom Ransomware · financial advisory · investment/US https://www.breachsense.com/breaches/ · https://www.ransomware.live/ · Sources: [Breachsense] · [ransomware.live]
Jun 23 GIA Partners LLC The Gentlemen Ransomware · financial services · US https://www.breachsense.com/breaches/ · https://www.ransomware.live/ · Sources: [Breachsense] · [ransomware.live]
Jun 23 AYA Bank Lapsus$ Ransomware · banking · financial services/Myanmar claimed full dump of main banking platform + customer PII; Lapsus$ stated data will be sold on dark markets if ransom not paid; AYA Bank has not issued a public statement; 🟥 unverified — treat as claimed only · https://www.ransomware.live/id/QVlBIEJBTktAbGFwc3VzJA · https://www.redpacketsecurity.com/lapsus-ransomware-victim-aya-bank/ · https://www.hookphish.com/blog/ransomware-group-lapsus-hits-aya-bank/ · Sources: [ransomware.live] · [RedPacket Security] · [HookPhish]
Jun 22 Central Bank of Libya Qilin Ransomware · banking · central bank/Libya ransomware confirmed; SWIFT payment system components targeted; virtual infrastructure and internal systems hit; CBL isolated affected systems June 22; investigations ongoing; no confirmed customer data breach or correspondent bank data exposure · https://www.ransomware.live/id/Q2VudHJhbCBCYW5rIG9mIExpYnlhQHFpbGlu · https://libyaobserver.ly/news/cbl-cyberattack-contained-investigations-ongoing-no-signs-impact-customer-accounts · Sources: [ransomware.live] · [Libya Observer]
Jun 22 NationsBuilders Insurance Services Aur0ra Ransomware · insurance · US US-based specialty insurance risk management firm offering surplus and specialty lines coverage; Aur0ra DLS claim June 22, 2026; over 2.7 million file-tree entries compromised claimed; data scope and victim statement not confirmed · https://www.dexpose.io/aurora-ransomware-attack-on-nationsbuilders-insurance-services/ · Sources: [DeXpose]
Jun 22 Insurity Icarus Ransomware · insurance software · US Salesforce CRM data · https://www.bleepingcomputer.com/news/security/klue-oauth-breach-linked-to-icarus-salesforce-data-theft-attacks/ · Sources: [BleepingComputer]
Jun 22 KTR Real Estate Advisors Anubis Ransomware · financial services · real estate advisory/US client database claimed; attack est. 2026-06-19 · https://www.dexpose.io/anubis-ransomware-group-strikes-ktr-real-estate-advisors/ · https://www.redpacketsecurity.com/anubis-ransomware-victim-ktr-real-estate-advisors/ · Sources: [DeXpose] · [RedPacket Security]
Jun 19 Aflac Scattered Spider Extortion · insurance · US June 2025 social-engineering intrusion; 22.6M people notified (≥13.9M with PHI) · Sources: The Record / HIPAA Journal
Jun 16 River Bank & Trust Unattributed Breach · banking · financial services/US ransomware attack June 16, 2026; SEC 8-K filed June 25, 2026; PII of customers and employees potentially exposed; investigation ongoing; operational impact not disclosed; actor unattributed · https://www.sec.gov/Archives/edgar/data/1641601/000119312526282946/ck0001641601-20260619.htm · https://1819news.com/news/item/river-bank-trust-hit-by-ransomware-attack-from-unauthorized-threat-actor · Sources: [SEC 8-K] · [1819 News]
Jun 12 Lucanet Icarus Ransomware · financial performance management software · Germany Salesforce CRM data accessed via Klue OAuth integration; disclosed June 30, 2026 · https://www.securityweek.com/more-klue-breach-victims-identified-as-hackers-get-hacked/ · Sources: [SecurityWeek]
Jun 10 Liberty Insurance Corporation Krybit Ransomware · insurance · Philippines Sources: ransomware.live DLS
Jun 09 M1xchange WorldLeaks Ransomware · fintech · India Sources: ransomware.live DLS
Jun 09 Philadelphia Insurance Companies Ethics Ransomware · Insurance · USA DLS claim by new group Ethics (debuted Aug 12, 2026); one of 3 simultaneous inaugural postings; estimated attack date Jun 2026; scope unverified · Sources: https://www.dexpose.io/ethics-ransomware-group-targets-philadelphia-insurance-companies/
Jun 01 RRCA Accounts Management Unattributed Breach · collections · US 115,837 individuals affected

May 2026

May 28 VVO Finance Everest Ransomware · financial services · Germany Everest DLS May 28, 2026; data scope undisclosed; no victim statement; 🟥 unverified · https://www.hookphish.com/blog/ransomware-group-everest-hits-vvo-finance/ · https://www.redpacketsecurity.com/everest-ransomware-victim-vvo-finance/ · Sources: [HookPhish] · [RedPacket Security]
May 03 Fiserv Inc. Everest Ransomware · fintech · US powers core banking systems, digital platforms, merchant acquiring, and Clover POS for thousands of financial institutions worldwide; Everest DLS May 3, 2026; no ransom demand stated; Fiserv has not confirmed; 🟥 unverified · https://www.dexpose.io/everest-ransomware-attack-targets-financial-tech-leader-fiserv/ · https://www.redpacketsecurity.com/everest-ransomware-victim-fiserv/ · https://www.breachsense.com/breaches/fiserv-data-breach/ · Sources: [DeXpose] · [RedPacket Security] · [Breachsense]
May 02 TSYS Everest Ransomware · payment processing · US Global Payments' core payment-processing and card-issuer subsidiary; Everest DLS May 2, 2026; data scope undisclosed; no victim statement; 🟥 unverified · https://www.hookphish.com/blog/ransomware-group-everest-hits-tsys/ · https://www.redpacketsecurity.com/everest-ransomware-victim-tsys/ · Sources: [HookPhish] · [RedPacket Security]

April 2026

Apr 30 Liberty Mutual Insurance Everest Ransomware · insurance · US 108 GB (52,429 files) dumped May 4 after ransom deadline; policyholder names, addresses, policy numbers, financial details; Liberty Mutual confirmed "third-party vendor" investigation and denied direct system compromise; 🟨 vendor breach confirmed · https://www.bankinfosecurity.com/everest-group-begins-leaking-alleged-liberty-mutual-data-a-31589 · https://cybernews.com/security/liberty-mutual-ransomware-attack-policyholder-data/ · Sources: [BankInfoSecurity] · [Cybernews]
Apr 20 Citizens Financial Group Everest Ransomware · banking · US shared statement-printing vendor compromised; 3.4M records (names, home addresses, account numbers, internal document flags; no SSNs confirmed); Everest DLS April 20, 2026; Citizens confirmed third-party vendor breach; class action filed US District Court Providence April 24; 🟨 vendor breach confirmed · https://www.scworld.com/brief/extensive-citizens-financial-group-frost-bank-breaches-claimed-by-everest-ransomware · https://www.americanbanker.com/news/citizens-frost-blame-vendor-after-data-breach-claim · Sources: [SC Media] · [American Banker]
Apr 20 Frost Bank Everest Ransomware · banking · US same shared vendor as Citizens Financial Group; 250K records incl. SSNs, tax IDs, mortgage rates, income data, home addresses; Everest DLS April 20, 2026; Frost confirmed third-party vendor breach; full data dumped after 6-day deadline; 🟨 vendor breach confirmed · https://www.scworld.com/brief/extensive-citizens-financial-group-frost-bank-breaches-claimed-by-everest-ransomware · https://cybernews.com/security/everest-ransomware-frost-citizens-bank-breach/ · Sources: [SC Media] · [Cybernews]
Apr 16 Empower Group DragonForce Ransomware · financial services · UAE UAE financial services firm; DragonForce DLS claim April 16, 2026; 316.38 GB exfiltrated claimed; data scope unconfirmed; previously uncaptured; 🟥 unverified · https://www.ransomware.live/group/dragonforce · https://www.dexpose.io/ · Sources: [ransomware.live] · [DeXpose]
Apr 16 Standard Bank Group PrinzEugen Ransomware · banking · financial services/South Africa 1.2 TB exfiltrated; 1 BTC ransom demanded and refused; Group is South Africa's largest bank by assets; DLS claim April 16; first widely documented Prinz Eugen victim (new Go-based strain analyzed June 20 by ThreatDown) · https://www.bleepingcomputer.com/news/security/new-prinz-eugen-ransomware-prioritizes-recent-files-for-encryption/ · https://www.threatdown.com/blog/prinz-eugen-ransomware-a-deep-dive-into-a-new-go-based-encryptor/ · Sources: [BleepingComputer] · [ThreatDown]

March 2026

Mar 17 AssuranceAmerica Unattributed Breach · insurance · auto/US 14-state auto insurer headquartered in Atlanta, GA; employee credential compromise allowed unauthorized access March 17 – June 15, 2026; 6,990,000+ individuals' driver's licence numbers exfiltrated across 14 states; notification letters began July 10, 2026; actor unattributed · https://www.bleepingcomputer.com/ · https://securityaffairs.com/ · https://www.technadu.com/ · Sources: [BleepingComputer] · [SecurityAffairs] · [TechNadu]

← All industries · Victim database →