Skip to content
Tiatra, LLCTiatra, LLC
Tiatra, LLC
Information Technology Solutions for Washington, DC Government Agencies
  • Home
  • About Us
  • Services
    • IT Engineering and Support
    • Software Development
    • Information Assurance and Testing
    • Project and Program Management
  • Clients & Partners
  • Careers
  • News
  • Contact
 
  • Home
  • About Us
  • Services
    • IT Engineering and Support
    • Software Development
    • Information Assurance and Testing
    • Project and Program Management
  • Clients & Partners
  • Careers
  • News
  • Contact

New Threat Intelligence: The CrowdStrike 2026 Financial Services Threat Landscape Report

The financial services industry is the fourth most-targeted sector globally, accounting for 12% of all observed activity. eCrime and nation-state adversaries spanning all motivations target these organizations due to their unique convergence of valuable assets, strategic intelligence, and geopolitical significance.

The CrowdStrike 2026 Financial Services Threat Landscape Report analyzes the key trends shaping the sector from April 1, 2025, through March 31, 2026. The report provides insights organizations need to anticipate threats and strengthen defenses as attacks continue to evolve.

Hands-on-keyboard intrusions against financial institutions increased 43% globally and 48% in North America over the past two years. As these threats accelerate, businesses must understand how adversaries operate in order to stop them.

eCrime pressure on financial services intensifies

eCrime activity targeting financial services escalated in 2025. Big game hunting (BGH) adversaries named 423 financial services entities on dedicated leak sites, a 27% increase year over year.

MUTANT SPIDER drove the highest volume of intrusions during the reporting period and likely sold access to ransomware operators. SCATTERED SPIDER resumed aggressive ransomware operations against insurance entities following a significant pause.

Additional eCrime activity included:

  • CHATTY SPIDER conducted high-tempo data theft and extortion campaigns targeting legal and financial services organizations, leaking data from 41 victims.
  • SOLAR SPIDER targeted financial institutions across Europe, the Middle East, South Asia, and Southeast Asia using transaction-themed lures to deploy remote access tools.
  • PLUMP SPIDER has targeted Brazilian financial entities since at least 2023 in attempts to access payment systems and conduct fraudulent transactions.

Nation-state adversaries scale theft and deception

Democratic People’s Republic of Korea (DPRK)-nexus groups sustained operations targeting cryptocurrency and fintech entities. These adversaries stole $2.02 billion in digital assets in 2025, a 51% increase from 2024. Stolen funds directly support the regime’s military programs. PRESSURE CHOLLIMA stole $1.46 billion in cryptocurrency through trojanized software distributed via supply chain compromise — the largest single financial theft ever reported.

DPRK-nexus threat actors increased operational tempo and advanced their social engineering tradecraft against financial entities. FAMOUS CHOLLIMA doubled their operations, targeting cryptocurrency exchanges, fintech platforms, and traditional banks.

STARDUST CHOLLIMA tripled their operational tempo, using recruiter impersonation, malicious coding challenges, and synthetic video conferencing environments to target fintechs across North America, Europe, and Asia. 

China-nexus adversaries posed the most significant intelligence collection threat to financial services organizations, especially in South and Southeast Asia. These operations likely reflect interest in regional financial systems and economic intelligence.

Observed China-nexus tactics, techniques, and procedures (TTPs) include: 

  • HOLLOW PANDA targeted financial institutions in South America and Southeast Asia.
  • VAULT PANDA deployed KEYPLUG malware via DLL search-order hijacking.
  • GENESIS PANDA targeted a Southeast Asia-based financial entity and a North American fintech organization using VShell implants and FScan utilities.
  • MURKY PANDA deployed a Chinese operational relay box (ORB) network to access Microsoft 365 email accounts from more than 150 IP addresses in 36 countries; they targeted 340 organizations across 30+ sectors, including financial services.

The trends outlined in this report create significant operational risk for financial services businesses. Ransomware pressure, sustained intelligence collection, and continued digital asset theft often move quickly through trusted access paths. As AI capabilities advance, adversaries are likely to increase the sophistication, scale, and speed of their operations.

Defenders need intelligence-led visibility, continuous hunting, and the ability to act quickly with context. CrowdStrike Counter Adversary Operations combines threat intelligence, managed threat hunting, and trillions of telemetry events from the AI-powered CrowdStrike Falcon® platform to detect, disrupt, and stop evasive adversaries. 

Learn more: Download the CrowdStrike 2026 Financial Services Threat Landscape Report.


Read More from This Article: New Threat Intelligence: The CrowdStrike 2026 Financial Services Threat Landscape Report
Source: News

Category: NewsJune 2, 2026
Tags: art

Post navigation

NextNext post:Workday launches Agent Passport to test and monitor AI agents in the enterprise

Related posts

Workday launches Agent Passport to test and monitor AI agents in the enterprise
June 2, 2026
Snowflake recasts its AI strategy around action, not answers, with CoWork
June 2, 2026
AI doesn’t just make mistakes. It defends them
June 2, 2026
Vibe coding an AI governance platform forced me to rethink governance itself
June 2, 2026
Cloud strategies have become more complicated than ever
June 2, 2026
AI killed the code review. What happens to knowledge sharing?
June 2, 2026
Recent Posts
  • New Threat Intelligence: The CrowdStrike 2026 Financial Services Threat Landscape Report
  • Workday launches Agent Passport to test and monitor AI agents in the enterprise
  • Snowflake recasts its AI strategy around action, not answers, with CoWork
  • AI doesn’t just make mistakes. It defends them
  • Vibe coding an AI governance platform forced me to rethink governance itself
Recent Comments
    Archives
    • June 2026
    • May 2026
    • April 2026
    • March 2026
    • February 2026
    • January 2026
    • December 2025
    • November 2025
    • October 2025
    • September 2025
    • August 2025
    • July 2025
    • June 2025
    • May 2025
    • April 2025
    • March 2025
    • February 2025
    • January 2025
    • December 2024
    • November 2024
    • October 2024
    • September 2024
    • August 2024
    • July 2024
    • June 2024
    • May 2024
    • April 2024
    • March 2024
    • February 2024
    • January 2024
    • December 2023
    • November 2023
    • October 2023
    • September 2023
    • August 2023
    • July 2023
    • June 2023
    • May 2023
    • April 2023
    • March 2023
    • February 2023
    • January 2023
    • December 2022
    • November 2022
    • October 2022
    • September 2022
    • August 2022
    • July 2022
    • June 2022
    • May 2022
    • April 2022
    • March 2022
    • February 2022
    • January 2022
    • December 2021
    • November 2021
    • October 2021
    • September 2021
    • August 2021
    • July 2021
    • June 2021
    • May 2021
    • April 2021
    • March 2021
    • February 2021
    • January 2021
    • December 2020
    • November 2020
    • October 2020
    • September 2020
    • August 2020
    • July 2020
    • June 2020
    • May 2020
    • April 2020
    • January 2020
    • December 2019
    • November 2019
    • October 2019
    • September 2019
    • August 2019
    • July 2019
    • June 2019
    • May 2019
    • April 2019
    • March 2019
    • February 2019
    • January 2019
    • December 2018
    • November 2018
    • October 2018
    • September 2018
    • August 2018
    • July 2018
    • June 2018
    • May 2018
    • April 2018
    • March 2018
    • February 2018
    • January 2018
    • December 2017
    • November 2017
    • October 2017
    • September 2017
    • August 2017
    • July 2017
    • June 2017
    • May 2017
    • April 2017
    • March 2017
    • February 2017
    • January 2017
    Categories
    • News
    Meta
    • Log in
    • Entries feed
    • Comments feed
    • WordPress.org
    Tiatra LLC.

    Tiatra, LLC, based in the Washington, DC metropolitan area, proudly serves federal government agencies, organizations that work with the government and other commercial businesses and organizations. Tiatra specializes in a broad range of information technology (IT) development and management services incorporating solid engineering, attention to client needs, and meeting or exceeding any security parameters required. Our small yet innovative company is structured with a full complement of the necessary technical experts, working with hands-on management, to provide a high level of service and competitive pricing for your systems and engineering requirements.

    Find us on:

    FacebookTwitterLinkedin

    Submitclear

    Tiatra, LLC
    Copyright 2016. All rights reserved.