Financial Services Cybersecurity Statistics
Top Topics in Financial Services
Latest Statistics
38% of organizations allow AI agents to create and modify business records
Financial services breaches cost on average $6.3 million.
Financial services recorded the highest frequency of compromises by sector at 387.
Malware activity averaged 39,341 hits per firewall in the first half of 2026, giving financial services the second-highest per-device malware intensity of any industry, behind only healthcare.
51% of IAM leaders and stakeholders cite the inability to support legacy apps and infrastructure as an obstacle to universal phishing-resistant MFA.
The GoodTech Telnet Server Buffer Overflow vulnerability generated 42.2 million detection events in the financial services industry in the first half of 2026.
Only 28% of the MFA used for workforce authentication in financial services is phishing-resistant.
SaaS applications in financial organizations are protected by MFA at a rate of 74%.
Legacy systems in financial organizations are protected by MFA at a rate of 50%.
54% of financial organizations report that at least half their applications and infrastructure are legacy.
Only 15% of workforce authentication flows in financial services are passwordless.
79% of IAM leaders and stakeholders cite technical or architectural complexity as an obstacle to universal phishing-resistant MFA.
53% of IAM leaders and stakeholders cite cost and budget constraints as an obstacle to universal phishing-resistant MFA.
Among organizations that cite regulatory compliance as a top driver to modernize, 79% report that at least half their applications and infrastructure are legacy.
68% of restaurant leaders lose more than $1,000 per hour when point-of-sale or ordering systems fail during a peak meal rush.
Log4Shell generated 35.6 million detection events in the first half of 2026 in the financial services industry, more than two years after disclosure.
Ten ransomware families were active against the financial services sector in the first half of 2026, including REvil (Sodinokibi) and Prometheus.
Financial services experienced more than double the cross-sector average of cyberattack attempts per device in the first half of 2026.
Financial services saw 132,378 IPS hits per device in the first half of 2026, the highest attack intensity of any industry SonicWall tracks.
94% of IAM leaders and stakeholders at financial services firms report that phishing attacks increased over the past year.
82% of IAM leaders and stakeholders at financial services firms are confident their current controls can mitigate account takeover risk.
34% of restaurant leaders say a loss under $50,000 would significantly impact their business.
Interactions with Network APIs, including SIM Swap and Number Verification, grew by 91%, with the finance sector leading adoption.
Internal information disclosure accounts for 42.7% of critical exposures in Financial Services.
35.9% of IT and security professionals report experiencing business email compromise (BEC) resulting in financial or data loss in the past 12 months.
Financial losses totalling around £270,000 were reported by UK organisations that experienced ransomware last year, a 50 per cent increase compared to previous year.
Average ransom payment dropped to $2.8 million, down from $3.6 million in 2025.
83% of ransomware victims paid a ransom, up from 70% previously.
In North America, 24% of breached organizations reported losses of at least $100,000 in the past year.
In North America, 12% of breached organizations reported losses above $250,000 in the past year.