Report by Black Kite
2026 State of Financial Services: The Dual Storm of Ransomware and Vendor Ecosystem Risk
Key Findings
Direct ransomware attacks on financial institutions spiked 76% year-over-year in Q1 2026.
Across all financial services vendors, 50.2% carry high-severity CVEs.
Over 48,000 CVEs were published globally in 2025, an 18% year-on-year increase.
In September 2025, Qilin's compromise of a single South Korean MSP affected 32 financial institutions and resulted in over 2 terabytes of stolen data.
Qilin was responsible for 59 finance-sector incidents in the past year.
From 2024 to 2025, the number of critical vulnerabilities carried across vendors serving the financial sector increased 387%.
The number of distinct threat groups targeting finance increased from 37 in 2023 to 45 in 2024 and to 48 in 2025.
Reported ransomware incidents targeting finance increased 30% from 2024 to 2025.
Among the 140 vendors whose client base is meaningfully concentrated in finance, critical vulnerabilities increased 181%.
Critical-level patch management failures were present in 78% of the 140 vendors whose client base is meaningfully concentrated in finance.
54% of the 140 vendors whose client base is meaningfully concentrated in finance carry at least one vulnerability listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
Banks reported 71 ransomware disclosures in 2023 compared to 44 disclosures by investment firms, while by 2025 banks fell to 36 disclosures and investment firms rose to 84 disclosures (41.6% of all incidents).