Report by CrowdStrike

2026 Financial Services Threat Landscape Report

9 FINDINGSPublished May 14, 2026
View Original Report →

Key Findings

MURKY PANDA deployed an operational relay box network across more than 150 endpoints in 36 countries, targeting 340 organizations across more than 30 sectors.

Cyber EspionageNetwork Operations

423 financial services organizations appeared on dedicated leak sites, marking a 27% year-over-year increase.

Data LeaksFinancial ServicesData Leak Sites

PRESSURE CHOLLIMA conducted the largest financial theft ever reported: $1.46 billion in cryptocurrency via a trojanized supply chain compromise.

CryptocurrencySupply ChainFinancial Theft

Hands-on-keyboard intrusions against financial institutions spiked 43% globally and 48% in North America over the past two years.

Financial ServicesHands-on-keyboard IntrusionsNorth America

DPRK-nexus actors stole a reported $2.02 billion in digital assets across the financial services sector in 2025.

Digital Asset TheftFinancial Services

SCATTERED SPIDER resumed aggressive ransomware operations against insurance entities in the first half of 2025 after a four-month pause.

RansomwareInsurance

FAMOUS CHOLLIMA doubled its operations using AI-generated identities to infiltrate cryptocurrency exchanges, fintech platforms, and consumer banks.

AI-Generated IdentitiesCryptocurrencyFinancial FraudDeepfakesFinancial Services

DPRK-nexus actors drove a 51% year-over-year increase in digital asset theft in 2025.

Digital Asset TheftNation-State Threats

STARDUST CHOLLIMA tripled its operational tempo and deployed AI-generated recruiter personas and synthetic video conferencing environments to target fintechs across North America, Europe, and Asia.

AI-Generated IdentitiesFintechDeepfakesGlobal Threats