Skip to main content

Sector intelligence · rolling 90-day view

Financial Services Cybersecurity News

Track current cyber incidents and threat signals across the financial ecosystem, from customer-facing payment services to lending, insurance and investment operations.

Current 90-day insights

What does the current financial services view show?

These observations are calculated from signals currently classified in this sector. They describe the available reporting, not the sector's total incident prevalence.

49

Matching signals

in the rolling 90-day window

12

High or critical

confidence classifications

45

Named organizations

represented in current signals

Explore related intelligence

Explore this reporting from another angle

Based on all published financial services signals in the rolling 90-day window. Counts describe this reporting set, not overall incident prevalence.

Current signals

What is happening in Financial Services?

Explore all cybersecurity news
Srbancorp logoSrbancorp
High

SR Bancorp Discloses Data Security Incident at Internal Audit Provider Mercadien, Exposing Somerset Regal Bank Customer Data

SR Bancorp, Inc. reported a data security incident on July 10, 2026, involving its internal audit service provider, Mercadien, P.C. CPAs. An unauthorized actor accessed and acquired files from Mercadien's servers that contained sensitive customer data belonging to Somerset Regal Bank. The compromised information included customer names, Social Security numbers, account numbers, identification documents, and dates of birth. Importantly, SR Bancorp confirmed that the bank's own business systems, payment systems, customer access to accounts, and core information technology infrastructure were not directly impacted or disrupted by this incident. The company is coordinating customer notifications through Mercadien as required by applicable federal and state laws and regulatory guidance. While the incident exposes SR Bancorp to regulatory notification requirements, reputational risk, and potential legal liability, the company has initially assessed the financial impact as immaterial to its consolidated financial condition or results of operations. However, this assessment could change if the data is published or misused, or if further cybersecurity incidents occur. This event highlights the inherent risks associated with third-party vendors handling sensitive customer information.

Finance and Insurance

Aflac logoAflac
Medium

Aflac Life Insurance Japan Suffers Cybersecurity Breach Exposing Policyholder Data

Aflac Life Insurance Japan disclosed unauthorized access to its systems between June 15 and June 25, 2026. The breach affected files containing policy details, personal information, and bank account information of approximately 4.38 million customers. The company has suspended affected systems and is investigating the incident with third-party cybersecurity experts.

Finance and Insurance

Naic logoNaic
Medium

National Association of Insurance Commissioners (NAIC) Confirms Data Breach via Oracle PeopleSoft Zero-Day

The National Association of Insurance Commissioners (NAIC), a US insurance regulatory standards body, confirmed a cyberattack after the ShinyHunters group claimed theft of 3.1TB of data. The breach was reportedly achieved through an Oracle PeopleSoft zero-day vulnerability. ShinyHunters claimed access to regulatory filings, production logs, cloud configuration files, and other internal records.

Finance and Insurance

Riskstrategies logoRiskstrategies
Medium

Risk Strategies Discloses Data Breach Involving Personal and Medical Information

Risk Strategies Data Breach Exposes Social Security Numbers Risk Strategies , officially known as RSC Insurance Brokerage Inc., disclosed a data breach involving sensitive personal and medical information. Between January 15, 2026, and January 16, 2026, an unauthorized user gained access to the Microsoft 365 account of a Risk Strategies employee. An investigation of the affected files, which concluded on June 1, 2026, determined the files contained personal information belonging to individuals. The incident compromised names, Social Security numbers and medical records. Risk Strategies began mailing affected individuals notification letters concerning the incident on June 23, 2026. A total number of 15,055 individuals were affected nationwide including 76 Nebraska residents and 47 Massachusetts residents were impacted. Risk Strategies is offering affected individuals a complimentary 24-month membership to credit monitoring services provided by Epiq. The service, called Privacy Solutions ID 3B Credit Monitoring, can be activated at privacysolutionsid.com . Affected individuals received a unique activation code and enrollment deadline in their notification letter. Affected individuals with questions about the incident can call Risk Strategies at 866-659-7098, Monday through Friday, from 9:00 a.m. to 9:00 p.m. EST. For help with the Epiq enrollment process, individuals can call 866-675-2006, Monday through Friday, from 9:00 a.m. to 5:30 p.m. ET. SUBMIT YOUR CLAIM TO THE LAW FIRM HANDLING THIS INVESTIGATION Affected information types not yet disclosed This browser does not support inline PDFs. Please download the PDF to view it: Download PDF Class actions settlements delivered to your inbox. SportsMed Physical Therapy Data Breach Exposes Health Information Trudeau Center Breach Affects 5,630 Individuals Alkegen Data Breach Exposes Personal and Protected Health Information Whitfield Hospital Breach Exposed Medical and Health Information Attorneys working with ClassAction.org are looking into whether a class action lawsuit can be filed in light of the Risk Strategies data breach. As part of their investigation, they need to hear from individuals who had their information exposed in the incident , including those who received notice of the Risk Strategies data breach or otherwise believe they are affected. Risk Strategies Security Incident: What Happened? RSC Insurance Brokerage, which operated as Risk Strategies before merging with Brown & Brown, has reported a data breach involving personal information. According to a sample notification letter (pictured below), names and Social Security numbers were involved. For some of those impacted by the Risk Strategies data breach, medical information and health, dental, and/or vision insurance information may have been compromised. A report detailing the cybersecurity incident was submitted to the Massachusetts Office of Consumer Affairs and Business Regulation on June 23, 2026. What You Can Do After the Risk Strategies Data Breach If your information was exposed in the Risk Strategies data breach, attorneys want to hear from you. You may be able to start a class action lawsuit to recover compensation for loss of privacy, time spent dealing with the breach, out-of-pocket costs, and more. A successful case could also force Risk Strategies to ensure they take proper steps to protect the information they were entrusted with. Affected by the Risk Strategies data breach? Fill out the form on this page today. If you believe your information was exposed in the Risk Strategies data breach, fill out the form on this page to get in touch with us. An attorney or legal representative may then reach out to you to explain more about this investigation and ask you a few questions. Remember, there is no cost to get in touch, and you are under no obligation to take action after speaking to someone. New cases and investigations, settlement deadlines, and news straight to your inbox. Whitfield Regional Hospital Data Breach 2026 Community Health Center of Buffalo Data Breach 2026 Advantage Home Health Care Data Breach 2026 Unlimited Technology Systems Data Breach 2026 Heart Care Centers of Illinois Data Breach 2026 Clover Health Investments Data Breach 2026 Morris Communications Company Data Breach 2026 Brown Health Medical Group-MA Data Breach 2026 Case & Associates Properties Data Breach 2026

Information

Bmi logoBmi
Medium

Melli Bank Affected by Cyberattacks in Iran

Melli Bank was among three major Iranian banks affected by a wave of cyberattacks reported on June 23, 2026. The incident prompted a temporary nationwide suspension of card-based services to prevent unauthorized access. This follows an earlier wave of disruptions in mid-June.

Finance and Insurance

Tejaratbank logoTejaratbank
Medium

Tejarat Bank Affected by Cyberattacks in Iran

Tejarat Bank was among three major Iranian banks affected by a wave of cyberattacks reported on June 23, 2026. The incident prompted a temporary nationwide suspension of card-based services to prevent unauthorized access. This follows an earlier wave of disruptions in mid-June.

Finance and Insurance

Ayabank logoAyabank
Medium

AYA BANK Hit by Lapsus$ Ransomware Attack

AYA BANK, a prominent financial institution in Myanmar, fell victim to a ransomware attack by the Lapsus$ group, discovered on June 23, 2026. Lapsus$ claimed to have stolen over 120 gigabytes of data, including a full dump and PII, and threatened to sell it if a ransom was not paid. AYA Bank acknowledged a breach of an older application portal exposing some customer information but stated its core financial networks remained secure.

Finance and Insurance

Bsis logoBsis
Medium

Saderat Bank Affected by Cyberattacks in Iran

Saderat Bank was among three major Iranian banks affected by a wave of cyberattacks reported on June 23, 2026. The incident prompted a temporary nationwide suspension of card-based services to prevent unauthorized access. This follows an earlier wave of disruptions in mid-June.

Finance and Insurance

Assuranceamerica logoAssuranceamerica
Medium

AssuranceAmerica Managing General Agency data breach exposes policyholder data

AssuranceAmerica Managing General Agency, LLC, an Atlanta-based nonstandard auto insurance provider, reported a data breach to the South Carolina Department of Consumer Affairs on June 18, 2026. The breach, detected on March 17, 2026, involved an unauthorized third party accessing and copying files from its computer systems after targeting a single employee. A review completed on June 15, 2026, identified that names, contact details, insurance policy information, driver/vehicle information, claims data, driver's license numbers, tax ID information, and potentially Social Security numbers were exposed.

Finance and Insurance

Sofi logoSofi
Medium

SoFi Hong Kong Confirms Third-Party Data Breach

SoFi Hong Kong, a subsidiary of the financial technology company SoFi, confirmed a data breach after hackers gained unauthorized access to a database at a third-party vendor containing customer information. The company is advising customers to update passwords, enable two-factor authentication, and monitor their accounts.

Finance and Insurance

Dentaquest logoDentaquest
Medium

DentaQuest Data Breach by ShinyHunters Affects 2.6 Million Accounts

Dentaquest Hit with Cyberstrike Affecting 2.6M Dental benefits administrator hit with cyberstrike affecting 2.6M | DrBicuspid.com Dental benefits administrator and insurance provider DentaQuest was hit recently by a cybersecurity incident, allegedly exposing the personal data of 2.6 million accounts, according to a story published June 4 on Bleeping Computer . DentaQuest wrote in a statement posted June 1 on its website that it’s actively managing the data breach, which involved “unauthorized access to a limited portion of our network.” Despite the incident, DentaQuest’s systems are fully operational with limited disruption to its customers, according to a statement. In May, extortion group ShinyHunters listed DentaQuest on its data leak site, claiming it had 234GB of stolen data, including names, government-issued identification cards, and health insurance information, from the company, according to Bleeping Computer . The cyber gang publicly released the stolen information after it reportedly could not reach an agreement with DentaQuest, according to the story. DentaQuest did not confirm the number of accounts affected. It stated that it took immediate action to mitigate the threat after discovering the incident. Furthermore, the company wrote in the statement that it was working with a cybersecurity expert, forensic investigators, and law enforcement. “We are working as quickly and carefully as possible to determine the exact scope of the incident, including the nature and extent of any data that may have been compromised,” DentaQuest stated. DentaQuest, which is part of Sun Life , serves more than 30 million members in U.S. and manages plans and provider networks for employers, individuals, Medicaid recipients, and Medicare Advantage beneficiaries. Data Breach Roundup (May 29 - June 4, 2026) Charter Communications data breach affects 4.9 million accounts An update to a breach from last week, there's not much new here except that we now know how many people were impacted. ShinyHunters claims the data includes consumer and business customer names, email addresses, physical addresses, phone numbers, phone types, plan information, support ticket data, and some CPNI data. Grand Theft Auto V cheat service gets hacked, exposing thousands of gamers Atlas Menu is a popular cheat service for Grand Theft Auto V online, and has now suffered a data breach. Stolen data includes email addresses, usernames, hashed passwords, IP addresses, and support tickets of about 64,000 accounts. There's no information in this article about how Atlas Menu was breached. Ultrahuman says hackers accessed customers’ wellness data via internal tool Ultrahuman sells smart rings and metabolic health-tracking devices that enable users to monitor metrics such as sleep, activity, and recovery. The startup is best known for its Ring Air, which competes with the Oura Ring. The company says the incident was the result of gaining credentials stolen from an employee’s malware-infected laptop. They have declined to say how many people or what data was impacted, citing an ongoing investigation. UN food agency discloses breach affecting 600,000 Gaza households The UN's World Food Programme (WFP) says that the self-registration application (SRA) for Palestine was breached. Affected data included names, ID numbers, phone numbers, and location information (such as neighborhood data recorded during registration). DentaQuest data breach exposed info of 2.6 million accounts DentaQuest, is one of the largest dental benefits administrators in the United States. The breach is the result of the ShinyHunters ransomware gang, and impacts Email addresses full names, phone numbers, government-issued IDs, health insurance information, genders, and dates of birth. California AG sues 23andMe over 2023 breach exposing health data A small update to a story that just won't end. This breach alleges "failure to protect sensitive customer genetic and personal information." We will update you if there's any further information.

Information

Eecu logoEecu
Medium

Educational Employees Credit Union (EECU) Data Breach Exposes Member Information

Educational Employees Credit Union (EECU) reported a data breach where an unauthorized individual gained access to a single employee email account on December 15, 2025. Following an investigation, EECU determined on May 8, 2026, that emails within the compromised account contained members' personal information. Notification letters were sent to affected individuals starting May 29, 2026. The exposed data includes names, addresses, Social Security numbers, driver's license numbers, and financial information.

Finance and Insurance

Beaconmutual logoBeaconmutual
Medium

Beacon Mutual Insurance Co. Ransomware Attack Compromises 131,000 Rhode Islanders' Data

Beacon Mutual Insurance Co., Rhode Island's largest workers' compensation insurer, disclosed that highly sensitive personal information belonging to over 131,000 Rhode Islanders was compromised in a ransomware attack earlier in the year. An unauthorized person gained access to the company's system between January 7th and January 14th, accessing files containing names, Social Security numbers, driver's license numbers, financial account numbers, health insurance information, and/or medical treatment details.

Finance and Insurance

Hdfcfund logoHdfcfund
Medium

HDFC Asset Management Company Ltd. Experiences Cyber Attack

HDFC Asset Management Company Ltd. (HDFC AMC), one of India's largest mutual fund managers, identified a cybersecurity incident on May 16, 2026, after receiving communication from an anonymous source claiming access to parts of its IT systems. The company promptly activated containment and incident response protocols and engaged a specialist cybersecurity firm for a forensic assessment. Preliminary findings suggest no material impact on operations or business continuity, though investor identity and financial data may have been exposed. The incident led to a drop in the company's stock price.

Finance and Insurance

Medium

American Lending Center Data Breach Affects 123,000 Individuals

American Lending Center this week revealed that a data breach discovered last year has impacted more than 123,000 individuals. American Lending Center (ALC) is a California-based non-bank lender that manages a $3 billion portfolio specializing in government-guaranteed small business loans. The organization is notifying individuals affected by the data breach that information such as names, dates of birth, and SSNs may have been stolen in a ransomware attack detected in July 2025.  “Through a forensic investigation into this breach, it was discovered that the threat actor compromised internal network, executed a ransomware attack, and accessed certain files that may have contained personal identifying or sensitive information,” ALC said in its notification to impacted customers, a c opy of which was submitted to the Maine attorney general’s office. The investigation was completed on April 8, and ALC has found no evidence that the potentially compromised information has been misused.  Companies often include a statement in their data breach notifications that there is no evidence of misuse, even when information has been made public by cybercriminals. Advertisement. Scroll to continue reading. In the case of ALC, no known ransomware group appears to have taken credit for the attack, which could indicate either that a ransom has been paid or that the financial institution has been targeted by a cybercrime gang that does not have a public leak website. SecurityWeek has reached out to ALC for clarification and will update this article if it responds. Related : Foxconn Confirms North American Factories Hit by Cyberattack Related : 716,000 Impacted by OpenLoop Health Data Breach Related : BWH Hotels Says Hackers Had Access to Reservation Data for 6 Months Related : Deal Reached With Hackers to Delete Data Stolen From the Canvas Educational Platform Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data Exploitation of ServiceNow Vulnerability Seen Days After Disclosure SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch New Index Tracks Material Breaches — And Refuses to Add Up the Losses WP2Shell WordPress Vulnerabilities Exploited in the Wild Two Scattered Spider Hackers Sentenced to Jail in UK ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains Cisco Launches Low-Cost AI Models for Source Code Security Empirical Security Raises $25 Million in Series A Funding SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage. CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! American Lending Center data breach impacts over 123,000 individuals American Lending Center revealed that a data breach discovered last year has impacted more than 123,000 individuals. The California-based non-bank lender, which specializes in government-guaranteed small business loans, is notifying affected individuals that personal information may have been stolen in a ransomware attack detected in July 2025, according to a recent report by Security Week. The breach involved a ransomware attack where threat actors compromised the internal network and accessed files containing personal identifying information. This potentially includes names, dates of birth, and Social Security numbers for over 123,000 individuals. A forensic investigation completed on April 8 found no evidence of misuse of the compromised data. It is unclear which ransomware group, if any, is responsible for the attack, as no known group has claimed responsibility.

Information

Newyorklife logoNewyorklife
Medium

New York Life Insurance Data Breach

New York Life Insurance disclosed a data breach that exposed sensitive personal information belonging to its customers and individuals connected to its services. This incident increases the risk of identity theft, insurance fraud, phishing attacks, and the misuse of financial and personal records for affected individuals.

Finance and Insurance

Medium

TransGlobal Insurance Agency Data Breach Exposes Personal Information

TransGlobal Insurance Agency, Inc. discovered suspicious activity on its computer network on February 24, 2026, indicating a data breach. A forensic investigation determined that cybercriminals accessed files around February 18, 2026, potentially acquiring sensitive personal information of thousands of individuals, including names, Social Security numbers, driver's license numbers, addresses, and dates of birth. Law firms are investigating potential class action lawsuits.

Finance and Insurance

What does this sector view cover?

Banks

Retail, commercial, digital and specialist banking organizations.

Credit unions

Member-owned financial institutions and their service providers.

Insurers

Insurance carriers, brokers and insurance technology platforms.

Fintechs

Technology-led financial products, platforms and infrastructure.

Payment providers

Payment processors, gateways, card services and digital wallets.

Lenders

Consumer, mortgage, business and specialist credit providers.

Investment and wealth management

Asset managers, investment firms, brokerages and wealth advisers.

Questions answered

Questions about financial services cybersecurity

What cyber threats are affecting financial services right now?

Financial organizations currently need to watch ransomware, data breaches, credential abuse, exposed systems and attacks through technology providers.

The mix changes as new incidents are reported, so this page combines a rolling 90-day signal view with stable guidance. Security leaders can use the current cases to test whether the same identities, internet-facing services, payment dependencies or third parties exist in their own environment.

What should financial-services CISOs monitor first?

Start with identity controls, internet-facing services, payment infrastructure, customer-data exposure, critical suppliers and operational resilience.

Priorities should reflect the services whose failure would interrupt customers or regulated operations. Current peer incidents help CISOs challenge control assumptions, identify recurring entry points and decide where a focused review or tabletop exercise will reduce risk fastest.

How does ransomware affect banks, insurers and payment providers?

Ransomware can make essential systems unavailable, expose sensitive data and create simultaneous recovery, regulatory and customer-communication pressure.

The operational effect depends on which service is hit and how quickly the organization can isolate it. A useful review connects each peer incident to recovery dependencies, identity containment, manual workarounds, data-loss decisions and the evidence needed for notifications.

Why is third-party cyber risk critical in financial services?

Financial services depend on interconnected processors, software platforms and service providers, so one supplier incident can affect many organizations at once.

A vendor inventory alone does not show this concentration risk. Teams should connect current supplier incidents to the business services they support, the data they handle, alternative providers, contractual reporting duties and the controls available when direct remediation is outside the organization.

Which data is most exposed in financial-services breaches?

Reported breaches may expose identity, account, transaction, payment-card, insurance or investment data, depending on the organization and affected system.

The decision-relevant question is not only which records were accessed, but what an attacker can do with them. Security and privacy teams should assess fraud potential, account takeover, identity abuse, customer harm, notification duties and whether exposed data can be combined with information from other incidents.

How should financial organizations use peer incident intelligence?

Use peer incidents as decision triggers for targeted control checks, threat hunting, supplier reviews and resilience exercises—not as a passive news feed.

Each signal should lead to a small number of testable questions: do we use the same technology, expose a similar service, depend on the same type of provider or hold comparable data? Recording the answer, owner and follow-up turns external reporting into evidence for risk decisions.

How do regulation and operational resilience shape incident response?

Financial organizations need response plans that restore critical services and produce timely, reliable evidence for the rules that apply in each jurisdiction.

Requirements vary internationally, but the operational disciplines are similar: understand service impact, preserve evidence, escalate decisions, coordinate suppliers and communicate consistently. Regional frameworks such as the EU's DORA add specific expectations, so legal and compliance teams should map current incidents to the obligations that actually apply.