Trustwave Reveals the Financial Sector's Cyber Threats

Share this article
Share this article
Prioritise Us on Google
The cost of a data breach in the finance sector is second only to healthcare
While cybercriminals targeting financial service providers is nothing new, they are using increasingly sophisticated techniques to access sensitive data

Fraudsters are finding new and advanced ways to use technology to access sensitive information, reveals the latest report from Trustwave.

The data supports research conducted by the International Monetary Fund (IMF), which warned that Global financial stability is under threat from the increasing frequency and sophistication of cyberattacks in April.

Trustwave’s SpiderLabs 2024 Risk Radar Report for the Financial Services Sector highlights several prominent trends currently used by malicious actors: 

Insider threats: The Trustwave SpiderLabs team found that 48% of risky findings were related to remote access software and protocol tunnelling. 

Phishing-as-a-Service (PaaS): This emerging threat offers sophisticated phishing tools through underground forums and Telegram marketplaces, with attackers increasingly using HTML and PDF attachments to obfuscate phishing URLs.

Ransomware: Financial institutions remain prime targets for ransomware attacks, with the report identifying LockBit and AlphV's as the predominant groups, with AlphV's share of attacks increasing from 10% to 24% in the past year.

The analysis, compounded with recent industry insights, reveals a sector grappling with sophisticated cyber threats amidst a backdrop of regulatory pressures and technological advancements.

In the last 20 years, nearly 20% of reported cyber cases were related to the global financial sector, resulting in $US12bn in direct losses to financial firms, according to the IMF’s Global Financial Stability Report. Since 2020 alone, direct losses have totalled an estimated $US2.5bn.

The IMF’s report found that banks are particularly vulnerable to attacks and noted that losses can be much greater for all types of firm when taking into account indirect losses and reputational damage.

The cost of a cyber attack

Trustwave's report reveals that the average data breach costs a firm US$6.08m. This is only second to the healthcare industry.

Stringent regulations such as the European Union's Digital Operational Resilience Act (DORA), to be enforced from 2025, will mandate robust cybersecurity measures and continuous resilience testing. This regulatory landscape extends globally, with jurisdictions like the US and Australia already imposing their own rigorous cybersecurity requirements.

Equally, as digital currencies gain legitimacy and integrate into traditional banking systems, new cybersecurity challenges emerge. Financial institutions are now faced with developing robust protection mechanisms for digital assets, and educating consumers on best practices for managing their cryptocurrency holdings, such as using cold storage or crypto wallets.

The path forward

Cyber threats are preventing financial service providers from planning ahead. A 2024 study from law firm Mayer Brown revealed that nearly eight in 10 leaders of financial services firms are unable to plan for the future due to concerns about their organisation's ability to withstand cyberattacks.

While the challenges are significant, there is hope on the horizon. The Trustwave report recommends several mitigation strategies, including:

  • Implementing advanced email filters with machine learning to detect anomalies
  • Conducting regular security audits and phishing simulations
  • Engaging in industry collaborations to stay updated on emerging phishing trends
  • Implementing hardware-based authentication to prevent MFA bypass attacks

The IMF advises firms strengthen their cybersecurity capacity through stress testing and information-sharing arrangements, among other methods. It also calls on authorities to develop national cybersecurity strategies that are adequate, appropriate and accompanied by regulatory frameworks.

As the correlation between the strength of a firm’s cybersecurity and its growth becomes more apparent, financial firms must adapt or feel the pressure of attackers and regulatory auditors.