Learning Objectives:

  • Identify the primary threat actor categories targeting central banks.

  • Analyse the motives, capabilities, and methods of each threat actor type.

  • Understand the role of state-sponsored actors in cyber conflicts and hybrid warfare.

  • Recognise the growing threat from organised cybercriminal groups and insider threats.

2.1 The Spectrum of Threat Actors

The cyber threat landscape facing central banks is characterised by a diverse spectrum of actors with varying motives, capabilities, and methods. Understanding these actors is essential for developing effective defensive strategies. A comprehensive analysis of 84 disclosed cyber attacks on 63 central banks has identified the main attack vectors and vulnerabilities, providing empirical insights into the threat actor landscape .

The primary threat actor categories targeting central banks include:

  • Cybercriminals: Financially motivated actors seeking monetary gain through theft, fraud, or ransomware.

  • State-Sponsored Actors: Nation-states or state-affiliated groups conducting cyber operations for strategic, political, or military purposes.

  • Hacktivists: Ideologically motivated actors seeking to promote political or social causes.

  • Insider Threats: Employees, contractors, or partners who misuse their access for malicious purposes or inadvertently cause security breaches.

2.2 Cybercriminals and Organised Crime

Cybercriminal groups are increasingly sophisticated and well-resourced, operating with business-like structures and leveraging advanced technologies. In 2025, direct ransomware attacks on financial institutions rose 30% from the previous year, with incidents in the first quarter of 2026 up 76% year-on-year . The number of distinct threat groups targeting the financial sector rose from 37 in 2023 to 45 in 2024 and to 48 in 2025, with groups such as Qilin, Akira, and Kill Security leading the list .

The financial sector’s ransomware landscape shifted significantly between 2023 and 2025. In 2023, banks were the main ransomware target, with 71 disclosures compared with 44 for investment firms. By 2025, banking incidents had fallen to 36, while disclosures involving investment firms had climbed to 84, making that segment the most targeted . This shift reflects attackers’ responsiveness to perceived vulnerabilities and the evolving security postures of different financial sub-sectors.

A campaign in South Korea in September 2025 illustrates the scale of modern cybercriminal operations. The Qilin ransomware group compromised a managed service provider, and the breach spread to 32 financial institutions, resulting in the theft of more than 2 terabytes of data . This incident demonstrates the cascading impact that can result from a single successful attack on a third-party provider.

Cybercriminals are also increasingly targeting payment systems and banking infrastructure. Phishing campaigns impersonate multiple payment ecosystems to maximise coverage. In 2025, Mastercard was the most mimicked brand for phishing, accounting for 33.45% of impersonations, while Visa accounted for 20.06% . This reflects the growing focus on widely used banking card networks. The continued presence of American Express (3.87%) and the increasing number of pages mimicking PayPay (11.72%) further highlight attacker experimentation and regional adaptation .

Mobile banking malware attacks grew by 1.5 times in 2025 compared to the previous reporting period, consistent with their growth in 2024, with a sharp surge in the number of unique installation packages . Complementing traditional financial malware, infostealers played a significant role in enabling financial crime both on PCs and mobile devices by harvesting credentials, cookies, and autofill data from browsers and applications, which attackers then used for account takeovers or direct banking fraud . Kaspersky analyses pointed to a surge in infostealer detections (up by 59% globally) .

2.3 State-Sponsored Actors

State-sponsored cyberattacks represent a particularly significant threat to central banks due to their strategic importance and the sophisticated capabilities of the attackers. The ECB has observed that geopolitical threats are increasingly playing out in cyberspace, with a relatively small cluster of countries, often classified as authoritarian regimes, being responsible for the majority of state-sponsored attacks . Such cyberattacks are clearly linked to geopolitical tensions .

State-sponsored actors primarily target state institutions such as governments and ministries, the armed forces, and public administration . Primary targets in critical infrastructures include the telecommunications, energy and financial sectors as well as defence and transport companies . In addition, other companies and social groups are targeted, including activists and political opposition groups and, to a lesser extent, the media and end users .

The motives for state-sponsored cyber activities are diverse, although attacks are aimed predominantly at data theft, potentially linked to espionage . However, and especially in times of open conflict, the goal of sabotage and data destruction is to cause maximum disruption by interfering with an opponent’s military operations or by destabilising civilian life . Disruptive attacks can also be used to exert pressure in the hope of forcing a change in behaviour or political position. As such, some cyberattacks can be a part of influence campaigns around important elections, for instance. In addition, some cyber activities are aimed at expropriation, in particular via ransomware attacks or the theft of crypto-assets .

The geopolitical dimension of cyber threats is particularly relevant to central banks. The ECB has noted that the degree to which countries have used cyberattacks to further their national interests varies greatly, with a relatively small cluster of countries, often classified as authoritarian regimes, being responsible for the majority of state-sponsored attacks . The risks of a cyber incident that could threaten the stability of a central bank are linked to geopolitical tensions.

2.4 Insider Threats

Insider threats are a growing concern for financial institutions. FINMA observed a sharp increase in reports of cyber attacks via supply chains and third parties in 2025, as well as more data thefts by insiders . This trend highlights the importance of an effective framework for insider threat detection and anomaly management .

Insider threats can take various forms:

  • Malicious Insiders: Employees or contractors who intentionally misuse their access for personal gain or to cause harm.

  • Negligent Insiders: Individuals who inadvertently cause security breaches through carelessness or failure to follow procedures.

  • Compromised Insiders: Employees whose credentials have been stolen by external attackers and are being used to access systems.

The Sri Lanka Central Bank case illustrates how governance failures and institutional weaknesses can create opportunities for fraud, even in the absence of a purely technical breach . The committee investigating the $2.5 million cyber fraud found that major foreign debt repayments were historically authorised by a single director without independent review by more senior officials, and officials failed to perform basic verification by checking lender invoices against signed loan agreements before approving payments . These procedural failures, combined with a compromised email system, enabled the fraud to succeed.