Learning Objectives:
-
Identify the most common attack vectors used against central banks and financial institutions.
-
Analyse the mechanics of each attack vector and how they are deployed.
-
Understand the evolving sophistication of attack techniques.
-
Recognise the role of identity and credential theft as a primary attack surface.
3.1 Phishing and Social Engineering
Phishing remains one of the most prevalent and effective attack vectors against financial institutions. The 2025 threat landscape is characterised by AI-assisted cloud intrusions, malicious AI-themed extensions, infostealers abusing AI ecosystems, autonomous vulnerability discovery, and AI agent exposure in enterprise environments . AI is no longer just a social engineering enhancer; it is now a direct operational threat vector .
Phishing campaigns are becoming increasingly sophisticated, leveraging generative AI to create more personalised and persuasive messages at scale. As one regulator noted, “AI-enabled scams, phishing can be more personalised and persuasive ‘at scale'” . Frictions to digital banking transactions remain useful to frustrate scammers, but banks must harness AI and strengthen their controls to better defend against more sophisticated tactics .
The scale of phishing activity is significant. Financial malware targeting corporate segments remains a major threat, with the Pure Trojan detected 896,633 times over 2025 globally, with over 64 thousand users attacked . Attackers typically distribute it through targeted emails, using abbreviations of document names, software titles, or other accounting-related keywords in the headers of attached files .
Phishing campaigns are tailored to regional popularity and user engagement, with different brands dominating in different regions. Netflix dominates heavily in the Middle East, Apple leads in APAC, while Spotify ranks first across Europe, LATAM, and Africa . This regional adaptation reflects the sophistication of modern phishing operations and the need for financial institutions to be aware of localised threats.
3.2 Malware and Infostealers
Financial malware remains a persistent threat to central banks and financial institutions. While desktop banking malware attacks have been declining as attackers increasingly focus on mobile vectors, Windows systems remain the primary platform targeted . According to Kaspersky Security Bulletin, overall detections included 1,338,357 banking Trojan attacks globally from November 2024 to October 2025, though this number is declining due to increasing focus on mobile vectors .
Mobile banker attacks grew by 1.5 times in 2025 compared to the previous reporting period, which is consistent with their growth in 2024, and also saw a sharp surge in the number of unique installation packages . This trend reflects the increasing reliance on mobile devices for financial management.
Infostealers play a significant role in enabling financial crime both on PCs and mobile devices by harvesting credentials, cookies, and autofill data from browsers and applications, which attackers then used for account takeovers or direct banking fraud . Kaspersky analyses pointed to a surge in infostealer detections (up by 59% globally) .
Brazilian-origin malware families such as Grandoreiro (part of the Tetrade group) stood out for their constant activity and global reach in 2025 . Despite a major law enforcement disruption in early 2024, Grandoreiro remained active in 2025, re-emerging with updated variants and continuing to operate . Other notable actors included Coyote and emerging families like Maverick, which abused WhatsApp for distribution while maintaining fileless techniques .
Beyond traditional bankers, other Brazilian malware families are worth mentioning, which specifically target relatively new and highly popular regional payment systems. One of the most prominent threats among these is GoPix Trojan focusing on the users of Brazilian Pix payment system . It is also capable of targeting local Boleto payment method, as well as stealing cryptocurrency .
3.3 Ransomware
Ransomware attacks against financial institutions rebounded in 2025 after a temporary easing in 2024, as criminal operators regrouped under new names . Direct ransomware attacks on financial institutions rose 30% in 2025 from the previous year, while incidents in the first quarter of 2026 were up 76% year-on-year .
The dismantling of major ransomware groups such as LockBit and Clop did not reduce the threat over the longer term. Instead, the disruption appears to have scattered operators, who later reappeared under new banners or were replaced by newer entrants . Qilin was one of the most active groups in the sector, with 59 incidents in the finance sector over the past year . The report said the rise of such groups showed how quickly the criminal market could refill gaps left by law enforcement action .
The shift in ransomware attack patterns between 2023 and 2025 reveals important trends. In 2023, banks were the main ransomware target, with 71 disclosures compared with 44 for investment firms. By 2025, banking incidents had fallen to 36, while disclosures involving investment firms had climbed to 84, making that segment the most targeted . This shift underscores the importance of continuous threat assessment and adaptation of defensive strategies.
3.4 Supply Chain Attacks
Software supply chain attacks are increasing and represent a significant vulnerability for central banks. Compromises in package registries, CI/CD pipelines, and developer tokens highlight the fragility of modern development ecosystems . A single compromised package can cascade into credential theft, cloud compromise, malicious code deployment, and customer-facing service disruption .
The financial services sector is particularly exposed to supply chain risks. A study found that 50.2% of vendors serving the sector carry high-severity common vulnerabilities and exposures (CVEs) . The number of critical vulnerabilities across vendors serving the financial sector rose 387% between 2024 and 2025 . Among 140 vendors whose client base is heavily concentrated in financial services, critical vulnerabilities increased 181%, and 54% had at least one vulnerability listed in the US Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalogue .
The Central Bank of Brazil’s experience in 2025 illustrates the severity of supply chain risks. Two prominent cases involved attacks on Sinqia and C&M Software, both Information Technology Service Providers (PSTIs) that connect institutions to systems managed by the Central Bank . The attacks diverted amounts that may have exceeded R$1 billion, although part was recovered . In the regulator’s view, the incidents revealed weaknesses in financial institutions’ controls over risk management related to third-party services .
The exploitation of vulnerabilities has overtaken phishing as the leading initial access route for breaches for the first time in the history of the Verizon Data Breach Investigations Report . This shift underscores the importance of robust patch management and vulnerability assessment capabilities.
3.5 Identity and Credential Theft
Identity is now the primary attack surface, with threats including real-time phishing kits, OAuth device code abuse, infostealer-driven credential harvesting, MFA bypass techniques, and privileged identity compromise . Identity and credential theft remain central to many cyber attacks targeting financial institutions.
The South Korea supply chain incident in September 2025 illustrates the scale of credential theft. The Qilin ransomware group compromised a managed service provider, and the breach spread to 32 financial institutions, resulting in the theft of more than 2 terabytes of data . The attack exploited vulnerabilities in the service provider to gain access to the credentials of multiple institutions.
The FINMA Cyber Risk Monitor has identified that insider threats are a growing concern, with a sharp increase in reports of data thefts by insiders in 2025 . This trend highlights the importance of robust identity governance, including privileged access management and continuous monitoring of user behaviour.