Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • The Security Leadership Issue
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
    • Podcasts
    • Polls
    • Photo Galleries
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityLogical SecuritySecurity & Business ResilienceBanking/Finance/Insurance

Ground truth in the financial threat landscape

By Tom Kellermann
securing the financial sector
August 23, 2021

It should come as no surprise that the pandemic hindered traditional crime groups from conducting business as usual. When the world shut down, criminals were forced to migrate their activities online and collaborate with existing cybercrime cartels, creating a surge in attacks that most organizations were not prepared for. For example, financial institutions saw a 118% increase in destructive attacks from 2020, as they were heavily targeted by the most advanced cybercrime cartels across the globe and their new affiliate networks.

Given the escalation from a modern bank heist to a virtual hostage situation we’ve witnessed over the past year, it is time financial institutions rethink their security posture and defense tactics to stay one step ahead of the adversary. This requires first taking a closer look at the recent evolution of cybercriminals and analyzing today’s most common attacks.

The Evolution of Cybercriminals

The formation of cybercrime cartels over the past few years has also unveiled new levels of organization and sophistication in their tactics. Two prime examples can be seen with the increase in attacks against targeted market strategies and the rise in the manipulation of timestamps, or Chronos attacks. Adversaries are no longer only after the ransom payment that comes as a result of hacking your network because they have discovered your data is now more valuable than your money. In early 2021, financial institutions saw an increase in attacks against targeted market strategies by 51%. Attackers identified that infiltrating a portfolio manager’s personal device allows them to be omniscient and obtain nonpublic market information that can be used to facilitate digital insider trading. Additionally, cybercriminals have found they can avoid detection through the manipulation of time stamps. This calls for a greater level of attention to be paid to the integrity of time, slowing the chance of adversaries altering the value of capital or trades in the future.

The Escalation

Gone are the days of traditional bank heists. Recent data from VMware found financial institutions (FIs) are facing a 38% increase in island hopping attacks, wherein the digital transformation of the institution is commandeered to launch attacks against its customers. FI’s and their customers are increasingly experiencing watering hole and application attacks as well as an increase in attacks that island-hop through the APIs of fintech vendors. The heist is escalating to a hostage situation as banking environments are being hijacked.

What Defenders Can Do

Implementing proactive strategies such as weekly threat hunting can help organizations be prepared for attacks and give security teams a deeper understanding of their threat environment. In addition, employing micro-segmentation and integrating your endpoint protection platform with your network detection and response is imperative in order to reinforce the FI’s security posture against these brazen cybercrime cartels.

The landscape has changed. Cybercrime is evolving and their elegant attacks show no sign of slowing down as the threat surface continues to expand as a result of the anywhere workforce. Leadership must appreciate that cybersecurity is no longer an expense but a functionality of conducting business. Trust and confidence in the safety and soundness of the future of the financial sector will depend on a proactive cybersecurity strategy.

 

KEYWORDS: cyber security cyber security threats Financial Cyber Security financial service security financial services organized crime ransomware

Share This Story

Tom kellermann

Tom Kellermann is the head cybersecurity strategist at VMware Carbon Black. Prior to joining VMware Carbon Black, Tom was the CEO and founder of Strategic Cyber Ventures. In January 2017, Tom was appointed the Wilson Center's Global Fellow for Cyber Policy. Tom previously held the positions of chief cybersecurity officer for Trend Micro, VP of security for Core Security, and deputy CISO for the World Bank Treasury.

Blog Topics

Security Blog

On the Track of OSAC

Blog Roll

Security Industry Association

Security Magazine's Daily News

SIA FREE Email News

SDM Blog

Manage My Account
  • Security eNewsletter & Other eNews Alerts
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Crisis Response Team
    Sponsored byEverbridge

    Automate or Fall Behind – Crisis Response at the Speed of Risk

  • Perimeter security
    Sponsored byAMAROK

    Why Property Security is the New Competitive Advantage

  • Duty of Care
    Sponsored byAMAROK

    Integrating Technology and Physical Security to Advance Duty of Care

Popular Stories

Internal computer parts

Critical Software Vulnerabilities Rose 37% in 2024

Coding

AI Emerges as the Top Concern for Security Leaders

Half open laptop

“Luigi Was Right”: A Look at the Website Sharing Data on More Than 1,000 Executives

Person working on laptop

Governance in the Age of Citizen Developers and AI

Shopping mall

Victoria’s Secret Security Incident Shuts Down Website

2025 Security Benchmark banner

Events

June 24, 2025

Inside a Modern GSOC: How Anthropic Benchmarks Risk Detection Tools for Speed and Accuracy

For today's security teams, making informed decisions in the first moments of a crisis is critical.

August 27, 2025

Risk Mitigation as a Competitive Edge

In today’s volatile environment, a robust risk management strategy isn’t just a requirement—it’s a foundation for organizational resilience. From cyber threats to climate disruptions, the ability to anticipate, withstand, and adapt to disruption is becoming a hallmark of industry leaders.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • eNewsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing