45 Ivan Allen Jr Blvd NW
Atlanta, GA 30308
+1 (888) 808-7330
General: [email protected]
Sales: [email protected]
Support: [email protected]
On 12 November 2025, a company that most people outside mortgage finance have never heard of discovered an intruder in its network. SitusAMC processes loan origination, servicing, and compliance work for residential lenders. Ten days later, it was confirmed that attackers had taken corporate data — accounting records, legal agreements — and that information belonging to its clients' customers may have been taken as well.
The clients included JPMorgan Chase, Citi, and Morgan Stanley. Reporting at the time indicated that more than 100 institutions were potentially affected, and that essentially every large US bank uses the company in some capacity. The FBI got involved. No bank was breached. No banking service went down. It wasn't even ransomware.
That is the shape of the problem now. The institutions themselves have spent a decade and enormous sums making direct compromise expensive. The organizations they hand their data to have not. And the seam between the two is where 2025 and 2026 have been decided.
Three independent datasets tell a consistent story.
Volume is up, and accelerating. Black Kite's 2026 Financial Services report counted 202 ransomware incidents against financial institutions in 2025, up from 156 the year before — a 30% rise that reversed the 2024 dip. That dip was real but temporary: it traced to the FBI's dismantling of ALPHV/BlackCat in December 2023 and Operation Cronos against LockBit in February 2024, which together dropped those two groups from 61 finance-sector incidents in 2023 to 16 in 2024. The operators dispersed rather than retired. By 2025, Qilin alone claimed 59 finance-sector victims, and the number of distinct groups targeting the sector had grown from 37 to 48. Q1 2026 recorded 65 finance incidents, 76% above Q1 2025.
Cost is up. IBM's 2026 Cost of a Data Breach Report, published on 29 July 2026 and covering breaches between March 2025 and February 2026, put the global average at $4.99 million — a record, up 12%. Financial services came in at roughly $6.29 million, second only to healthcare, and the sector absorbed one of the two heaviest concentrations of AI-driven attacks in the study, alongside energy.
The entry point moved. The 2026 Verizon DBIR — its nineteenth edition, covering incidents through October 2025 — found that exploitation of software vulnerabilities accounted for 31% of breaches, up from 20% and overtaking stolen credentials as the leading initial access vector for the first time. Third-party involvement climbed 60% year over year, accounting for 48% of all breaches.
Note what that last figure means in practice: for roughly half of breaches, the failure that mattered happened somewhere other than the victim's own estate.
On 14 August 2025, attackers entered Marquis Software Solutions through a SonicWall firewall. Marquis is a Texas company providing data analytics, CRM, compliance reporting, and marketing services to more than 700 US banks, credit unions, and mortgage lenders. Security researchers have linked the intrusion to Akira exploiting CVE-2024-40766 — a vulnerability disclosed a year earlier — though no group publicly claimed the attack, and the attribution should be read as a researcher assessment rather than a confirmed fact.
The exfiltrated files contained names, addresses, dates of birth, Social Security numbers, Taxpayer Identification Numbers, and financial account details. At least 74 institutions were affected. The victim count has fluctuated as filings accumulated: initial state notifications indicated more than 400,000 individuals, December filings put it above 670,000, and regulatory disclosures reviewed in March 2026 pushed the range to as high as 1.35 million. A breach notification letter from one Iowa credit union indicated that Marquis paid the ransom.
Two details deserve more attention than the headline number.
The first is timing. The intrusion occurred on 14 August. Marquis began notifying client institutions on 27 October. Those institutions were then responsible for notifying their own customers. Consumers with an affected account at a community bank in Maine learned about an August compromise in late autumn, through an institution that had itself only found out weeks earlier.
The second is that this was predictable in the narrow, technical sense. Black Kite reported that its Ransomware Susceptibility Index had flagged Marquis at elevated risk — a score of 0.437 against a finance-vendor average of 0.404 — one month before the attack. That is not a claim that anyone could have known the date. It is claimed that the signal was visible to anyone monitoring continuously, rather than annually.
South Korea recorded zero finance-sector ransomware disclosures in 2023 and zero in 2024. In 2025, it recorded 32, nearly all in a single month.
The campaign, which Qilin branded "Korean Leaks," ran in three waves between mid-September and early October 2025. Bitdefender's analysis found the affiliate had compromised a single domestic managed service provider — reported by Korea JoongAng Daily as GJTec — and used its standing privileged access to move into dozens of downstream firms in parallel. Thirty-three victims were claimed, 28 published, overwhelmingly from asset management companies. Over a million files and more than 2TB of data were exfiltrated. Four victim posts were later removed from the leak site, unusual behavior that suggests successful negotiation.
Bitdefender also noted the possible involvement of North Korea-affiliated actors (Moonstone Sleet), based in part on a leak-site post referencing North Korean interests that was subsequently scrubbed from later listings. Treat that as a plausible hypothesis with public supporting indicators, not a settled attribution.
Strip the geopolitics and the mechanics are mundane: one set of credentials that legitimately reached inside thirty organizations, and no MFA layer between the MSP's access and the client environments.
In late July 2025, TransUnion lost the personal data of 4,461,511 US consumers — names, dates of birth, and unredacted Social Security numbers — through a third-party application that supported its consumer operations. The intrusion happened on 28 July and was discovered on 30 July. ShinyHunters confirmed to BleepingComputer that the incident was part of the wider Salesforce-linked data theft wave that also hit Google, Cisco, Allianz Life, Workday, Qantas, and others, largely via OAuth token abuse against connected applications rather than any flaw in Salesforce itself. The attackers claimed roughly 13 million records in total.
TransUnion's statement that its core credit databases were untouched is accurate and almost beside the point. A credit bureau's crown jewels are not only in the credit file. Four and a half million SSN-plus-DOB-plus-name triples are the exact combination that enables synthetic identity fraud, and they were left through a support tool.
Then in February 2026, French authorities confirmed that around 1.2 million bank accounts had been exposed in the national FICOBA registry — a system tracking close to 300 million accounts belonging to roughly 80 million people — after attackers used credentials stolen from a government official. No exploit. No malware. A valid login.
On 5 May 2026, Community Bank — a Pennsylvania institution operating across Pennsylvania, Ohio, and West Virginia, a subsidiary of CB Financial Services — discovered that an employee had been putting non-public customer information into an unauthorized AI application. Names, dates of birth, Social Security numbers. Two days later, CB Financial determined the incident was material and filed a Form 8-K under Item 1.05.
There was no attacker. There was no operational disruption. Wilson Sonsini's client alert identified it as the first 8-K attributing a material cybersecurity incident to shadow AI, and an American Banker review of the SEC full-text database found the phrase "unauthorized artificial intelligence" appearing in exactly one filing on record. The bank later said it reached the application's vendor in time to prevent the data from being used for model training.
One employee's shortcut triggered three obligations simultaneously: SEC materiality disclosure, 36-hour notification to the bank's prudential regulator, and customer notice under Gramm-Leach-Bliley.
This is not an outlier waiting to become a trend — it is a trend that finally produced a filing. The 2026 DBIR found employee use of unapproved AI tools tripled to 45%. IBM's 2026 report found that shadow AI accounted for 43% of security incidents, more than double the prior year's 20%, with roughly one in five of those resulting in a regulatory fine; close to seven in ten breached organizations had no governance policy for AI use at all. The OCC's March 2026 guidance is unambiguous: banks are accountable for third-party AI tools, regardless of who approved them.
Two economies are running in parallel, and they behave differently.
Ransomware is getting less profitable per incident and more common anyway. The 2026 DBIR found the median ransom payment fell to $139,875 from $150,000, with 69% of victims declining to pay, up from 65%. But finance is an outlier on the demand side — Sophos data cited in 2026 reporting shows record median demand of around $3 million for financial services, 59% of surveyed finance organizations having data successfully encrypted (up from 49%), and data theft accompanying encryption in 31% of cases. Meanwhile, the FBI and CISA reported that Akira had claimed approximately $244 million in proceeds by late September 2025, with observed cases in which exfiltration was completed in just over two hours from initial access.
Direct theft is concentrated and state-run. Chainalysis attributed roughly $2.02 billion in cryptocurrency theft to DPRK-linked actors in 2025 — a 51% increase, about 60% of the global total, and a record 76% of all service compromises. The February 2025 Bybit theft accounted for $1.5 billion of that on its own, the largest single crypto theft on record, attributed by the FBI to the Lazarus cluster it tracks as TraderTraitor. Cumulative DPRK theft since 2017 now sits around $6.75 billion by that lower-bound estimate, and the pattern continued into 2026 with the roughly $292 million KelpDAO exploit in April.
Notably, the sector-wide entry point in most of these cases was not cryptographic. It was people: contractor laptops, IT-worker infiltration, executive impersonation.
Institutions absorbed three regulatory shifts in eighteen months.
NYDFS Part 500 completed its Second Amendment phase-in on 1 November 2025, and the final two provisions are the operationally expensive ones: MFA for any individual accessing any information system, and documented asset inventory programs. The first annual certification covering those requirements was due 15 April 2026 — signed, under the Second Amendment, with personal accountability attached. Days before the deadline, NYDFS issued an industry letter on third-party service provider risk, making clear that covered entities cannot delegate Part 500 obligations to vendors and should contractually require vendor MFA at the same standard. The department then issued prescriptive FAQs on what counts as compliant MFA, warning that push-based and SMS methods are weak.
SEC Item 1.05 turned material incidents into four-business-day public filings, which is how a mid-size Pennsylvania bank's internal AI policy failure became national news.
DORA entered full application in the EU with no grace period remaining, and PCI DSS 4.0.1 requirements likewise landed. For any institution operating across jurisdictions, 2026 is the first year in which all of these are simultaneously enforceable rather than phasing in.
The evidence from these incidents points in a fairly narrow direction.
Treat vendor risk as concentration risk, and map beyond tier one. Marquis and GJTec were both third-party exposures for most affected institutions — nobody's risk register listed "our vendor's MSP." Black Kite found 76 of the 140 vendors, most concentrated in finance, carry at least one CISA KEV-listed vulnerability, and 78% show a critical patch-management failure. That is not theoretical: 57.9% already have phishing infrastructure impersonating them, and 42.1% have employee credentials sitting in stealer logs.
Replace annual reviews with continuous monitoring. Within Black Kite's 140-vendor finance pool, vendors carrying CVSS 9+ vulnerabilities grew from 15 to 73 in twelve months, and confirmed breaches rose from 6 to 39. A vendor that reviewed clean last year is not evidence of anything today.
Extend MFA to the places it usually stops. The Korean Leaks MSP, the FICOBA registry credential, and the OAuth-connected apps in the Salesforce campaign share a category: legitimate access paths that sat outside the MFA perimeter. NYDFS reached the same conclusion from the enforcement side, describing MFA deficiency as the most exploited gap it sees.
Patch the edge on a KEV clock. CVE-2024-40766 was public for a year before it opened Marquis. With vulnerability exploitation now the leading initial access vector and exploit timelines compressing, "in the next maintenance window" is not a control.
Build DLP coverage for generative AI, then write the policy. Most security stacks cannot see an employee paste a spreadsheet into a browser tab. Policy documents that no control enforces are, per the CB Financial case, sufficient grounds for an 8-K rather than a defense against one.
Rehearse vendor-origin incident response specifically. The Marquis timeline left affected institutions with no meaningful window: they learned about an August compromise in late October and inherited both the notification obligation and the customer relationship. Whether your team has ever exercised that scenario is a good proxy for how the next one goes.
Why Organizations Choose Zaxtron
Organizations face increasingly sophisticated ransomware campaigns that exploit unpatched systems, stolen credentials, exposed remote access, and third-party weaknesses. To stay protected, they need actionable intelligence, not just alerts, to identify and reduce cyber risks before disruption occurs. Zaxtron provides Cybersecurity Risk Management, AI Risk Management, and Cyber Threat Intelligence services that deliver continuous visibility and risk-based insights. By combining attack surface intelligence, vulnerability data, threat and breach intelligence, and third-party risk analysis, Zaxtron offers a complete view of cyber exposure. This helps security leaders respond to threats, improve vendor security, and make informed decisions. Contact Zaxtron to strengthen cyber resilience today.
Flagging where the underlying evidence is softer than the prose might suggest:
Cookie preferences