Critical Infrastructure at Risk: Financial Systems

Critical Infrastructure at Risk: Financial Systems

Bottom Line Up Front (BLUF)

One vendor breach exposed 1.35 million customers across 74 banks. The NY Fed says an attack on one top-5 bank could disrupt 38% of the network. The final chapter in our Critical Infrastructure series.

Key Judgments

  • [CONFIRMED] – Financial-sector cyber incidents rose 76% in Q1 2026 alone compared to Q1 2025, per Black Kite’s 2026 Financial Services Report, continuing a trend CrowdStrike separately measured as a 109% increase in targeted intrusion attempts against the sector in 2024. The number of distinct threat groups actively targeting financial institutions grew from 37 to 48 over the same period.
  • [CONFIRMED] – Unlike the physical-disruption risk examined in this series’ prior installments, the financial sector’s dominant vulnerability runs through third-party vendors rather than direct institutional compromise: the 2025 Marquis Software breach – a single compromised vendor – exposed 1.35 million customers across more than 74 US financial institutions, and a separate single compromised managed service provider cascaded into breaches at 32 financial institutions and more than 2 terabytes of stolen data. Black Kite’s tracking finds 76 of 140 core finance-sector vendors carry at least one CISA-listed known-exploited vulnerability, and 109 of 140 have critical-level patch management failures.
  • [CONFIRMED] – The Federal Reserve Bank of New York has formally modeled systemic interconnection risk specific to this sector in a way no other sector in this series has been subject to: its analysis found that a successful attack on just one of the five largest US banks could disrupt as much as 38% of the entire US financial network, reflecting the density of interbank and counterparty relationships underlying the system.
  • [CONFIRMED] – Business email compromise remains the highest-volume fraud vector by dollar loss: the FBI’s Internet Crime Complaint Center recorded $2.9 billion in BEC losses in 2024, with wire fraud the dominant method – a threat distinct from the systemic/vendor-compromise risk examined above, targeting individual transactions rather than institutional infrastructure directly.
  • [ASSESSED] – CommandEleven Intelligence assesses the financial sector offers this series’ clearest evidence that coordinated law enforcement action can meaningfully suppress a specific threat actor’s capability: the FBI’s December 2023 dismantlement of the ALPHV/BlackCat ransomware group and the February 2024 “Operation Cronos” seizure of LockBit’s infrastructure together drove documented finance-sector ransomware incidents from those two groups down from 61 in 2023 to 16 in 2024 – even as other groups, including Qilin (59 confirmed finance-sector victims by 2025), moved to fill the resulting gap.

The Threat Surface: Uniquely Interconnected, Uniquely Modeled

The Threat Surface: Uniquely Interconnected, Uniquely Modeled

The financial sector differs from every other sector examined in this series in one structural respect: its interconnection risk has been formally, quantitatively modeled by a government body, rather than remaining a matter of general assessment. The Federal Reserve Bank of New York’s finding – that a successful attack on just one of the five largest US banks could disrupt up to 38% of the entire national financial network – reflects the density of interbank lending, clearing, and counterparty relationships that make banking fundamentally more interconnected than water, electricity, or gas utilities, which despite their own fragmentation (documented in this series’ prior installments) generally operate with more geographic and operational independence from one another. This dossier treats that modeled interconnection figure as the single most important structural fact distinguishing financial-sector risk from the rest of this series.

The Supply Chain Is the Real Vulnerability

Where water security concentrated on exposed industrial controls and communications concentrated on a single dominant nation-state campaign, financial-sector risk concentrates on the vendor ecosystem underlying the industry. The 2025 Marquis Software breach illustrates the pattern with unusual clarity: a single third-party software provider’s compromise exposed 1.35 million customer records across more than 74 separate US financial institutions – none of which were themselves directly breached. A separate documented case saw a single compromised managed service provider cascade into confirmed breaches at 32 financial institutions, with attackers exfiltrating more than 2 terabytes of data before detection. Black Kite’s sector-wide vendor assessment finds this is not an isolated pattern: 76 of the 140 core vendors financial institutions rely on – cloud providers, payment processors, core banking platforms – carry at least one CISA Known Exploited Vulnerabilities-listed flaw, and 109 of 140 show critical-level patch management failures. IBM’s X-Force Threat Intelligence Index attributes 36% of finance-sector intrusions specifically to exploitation of internet-facing applications, a category that substantially overlaps with this vendor-ecosystem exposure.

  • [ASSESSED] – CommandEleven Intelligence assesses this vendor-concentration risk is analytically similar to the “manufacturing plain” resilience pattern this dossier’s companion Iran War Doctrine series identified in a different context – except inverted. Where a decentralized adversary network is difficult to eliminate because no single node matters enough to justify the effort, the financial sector’s small number of shared, load-bearing vendors means a single compromised node can cascade disproportionately across dozens of otherwise-independent institutions, the opposite resilience profile.

Who’s Targeting Finance: State Actors and Criminal Enterprises Together

Financial-sector targeting draws both state-sponsored and purely criminal actors, often using comparable technical sophistication toward different objectives. North Korea’s Lazarus Group has conducted a sustained, multi-year campaign of bank heists and cryptocurrency theft against US and global financial institutions, using advanced social engineering (including recruitment-themed spear-phishing targeting fintech personnel specifically), zero-day exploit chains, and multi-stage malware – with theft proceeds assessed as a direct revenue source for the North Korean state rather than conventional espionage. FIN7, an Eastern Europe-based criminal group, has separately built a persistent presence targeting US financial services through weaponized Office documents and the custom CARBANAK backdoor, focusing on point-of-sale systems and banking infrastructure to extract data and execute fraudulent transactions directly.

Business email compromise operates as a distinct, high-volume threat orthogonal to both: the FBI’s $2.9 billion 2024 loss figure reflects a fraud pattern – impersonation-based wire transfer manipulation – that requires no infrastructure compromise at all, only successful social engineering against an individual employee with transaction authority.[DATA DEFICIT] This dossier does not have a reliable breakdown of what share of 2024 BEC losses specifically targeted financial institutions themselves versus institutions’ corporate customers; the $2.9 billion figure is sector-agnostic FBI reporting rather than finance-sector-specific.

The Success Story: What Enforcement Can Actually Do

The Success Story: What Enforcement Can Actually Do

This dossier’s review of the financial sector surfaces a genuinely positive data point largely absent from this series’ prior installments: coordinated law enforcement action against ransomware infrastructure has produced measurable results. The FBI’s December 2023 dismantlement of the ALPHV/BlackCat group and the February 2024 multinational “Operation Cronos” seizure of LockBit’s infrastructure together drove finance-sector ransomware incidents attributable to those two groups down from 61 in 2023 to just 16 in 2024 – a genuine, quantified enforcement success rather than an assessed or aspirational one.

  • [ASSESSED] – CommandEleven Intelligence assesses this success is real but partial rather than durable: the overall count of distinct groups targeting the finance sector grew from 37 to 48 over roughly the same period, and Qilin – a group that had limited prominence before ALPHV/BlackCat and LockBit’s disruption – had independently claimed 59 finance-sector victims by 2025, suggesting displaced criminal capacity migrated to new groups rather than exiting the ecosystem. This dossier treats the ALPHV/LockBit enforcement actions as evidence that targeted infrastructure seizure is a genuinely effective tool against a specific group, while noting it does not appear to have reduced the sector’s aggregate threat exposure once newer entrants are accounted for.

Government and Industry Response

The Bank Policy Institute – representing the sector’s largest institutions – has publicly characterized global cybercrime as a “$10 trillion tax on the global economy” and endorsed reauthorization of cyber threat information-sharing legislation as a policy priority, alongside continued engagement with the 2026 National Cybersecurity Strategy. Regulatory reporting requirements administered through the SEC and the Federal Financial Institutions Examination Council (FFIEC) create mandatory disclosure obligations for material cyber incidents affecting financial institutions – a regulatory posture with real teeth relative to some sectors examined earlier in this series, though this dossier’s sourcing does not indicate these requirements have kept pace with the vendor-ecosystem risk documented, since third-party vendor compromises can affect an institution’s customers without necessarily triggering the same disclosure threshold as a direct institutional breach.

Assessment

[ASSESSED] – The financial sector’s risk profile is distinguished from every other sector examined in this series by two structural features: government-modeled systemic interconnection risk that has no clear parallel in water, grid, gas, or communications infrastructure, and a threat landscape concentrated overwhelmingly in the vendor ecosystem rather than in direct institutional compromise. Where this series’ prior installments generally found risk concentrated in either a dominant technical vector (water’s exposed PLCs) or a dominant single actor (communications’ Salt Typhoon), financial-sector risk is genuinely diffuse – state actors, criminal enterprises, and vendor-ecosystem fragility all contribute independently, with the NY Fed’s 38% interconnection finding as the clearest evidence that this diffuse risk nonetheless carries real systemic concentration at the very top of the sector.

Series Continuity

This is the final sector-specific installment in this series. A closing synthesis piece will draw together the throughlines across all five sectors examined – water, electricity, natural gas, communications, and finance – including the recurring patterns of fragmented ownership, vendor/supply-chain concentration, and the consistent presence of the same small set of state-linked actors (China’s Volt Typhoon and Salt Typhoon, Iran-linked water-sector targeting) across sectors this series treated individually.

CONFIRMED – Primary/Official Record & Direct Reporting:

ASSESSED – Credible Secondary Reporting:

Excluded from this dossier: Specific technical detail on exploitation methodology for any named vulnerability, vendor, or malware family beyond what is necessary to establish the general threat pattern. This dossier treats such detail as unsuitable for public release.

Protecting Your Household’s Financial Security: A $500 Baseline

This section is general personal-finance security guidance, modeled on standard FTC and CFPB public recommendations. It is not specific to any threat actor or incident, and does not depend on or respond to classified or sensitive information.

  • Credit freezes at all three bureaus (≈$0): Freezing credit with Equifax, Experian, and TransUnion is free by law and is the single highest-value action against identity theft resulting from any financial-sector data breach – it can be temporarily lifted whenever you need to apply for credit.
  • Hardware security key for banking/email (≈$25-50 per device): A physical security key provides stronger protection against phishing-based account takeover than SMS-based two-factor authentication, which remains vulnerable to the kind of interception this series’ Communications installment examined.
  • A small emergency cash reserve (≈$200-300, held as cash): Not an investment recommendation – simply a hedge against a scenario where a banking outage or fraud freeze temporarily restricts access to your primary accounts, consistent with FEMA and CFPB general emergency-preparedness guidance.
  • Transaction alerts enabled on every account (≈$0): Real-time text or app alerts for any transaction let you catch fraudulent activity within minutes rather than at your next statement review.
  • Know your bank’s fraud-reporting process in advance: Save your bank’s fraud department number separately from your regular banking app access, since a compromised phone or account may limit your ability to look it up during an actual incident.

CommandEleven Intelligence is not a licensed financial advisor; this guidance reflects publicly available FTC/CFPB recommendations and general good practice, not a CommandEleven Intelligence-specific assessment of any household’s individual financial risk.

The Critical Infrastructure at Risk Series

Linked Entities

Operational Theater

Area of Responsibility Map