
By Endurance Advisory and Summit Financial Group
The financial services industry, encompassing banks, credit unions, investment firms, insurance providers, and fintech companies, continues to face growing cyber risks in 2025. According to IBM's Cost of a Data Breach Report, the industry experienced thousands of breaches globally, with an average cost of $4.88 million per incident, significantly higher than the global average. These threats are intensified by the proliferation of digital banking and digital assets, which expand attack surfaces and introduce novel vulnerabilities. Endurance Advisory and Summit Financial Group have partnered to offer joint assessments, expert advisory, troubleshooting, and customized insurance solutions, helping institutions build a unified approach to cybersecurity.
Ransomware attacks. Ransomware incidents in finance surged by 126 percent in the first quarter of 2025. While attacks remain prevalent, total ransom payments decreased by 35 percent year over year to approximately $813 million in 2024, with only about 28 percent of victims paying. Robust backups and cloud-based redundancy have reduced vulnerability, while AI-enhanced endpoint protection and automated incident response tools enable early detection and isolation.
Phishing and social engineering. Verizon's 2025 Data Breach Investigations Report indicates that phishing contributes to 14 percent of breaches, amplified by AI-generated deepfakes targeting digital banking users. Multi-factor authentication to block credential theft, AI-based email filters for detecting anomalies, and behavioral-analytics-augmented user training are reducing effectiveness. Zero-trust architectures and AI threat detection verify identities and flag suspicious behavior in real time. However, attackers are shifting to targeted social engineering and adversary-in-the-middle tactics that bypass multi-factor authentication.
Insider threats. Intentional or accidental insider actions contribute to around 60 percent of breaches, often exploiting access to digital assets or internal systems. Firms are enhancing training, updating policies on data access and acceptable use, and establishing clear consequences for violations. User access controls, activity monitoring, AI behavioral analytics, and data loss prevention tools are increasingly effective.
Third-party and supply chain risks. Vulnerabilities in vendors caused approximately 35.5 percent of incidents in 2024, including API exploits in embedded financial services, with risks extending to fourth parties in 4.5 percent of breaches. Institutions are increasingly using System and Organization Controls reports and tools like SecurityScorecard to gain visibility into third- and fourth-party ecosystems, assessing vendor security postures and identifying vulnerabilities such as unpatched systems or weak multi-factor authentication.
Heightened risks from digital banking and digital assets. Digital banking has expanded the attack surface, making institutions vulnerable to malware, unauthorized access, and data exfiltration. Fake banking apps distributed via Telegram targeted Android users in March 2025, leading to millions in fraudulent transactions across banks and fintech firms. Digital assets introduce unique threats such as wallet hacks, smart contract vulnerabilities, and DeFi exploits. Cybercriminals stole over $2.47 billion in crypto assets in the first half of 2025.
Ransomware has dominated cyber events in recent years, though payments are declining amid better defenses. Vendor risks have amplified effects across all firm sizes, with global insurers, regional banks, fintech specialists, and credit unions all facing severe threats. Insider and espionage incidents at federal financial regulators are likely to drive stricter regulation, urging enhanced vendor audits and response plans.
For years the FFIEC Cybersecurity Assessment Tool has served as the go-to checklist for banks and credit unions to demonstrate they are managing cybersecurity risks. With the tool set to retire on August 31, 2025, regulators are signaling a critical shift: move beyond static assessments to proactive strategies that anticipate emerging risks. Institutions are encouraged to transition to flexible frameworks like NIST CSF 2.0 for ongoing maturity evaluations.
This regulatory evolution opens the door to more meaningful conversations around risk. It is no longer just about passing an exam. It is about safeguarding customers, reputation, and business continuity when, not if, a cyber event strikes. That is where ongoing risk assessments, managed services, and cyber insurance become indispensable.
In today's mobile and hybrid work environments, devices are often the first line of attack. Financial institutions need more than antivirus. They require visibility into every device around the clock. Managed Detection and Response and Endpoint Detection and Response services provide proactive monitoring, automated response, and expert threat hunting to prevent breaches before they escalate. By leveraging a 24-hour Security Operations Center, institutions can dramatically reduce response times and ensure protection even when internal teams are offline.
Adding this layer of defense helps banks, credit unions, and fintechs detect ransomware, insider threats, and data exfiltration early, minimizing financial and reputational risk. Institutions of all sizes should prioritize endpoint detection as part of their cybersecurity strategy, whether through internal teams or third-party partners.
Breaches are inevitable. Cyber insurance provides a safeguard, covering ransom, legal fees, business interruption, and fines. Joint assessments can lower premiums where controls are demonstrably in place.
Endurance Advisory brings IT advisory and troubleshooting expertise, extending across financial services with end-to-end solutions. Summit Financial Group delivers cyber insurance for digital risks. Working with partners like these helps an institution not just check the box but build real confidence in its digital defenses. Our assessments evaluate governance, strategy, risk mitigation, business continuity and disaster recovery, technical and operational controls, and vendor diligence.
The following incidents span global banks, regional banks, community banks and credit unions, and major vendors. Figures are as reported at the time of publication.
LoanDepot ransomware breach, January 2024. The Alphv, or BlackCat, ransomware group targeted the national mortgage lender from January 3 to 5, compromising names, addresses, financial account numbers, phone numbers, dates of birth, and Social Security numbers. The attack disrupted operations for nearly two weeks and affected 16.9 million individuals.
Prudential Financial ransomware breach, February 2024. Alphv breached the insurer on February 5, exposing names, addresses, driver's license numbers, and other identification. Initially reported as affecting 36,000 individuals, the breach ultimately impacted 2.56 million people and triggered regulatory scrutiny.
FBCS data breach, February 2024. A ransomware attack on Financial Business and Consumer Solutions, a debt collection vendor supporting regional banks, occurred between February 14 and 26, exposing names, addresses, dates of birth, Social Security numbers, and account numbers. It affected 4.2 million people, with delayed notifications causing reputational harm at partner banks.
Santander Bank breach via Snowflake, May 2024. Compromised credentials and absent multi-factor authentication at cloud vendor Snowflake exposed account numbers, credit card information, and employee details, impacting 30 million customers, with stolen data sold on dark web forums.
Evolve Bank and Trust ransomware breach, May 2024, disclosed June 2024. The LockBit group breached the Memphis-based regional bank via a vendor, exposing names, Social Security numbers, account numbers, dates of birth, and contact information for 7.6 million people, and disrupting downstream fintech services.
Patelco Credit Union ransomware attack, June 2024. Ransomware prompted a digital banking shutdown at the California credit union and exposed names, Social Security numbers, driver's licenses, dates of birth, and emails. Initially reported as 500,000 members, it ultimately affected 1 million and led to member lawsuits.
Lafayette Federal Credit Union unauthorized access, September 2024. Unauthorized access at the Maryland credit union compromised member data. The number affected was not disclosed.
Cross Valley Federal Credit Union unauthorized access, December 2024. The Pennsylvania credit union experienced unauthorized system access potentially exposing member personal information. The number affected was not specified.
Randolph-Brooks Federal Credit Union data breach, December 2024. A breach at the San Antonio credit union exposed personal and banking information for over 4,600 customers.
NationsBenefits Holdings data theft, April 2025. The Clop ransomware group exploited Fortra GoAnywhere MFT vulnerabilities at the benefits vendor, stealing protected health and financial data affecting over 3 million individuals.
Via Credit Union unauthorized access, January 2025. Unauthorized access at the Indiana credit union compromised financial data. The number affected was not disclosed.
SogoTrade data breach, May 2025. A breach at the Missouri online brokerage, stemming from credentials compromised in May 2024, exposed names, financial account numbers, Social Security numbers, and tax identification numbers for an unspecified number of clients.
Consumer Financial Protection Bureau data breach, disclosed April 2025. A former employee transferred confidential data on 256,000 consumers and 45 institutions to a personal email account.
Office of the Comptroller of the Currency email espionage, April 2025. Attackers compromised an administrator account and accessed 150,000 sensitive financial institution emails over more than a year, affecting 103 bank regulators.
Espionage surge targeting financial sectors, February 2025. A reported 150 percent increase in state-linked cyber operations, and 300 percent in finance specifically, targeted US banks and vendors using backdoors and cloud services. Exact records affected are unknown.
Coinbase insider incident. Cybercriminals bribed and recruited rogue overseas customer support agents to access internal systems and steal data for 69,461 individuals, beginning as early as December 2024. The stolen data was used in social engineering attacks in which attackers posed as Coinbase representatives. Coinbase estimated a financial impact of $180 million to $400 million, primarily from reimbursements and related costs.