Safeguarding the Financial Services Industry Against Top Cybersecurity Threats in 2025 by Endurance Advisory and Summit Financial Group

By Endurance Advisory and Summit Financial Group

The financial services industry, encompassing banks, credit unions, investment firms, insurance providers, and fintech companies, continues to face growing cyber risks in 2025. According to IBM's Cost of a Data Breach Report, the industry experienced thousands of breaches globally, with an average cost of $4.88 million per incident, significantly higher than the global average. These threats are intensified by the proliferation of digital banking and digital assets, which expand attack surfaces and introduce novel vulnerabilities. Endurance Advisory and Summit Financial Group have partnered to offer joint assessments, expert advisory, troubleshooting, and customized insurance solutions, helping institutions build a unified approach to cybersecurity.

Top cybersecurity threats in financial services

Ransomware attacks. Ransomware incidents in finance surged by 126 percent in the first quarter of 2025. While attacks remain prevalent, total ransom payments decreased by 35 percent year over year to approximately $813 million in 2024, with only about 28 percent of victims paying. Robust backups and cloud-based redundancy have reduced vulnerability, while AI-enhanced endpoint protection and automated incident response tools enable early detection and isolation.

Phishing and social engineering. Verizon's 2025 Data Breach Investigations Report indicates that phishing contributes to 14 percent of breaches, amplified by AI-generated deepfakes targeting digital banking users. Multi-factor authentication to block credential theft, AI-based email filters for detecting anomalies, and behavioral-analytics-augmented user training are reducing effectiveness. Zero-trust architectures and AI threat detection verify identities and flag suspicious behavior in real time. However, attackers are shifting to targeted social engineering and adversary-in-the-middle tactics that bypass multi-factor authentication.

Insider threats. Intentional or accidental insider actions contribute to around 60 percent of breaches, often exploiting access to digital assets or internal systems. Firms are enhancing training, updating policies on data access and acceptable use, and establishing clear consequences for violations. User access controls, activity monitoring, AI behavioral analytics, and data loss prevention tools are increasingly effective.

Third-party and supply chain risks. Vulnerabilities in vendors caused approximately 35.5 percent of incidents in 2024, including API exploits in embedded financial services, with risks extending to fourth parties in 4.5 percent of breaches. Institutions are increasingly using System and Organization Controls reports and tools like SecurityScorecard to gain visibility into third- and fourth-party ecosystems, assessing vendor security postures and identifying vulnerabilities such as unpatched systems or weak multi-factor authentication.

Heightened risks from digital banking and digital assets. Digital banking has expanded the attack surface, making institutions vulnerable to malware, unauthorized access, and data exfiltration. Fake banking apps distributed via Telegram targeted Android users in March 2025, leading to millions in fraudulent transactions across banks and fintech firms. Digital assets introduce unique threats such as wallet hacks, smart contract vulnerabilities, and DeFi exploits. Cybercriminals stole over $2.47 billion in crypto assets in the first half of 2025.

Key trends and consequences

Ransomware has dominated cyber events in recent years, though payments are declining amid better defenses. Vendor risks have amplified effects across all firm sizes, with global insurers, regional banks, fintech specialists, and credit unions all facing severe threats. Insider and espionage incidents at federal financial regulators are likely to drive stricter regulation, urging enhanced vendor audits and response plans.

Evolving regulatory guidelines and the retirement of the FFIEC CAT

For years the FFIEC Cybersecurity Assessment Tool has served as the go-to checklist for banks and credit unions to demonstrate they are managing cybersecurity risks. With the tool set to retire on August 31, 2025, regulators are signaling a critical shift: move beyond static assessments to proactive strategies that anticipate emerging risks. Institutions are encouraged to transition to flexible frameworks like NIST CSF 2.0 for ongoing maturity evaluations.

This regulatory evolution opens the door to more meaningful conversations around risk. It is no longer just about passing an exam. It is about safeguarding customers, reputation, and business continuity when, not if, a cyber event strikes. That is where ongoing risk assessments, managed services, and cyber insurance become indispensable.

Endpoint protection and active monitoring

In today's mobile and hybrid work environments, devices are often the first line of attack. Financial institutions need more than antivirus. They require visibility into every device around the clock. Managed Detection and Response and Endpoint Detection and Response services provide proactive monitoring, automated response, and expert threat hunting to prevent breaches before they escalate. By leveraging a 24-hour Security Operations Center, institutions can dramatically reduce response times and ensure protection even when internal teams are offline.

Adding this layer of defense helps banks, credit unions, and fintechs detect ransomware, insider threats, and data exfiltration early, minimizing financial and reputational risk. Institutions of all sizes should prioritize endpoint detection as part of their cybersecurity strategy, whether through internal teams or third-party partners.

The role of commercial cyber insurance

Breaches are inevitable. Cyber insurance provides a safeguard, covering ransom, legal fees, business interruption, and fines. Joint assessments can lower premiums where controls are demonstrably in place.

Partnering for resilience

Endurance Advisory brings IT advisory and troubleshooting expertise, extending across financial services with end-to-end solutions. Summit Financial Group delivers cyber insurance for digital risks. Working with partners like these helps an institution not just check the box but build real confidence in its digital defenses. Our assessments evaluate governance, strategy, risk mitigation, business continuity and disaster recovery, technical and operational controls, and vendor diligence.

Major cybersecurity events in US financial services, 2024 to 2025

The following incidents span global banks, regional banks, community banks and credit unions, and major vendors. Figures are as reported at the time of publication.

LoanDepot ransomware breach, January 2024. The Alphv, or BlackCat, ransomware group targeted the national mortgage lender from January 3 to 5, compromising names, addresses, financial account numbers, phone numbers, dates of birth, and Social Security numbers. The attack disrupted operations for nearly two weeks and affected 16.9 million individuals.

Prudential Financial ransomware breach, February 2024. Alphv breached the insurer on February 5, exposing names, addresses, driver's license numbers, and other identification. Initially reported as affecting 36,000 individuals, the breach ultimately impacted 2.56 million people and triggered regulatory scrutiny.

FBCS data breach, February 2024. A ransomware attack on Financial Business and Consumer Solutions, a debt collection vendor supporting regional banks, occurred between February 14 and 26, exposing names, addresses, dates of birth, Social Security numbers, and account numbers. It affected 4.2 million people, with delayed notifications causing reputational harm at partner banks.

Santander Bank breach via Snowflake, May 2024. Compromised credentials and absent multi-factor authentication at cloud vendor Snowflake exposed account numbers, credit card information, and employee details, impacting 30 million customers, with stolen data sold on dark web forums.

Evolve Bank and Trust ransomware breach, May 2024, disclosed June 2024. The LockBit group breached the Memphis-based regional bank via a vendor, exposing names, Social Security numbers, account numbers, dates of birth, and contact information for 7.6 million people, and disrupting downstream fintech services.

Patelco Credit Union ransomware attack, June 2024. Ransomware prompted a digital banking shutdown at the California credit union and exposed names, Social Security numbers, driver's licenses, dates of birth, and emails. Initially reported as 500,000 members, it ultimately affected 1 million and led to member lawsuits.

Lafayette Federal Credit Union unauthorized access, September 2024. Unauthorized access at the Maryland credit union compromised member data. The number affected was not disclosed.

Cross Valley Federal Credit Union unauthorized access, December 2024. The Pennsylvania credit union experienced unauthorized system access potentially exposing member personal information. The number affected was not specified.

Randolph-Brooks Federal Credit Union data breach, December 2024. A breach at the San Antonio credit union exposed personal and banking information for over 4,600 customers.

NationsBenefits Holdings data theft, April 2025. The Clop ransomware group exploited Fortra GoAnywhere MFT vulnerabilities at the benefits vendor, stealing protected health and financial data affecting over 3 million individuals.

Via Credit Union unauthorized access, January 2025. Unauthorized access at the Indiana credit union compromised financial data. The number affected was not disclosed.

SogoTrade data breach, May 2025. A breach at the Missouri online brokerage, stemming from credentials compromised in May 2024, exposed names, financial account numbers, Social Security numbers, and tax identification numbers for an unspecified number of clients.

Consumer Financial Protection Bureau data breach, disclosed April 2025. A former employee transferred confidential data on 256,000 consumers and 45 institutions to a personal email account.

Office of the Comptroller of the Currency email espionage, April 2025. Attackers compromised an administrator account and accessed 150,000 sensitive financial institution emails over more than a year, affecting 103 bank regulators.

Espionage surge targeting financial sectors, February 2025. A reported 150 percent increase in state-linked cyber operations, and 300 percent in finance specifically, targeted US banks and vendors using backdoors and cloud services. Exact records affected are unknown.

Coinbase insider incident. Cybercriminals bribed and recruited rogue overseas customer support agents to access internal systems and steal data for 69,461 individuals, beginning as early as December 2024. The stolen data was used in social engineering attacks in which attackers posed as Coinbase representatives. Coinbase estimated a financial impact of $180 million to $400 million, primarily from reimbursements and related costs.

More insights

General
Article

What the Iran Conflict Taught Business Leaders

The February 2026 US-Israel operation, read through Kagan, Kissinger, Toll & Ferguson. What it teaches business leaders about diplomacy, decision speed & institutional resilience.

Digital & AI
Article

What a Mathematician, an Aerospace Engineer, and a Mechanical Engineer Taught Me About Governing AI

Lessons from a mathematician, an aerospace engineer & a mechanical engineer on governing what you cannot fully understand, & the posture bank directors need toward AI oversight.

Strategy & Liquidity
Article

Postulate for Global Finance and Geopolitics in 2026

Large dislocations in currency, credit, sovereign debt & digital-asset markets are rarely driven by the scale of an attacker. A 2026 postulate on structural vulnerability & how to assess stability.

General
Article

The Administrative Load: When Systems Drift Away from Value

Healthcare & finance keep adding layers of intermediation between payment & value. A systems view of why complexity accumulates, when it stops serving purpose, & what resilience through alignment looks like.

Risk & Compliance
Article

Three Crises. One Pattern. And We're Watching It Again.

Three credit dislocations across four decades, Texas energy & real estate, the dotcom IPO boom, and today's private-credit market, share one behavioral sequence. Why this one looks familiar.

Strategy & Liquidity
Article

The $2.9 Trillion Bet

How the $2.9 trillion AI data-center buildout is reshaping global capital, construction & the communities absorbing it, and where the $800 billion private-credit opportunity sits.

Digital & AI
Article

The Agentic Trap: Reading Between the Lines of Deloitte's AI Report

Deloitte's 2026 State of AI report reads as inevitable growth. An operator's view of the implementation risk beneath the optimism, from a 40% agentic failure rate to the governance banks need before decisions run autonomously.

Strategy & Liquidity
Article

Key Insights from Apollo's 2026 Outlook

Apollo's 2026 outlook read for financial services: a resilient US economy, a brief stagflationary slowdown, then AI-driven reacceleration, with the consumer-stress, policy & private-markets signals that matter for banks & investors.

Regulatory & Remediation
Article

A Shift Toward Greater Flexibility with Changes to Leveraged Lending Regulatory Guidance

The OCC & FDIC rescinded the 2013 Interagency Guidance on Leveraged Lending on December 5, 2025. What the move to principles-based supervision means for bank participation, private credit & internal risk governance.

General
Article

Surviving the Shadow: My Journey with Cancer and the Power, and Importance, of Early Detection

Stage 3B Hodgkin's lymphoma at 22, in 1984, when there were no records of long-term survival at that stage. A first-person case for early detection and for taking ownership of your own diagnosis.

General
Article

9/11 - A Personal Perspective by Stephen K. Curry

From the 48th floor of 9 West 57th, four miles north. An account of the day, the roll call that ran past midnight, and the colleagues who did not make it home.

Strategy & Liquidity
Article

Liquidity in 2025: A Shifting Landscape for Banks

Deposits are more volatile, more concentrated, and more rate-sensitive than at any point since the 1980s. What examiners now expect on ratios, stress testing, intraday readiness, and collateral.