CTI Report
Finance & Insurance : State of the cyber threat in 2026
The banking, finance, and insurance sector concentrates the bulk of global financial flows, the most sensitive personal data, and a growing dependence on a small number of shared service providers.
This 2026 edition documents a structural shift in the threat: less toward direct system compromise and more toward the exploitation of identities, third parties, and devices that institutions no longer fully control. This report provides quantified insight into the nature and cost of cyber risk for banks and insurers in 2025 and 2026, on a global scale.


Who This Report Is For
This report was designed for CISOs, risk managers, and compliance officers, for executive committees arbitrating security investments, and for cyber insurance brokers and underwriters assessing their clients' exposure.
01
An overview of the threat landscape and bypass techniques to factor into the security roadmap.
02
A mapping of risk scenarios and their documented financial impact.
03
Quantified benchmarks for arbitrating security investments and governance priorities.
04
Elements for assessing sectoral exposure to support pricing and client advisory.
The report draws on an annual, global database of documented incidents.
Threat Trends 2025-2026
Our CTI team analyzed how this exposure has concretely materialized for banks and insurers. Data exfiltration, fraud, espionage, extortion, sabotage: the report covers eight scenario families and the full range of threat actor profiles, from organized cybercriminals to state operators. This edition highlights four trends that structure these scenarios:
01
Third-Party Providers & Value Chain
Shared service providers whose compromise extends the impact well beyond the entity initially affected.
02
Artificial Intelligence
Offensive AI progressively shifting from assistance to the direct execution of operations.
03
Mobile Fraud
Mobile fraud spreading into Western Europe as tools become commercialized and professionalized.
04
Authentication
MFA mechanisms put to the test by increasingly convergent bypass techniques.

Third-Party Providers & Value Chain
The Change in Scale, Measured Incident by Incident
U.S. banks exposed via Marquis Software Solutions
Diverted through C&M Software on Brazil's PIX ecosystem
Providers compromised, four distinct propagation patterns
Artificial Intelligence
Offensive AI at Two Levels of Maturity
Identity & Authentication
MFA Put to the Test by New Bypass Techniques
Mobile Fraud
A Commercialization That Is Professionalizing the Threat
Six Questions on the Report “The State of Cyber Threats in the Finance & Insurance Sector”
DORA now treats third-party dependency as a distinct component of operational risk. The recurrence of this scenario over the next 12 to 18 months is rated highly likely.
Four distinct techniques converge on the same target, an authenticated session. Phishing-resistant authentication factors, behavioral detection, and independent verification of sensitive transactions: these three layers must surround MFA for it to be effective.
Volume of sensitive data, dependency on providers for client management, call centers that have become identity administration points: three structural features of the insurance business place identity verification under pressure that banking does not experience in the same way.
When the fraudulent transaction is executed directly from the customer's compromised device, the IP address, the device, and the session context remain consistent with the usual profile: controls based on location or device recognition detect nothing abnormal. One family, Herodotus, goes further by reproducing the rhythm of genuine human interaction, specifically to defeat behavioral detection.
Two access routes, both built on ordinary professional relationships, and a compliance question that does not fall to the security team.
AI-generated lures and AI-assisted code adaptation are already common practice, documented across numerous campaigns. Autonomous execution of a full intrusion, by contrast, currently rests on only one documented case, under assessment conditions that limit what can be drawn from it.
Get Started Now
What You Read Here, the Citalid Platform Quantifies
Access Our Report Now
35 pages tracing how risk has moved outside the systems that banks and insurers directly control, from provider compromises to identity abuse, to a threat landscape reshaped by AI.
Download the report









