CTI Report

Finance & Insurance : State of the cyber threat in 2026

The banking, finance, and insurance sector concentrates the bulk of global financial flows, the most sensitive personal data, and a growing dependence on a small number of shared service providers.

This 2026 edition documents a structural shift in the threat: less toward direct system compromise and more toward the exploitation of identities, third parties, and devices that institutions no longer fully control. This report provides quantified insight into the nature and cost of cyber risk for banks and insurers in 2025 and 2026, on a global scale.

Download the report

They trust us

Allianz
Capgemini
Groupe Rocher
Lagardère
Relyens
Unéo
Allianz
Capgemini
Groupe Rocher
Lagardère
Relyens
Unéo
Allianz
Capgemini
Groupe Rocher
Lagardère
Relyens
Unéo

Who This Report Is For

This report was designed for CISOs, risk managers, and compliance officers, for executive committees arbitrating security investments, and for cyber insurance brokers and underwriters assessing their clients' exposure.

01

CISOs & Security Leaders

An overview of the threat landscape and bypass techniques to factor into the security roadmap.

02

Risk Managers & Compliance

A mapping of risk scenarios and their documented financial impact.

03

Executive Committees

Quantified benchmarks for arbitrating security investments and governance priorities.

04

Cyber Insurance Brokers & Underwriters

Elements for assessing sectoral exposure to support pricing and client advisory.

The report draws on an annual, global database of documented incidents.

Threat Trends 2025-2026

Our CTI team analyzed how this exposure has concretely materialized for banks and insurers. Data exfiltration, fraud, espionage, extortion, sabotage: the report covers eight scenario families and the full range of threat actor profiles, from organized cybercriminals to state operators. This edition highlights four trends that structure these scenarios:

01

Third-Party Providers & Value Chain

Shared service providers whose compromise extends the impact well beyond the entity initially affected.

02

Artificial Intelligence

Offensive AI progressively shifting from assistance to the direct execution of operations.

03

Mobile Fraud

Mobile fraud spreading into Western Europe as tools become commercialized and professionalized.

04

Authentication

MFA mechanisms put to the test by increasingly convergent bypass techniques.

Third-Party Providers & Value Chain

The Change in Scale, Measured Incident by Incident

Four provider compromises, four techniques that bypass MFA, one data exploitation case, and one fraud case account on their own for nearly half of the incidents recorded over the period. The report reconstructs each shift through the incident that documents it: Marquis and its 74 U.S. banks, C&M Software and the $100 million diverted through the Brazilian PIX ecosystem, each told for what it reveals, not just for its scale.
74

U.S. banks exposed via Marquis Software Solutions

$100M

Diverted through C&M Software on Brazil's PIX ecosystem

4

Providers compromised, four distinct propagation patterns

Artificial Intelligence

Offensive AI at Two Levels of Maturity

Offensive AI is advancing at two very different speeds, and most industry commentary conflates them. On one hand, an already established practice: lure generation, code adaptation, and the piloting of criminal platforms, documented across dozens of campaigns. On the other, the OpenAI/Hugging Face incident of July 2026, an assessment conducted under particular conditions, which demonstrates a technical capability without demonstrating malicious use against the financial sector. The report treats both with the level of evidence they deserve, which is not the same.

Identity & Authentication

MFA Put to the Test by New Bypass Techniques

MFA remains necessary, but the report documents four techniques that bypass it today, from session hijacking to OTP interception. Three additional layers, phishing-resistant factors, behavioral detection, and independent verification of sensitive transactions, make it reliable again. Mobile fraud raises a related question: once the transaction is launched from the customer's genuine device, location and device recognition have little left to flag.For an organization, the question is therefore no longer just whether to activate MFA, but which of these three layers to add first to reduce its actual exposure, the one that corresponds to its most likely fraud channels.

Mobile Fraud

A Commercialization That Is Professionalizing the Threat

What has so far confined mobile fraud to Latin America and Southeast Asia was the cost of entry: a tool had to be developed or adapted for each market. NFCShare, originally designed to target Deutsche Bank, is now sold as a service and redeployed against Italian and other European institutions; Supercard X offers the same contactless payment relay for rent. Custom development is becoming a subscription, and the most recent families no longer settle for stealing credentials or intercepting SMS messages: Herodotus, which emerged in late 2025, reproduces the rhythm of genuine human interaction to defeat behavioral detection. Mobile banking fraud is not slowing down, it is professionalizing, both in its distribution and in its techniques.

Six Questions on the Report “The State of Cyber Threats in the Finance & Insurance Sector”

DORA now treats third-party dependency as a distinct component of operational risk. The recurrence of this scenario over the next 12 to 18 months is rated highly likely.

Four distinct techniques converge on the same target, an authenticated session. Phishing-resistant authentication factors, behavioral detection, and independent verification of sensitive transactions: these three layers must surround MFA for it to be effective.

Volume of sensitive data, dependency on providers for client management, call centers that have become identity administration points: three structural features of the insurance business place identity verification under pressure that banking does not experience in the same way.

When the fraudulent transaction is executed directly from the customer's compromised device, the IP address, the device, and the session context remain consistent with the usual profile: controls based on location or device recognition detect nothing abnormal. One family, Herodotus, goes further by reproducing the rhythm of genuine human interaction, specifically to defeat behavioral detection.

Two access routes, both built on ordinary professional relationships, and a compliance question that does not fall to the security team.

AI-generated lures and AI-assisted code adaptation are already common practice, documented across numerous campaigns. Autonomous execution of a full intrusion, by contrast, currently rests on only one documented case, under assessment conditions that limit what can be drawn from it.

Get Started Now

What You Read Here, the Citalid Platform Quantifies

Access Our Report Now

35 pages tracing how risk has moved outside the systems that banks and insurers directly control, from provider compromises to identity abuse, to a threat landscape reshaped by AI.

Download the report