65% of Financial Organizations Targeted by Ransomware as Cybercriminals Escalate Attacks
The financial sector continues to be a significant target for cybercriminals, protecting both large amounts of money and sensitive personal data.
The financial sector continues to be a significant target for cybercriminals, protecting both large amounts of money and sensitive personal data.
In 2024, 65% of financial organizations were affected by ransomware, representing the highest rate across various industries. The average recovery cost, excluding ransom payments, was $2.73 million.
Cyberattacks on banks, insurers, and fintech firms, primarily fueled by phishing, ransomware, and data theft, have intensified. Analysis indicates that 90% of these attacks originate from phishing, highlighting the necessity for rapid behavioral insights from platforms like ANY.RUN, utilized by over 15,000 organizations.
Despite increased security investments, nearly one-third of attacks bypass traditional defenses. The prevention efficacy is reported to be between 62-69% according to Picus Security. In 2024, underground markets listed 14.5 million stolen credit cards, a 20% increase from the previous year, which escalates the risks to transactional integrity.
These trends result in operational downtime, regulatory penalties, and reduced customer confidence, with even minor detection delays proving costly.
The financial sector continues to be a significant target for cybercriminals, protecting both large amounts of money and sensitive personal data.
Traditional Security Operations Centers (SOCs) in the financial sector deploy SIEM, EDR, and email gateways. However, they often face challenges such as alert fatigue and delayed threat visibility. Analysts spend significant time cross-referencing Indicators of Compromise (IOCs), with threat intelligence frequently arriving post-incident, prolonging response times and increasing costs.
ANY.RUN provides Threat Intelligence solutions that address these challenges by offering sandbox-powered feeds and lookups for proactive defense. Threat Intelligence Feeds provide contextual IOCs—IPs, domains, URLs—that integrate seamlessly into SIEM/SOAR systems via APIs and STIX/TAXII, leading to a 36% increase in detection rates, reduced false positives, and faster triage.
Threat Intelligence Lookup gives instant verdicts on over 40 IOC types, reducing Mean Time to Response (MTTR) by 21 minutes. For example, querying specific domains can reveal ties to active threats, facilitating real-time threat hunting.
Integrating ANY.RUN’s solutions can shift SOCs from a reactive stance to proactive threat hunting, improving rules and coverage before alerts are triggered. This integration aids in reducing breach probabilities, ensuring compliance with PCI DSS and DORA, and achieving operational efficiencies and cost savings.
ANY.RUN's ecosystem, including malware sandboxes for Windows, Linux, and Android, supports analysts worldwide in maintaining robust security postures, proving the value of threat intelligence in safeguarding financial operations.
Based on reporting by Cyber Security News.
