Ransomware Attacks and Vendor Vulnerabilities Surge, Creating Two-Front Cyber Threat for Financial Services
Event summary
- Q1 2026 direct ransomware attacks on financial institutions spiked 76% year-over-year.
- 50.2% of financial services vendors carry high-severity CVEs, with 54% of key vendors having at least one actively exploited vulnerability.
- The number of distinct threat groups targeting finance climbed to 48 in 2025, led by Qilin, Akira, and Kill Security.
- Critical vulnerabilities in vendors serving finance increased 387% from 2024 to 2025.
- 78% of vendors serving finance have critical-level patch management failures.
The big picture
The financial sector is facing a dual threat from both direct ransomware attacks and a surge in vendor vulnerabilities. The dismantlement of major ransomware groups has not reduced the threat but rather rerouted it, with new actors rapidly filling the vacuum. The growing volume of vulnerabilities and the increasing speed of exploitation are creating a structural crisis that requires a shift in how financial institutions manage cyber risk. The ability to continuously identify, prioritize, and respond to critical exposures across both internal environments and third-party relationships is becoming an operational requirement.
What we're watching
- Threat Evolution
- How the reorganization of ransomware groups into smaller, more agile units will impact the financial sector's ability to defend against attacks.
- Vendor Risk Management
- Whether financial institutions can effectively manage the growing volume of vulnerabilities in their vendor ecosystems, especially as regulatory scrutiny increases.
- Cybersecurity Investments
- The pace at which financial institutions will adopt continuous monitoring, predictive analytics, and quantified risk capabilities to stay ahead of evolving threats.
Related topics
