Security1 publisher2 min readPublished
Both banks Everest named in April traced the breach to a third-party vendor
Intel 471's 18-month sweep of the underground counted 340 financial-sector extortion victims across 74 countries, 159 firms with access for sale and 562 claimed DDoS attacks. The dated intrusions came in through vendors and help-desk calls.
The Watch · Security desk

What happened
- Intel 471 published a financial-sector threat report drawn from closed forums, data leak sites, marketplaces, Telegram groups and human intelligence engagements between January 2025 and June 2026.
- Extortion groups hit 340 financial services victims across 74 countries during the window, with the United States, United Kingdom and Canada taking the largest share.
- Everest claimed two U.S. banks in April 2026, and both banks confirmed the breach originated at a third-party vendor and not from direct access to their own networks.
- BlackFile posed as IT support at U.S. hedge funds and steered staff to pages imitating Okta or Microsoft 365 that captured credentials, session tokens and MFA codes for cloud access.
- Hacktivists claimed 562 DDoS attacks against the financial sector over the same period, led by NoName057(16) and Dark Storm Team.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Both confirmed bank compromises started outside the banks' own estates, so control coverage inside a bank does not measure its exposure. Vendor inventory and contract review carry the part that perimeter spending cannot reach.
- constraint The phishing pages harvested session tokens and MFA codes, which are produced after the second factor is satisfied. Enrolling stronger MFA does not close that route; the detection has to sit on session reuse and cloud sign-in behaviour.
- contradiction Intel 471 leads with a packaged fraud chain of stolen identities, forged documents and mules, but the counts it published measure corporate intrusion. A budget case built on the released numbers argues for vendor and credential work.
The window is 18 months, January 2025 through June 2026 [16]. Spread the 340 extortion victims across it and the sector absorbed about 19 published victims a month [17]. The DDoS claims run higher: 562 over the same period, roughly 31 a month [18]. Intel 471 ties those campaigns to the Russia-Ukraine conflict and to tensions in the Middle East, with groups framing bank disruption as a blow against the countries they oppose [12]. On the extortion side the most prevalent groups were Qilin, Akira and The Gentlemen, and the worst-hit subsectors were insurance, investment management, and banking and securities [3].
The access market is the other supply line. Brokers advertised unauthorized access affecting 159 financial services entities [9]. About 60 of those were offered as compromised VPN credentials, roughly 38 percent of the entities listed [10][19]. One listing offered RDP and shell access to a South Africa-based financial institution [10].
CLOP claimed a U.K.-based payments and commerce services company on Jan. 21, 2026 [7]. No mechanism is stated for that intrusion. Intel 471 says the group has previously exploited vulnerabilities in widely deployed, centralized enterprise products, and that this creates a supply-chain-like concentration effect across downstream customers [8]. Its summary of how extortion actors got in names third-party exposure, supply chain compromise, credential phishing and the credential and access market [15].
The report's own framing leads elsewhere. It opens on an AI voice agent posing as a bank's IT desk, stolen identities packaged with financial profiles, document forgery services with mules to complete verification, and a $1.5 billion crypto heist carried out by a nation-state threat group [13]. Those consumer-facing services sit in a separate category in the report, alongside payment fraud, automated carding, banking trojans, phishing-as-a-service, AI-enabled document forgery and verification bypass, and identity theft [14].
No listing volumes, prices or vendor names accompany that fraud chain in the published summary [20]. Every number Intel 471 put on the page counts corporate intrusion: 340 victims, 159 brokered accesses, 562 DDoS claims [2][9][11]. Intel 471 says the full report covers the fraud services in detail [14]. A defender arguing to move money toward identity proofing and voice verification will have to take the figures from there, because the ones released describe vendors, credentials and help-desk calls.
What to watch
- Identification of the shared vendor behind both Everest bank claims would move the incident count from two banks to one supplier.
- Whether BlackFile's IT-support impersonation moves from hedge funds and investment managers to retail bank support lines.
- Whether Intel 471 releases listing volumes or prices for the identity, forgery and mule bundles its summary describes.