Report

Trust Under Attack: The Growing Cyber Risks Facing Financial Services Organizations

2026 Financial Services Threat Intelligence Report

The average cost of a data breach for financial services organizations reached $5.56 million in 2025 — the second-highest average data breach cost of any industry tracked, behind only healthcare — and total cybercrime losses reported to the FBI grew 26% year-over-year, according to IBM's 2025 Cost of a Data Breach Report and the FBI's 2025 IC3 Annual Report.

Financial services organizations hold vast amounts of sensitive information, including PII and account data on customers, proprietary data about pending deals and transactions, and, in many cases, direct access to the payment infrastructure that moves money itself. Leaked information about an upcoming transaction can be used to move markets or harm a firm's competitive position — and threat actors know it.

Case volume targeting financial services grew 80.3% year over year, according to eSentire's Threat Response Unit (TRU), with techniques such as ClickFix and IT staff impersonation using Microsoft Teams outreach now outranking email-based credential theft as the way attackers first get in.

In our new Financial Services Threat Intelligence Report, eSentire's TRU shares a detailed analysis of threat data from security investigations across our global customer base throughout 2025 and into 2026. Key findings include:

  • ClickFix was the single most common malware delivery vector in the finance sector at 22.1% of cases, running 10.8 points above the cross-industry average.
  • Malware was the leading threat type observed against financial services organizations at roughly 38% of observations, with credential-access account compromise close behind at 35.5%.
  • In 2026 year to date, Microsoft Teams surged to the number one overall initial-access vector at 29.0% of events, with ClickFix close behind at 22.4% — together, these two vectors account for just over half of all finance-sector initial access so far in 2026.

Download the full report to explore the current threat landscape impacting financial services organizations, the most prevalent attack vectors observed by TRU in 2025, and actionable recommendations to help protect against cyberattacks, strengthen defenses, and minimize business disruption.

Download Now

The average cost of a data breach for financial services organizations reached $5.56 million in 2025 — the second-highest average data breach cost of any industry tracked, behind only healthcare — and total cybercrime losses reported to the FBI grew 26% year-over-year, according to IBM's 2025 Cost of a Data Breach Report and the FBI's 2025 IC3 Annual Report.

Financial services organizations hold vast amounts of sensitive information, including PII and account data on customers, proprietary data about pending deals and transactions, and, in many cases, direct access to the payment infrastructure that moves money itself. Leaked information about an upcoming transaction can be used to move markets or harm a firm's competitive position — and threat actors know it.

Case volume targeting financial services grew 80.3% year over year, according to eSentire's Threat Response Unit (TRU), with techniques such as ClickFix and IT staff impersonation using Microsoft Teams outreach now outranking email-based credential theft as the way attackers first get in.

In our new Financial Services Threat Intelligence Report, eSentire's TRU shares a detailed analysis of threat data from security investigations across our global customer base throughout 2025 and into 2026. Key findings include:

  • ClickFix was the single most common malware delivery vector in the finance sector at 22.1% of cases, running 10.8 points above the cross-industry average.
  • Malware was the leading threat type observed against financial services organizations at roughly 38% of observations, with credential-access account compromise close behind at 35.5%.
  • In 2026 year to date, Microsoft Teams surged to the number one overall initial-access vector at 29.0% of events, with ClickFix close behind at 22.4% — together, these two vectors account for just over half of all finance-sector initial access so far in 2026.

Download the full report to explore the current threat landscape impacting financial services organizations, the most prevalent attack vectors observed by TRU in 2025, and actionable recommendations to help protect against cyberattacks, strengthen defenses, and minimize business disruption.

Get The Report