July 2026 Security Issues in Korean & Global Financial Sector

July 2026 Security Issues in Korean & Global Financial Sector

Statistics on Malware Distributed to the Financial Sector


  • In Attack Stage 1, phishing (a technique that tricks users into opening malicious links or attachments) had the highest rate at 1.7, Down from 2.3 The previous month.
  • In Attack Stage 2, Dropper/Downloader (a type that downloads additional malware) was the most prevalent at 1.7, Up from 1.4 The previous month.
  • In Stage 3, Infostealers (malware designed to steal information) were the most prevalent at 0.2, While Ransomware and CoinMiner each accounted for 0.1.
  • In terms of detection distribution for each type, phishing ranked first at 31.6%. The top three types—phishing, loaders (19.9%), And backdoors (16.6%)—Combined to account for approximately 68% of the total.
  • This demonstrates that multi-stage attack chains—which begin with an initial phishing lure and progress to the download of additional malware, the installation of backdoors, and Information Theft—have become commonplace.
  • Among malicious attachments, HTML was the most common at 24.4%, Followed by PE at 12.7%, APK at 9.8%, XLS at 7.8%, PDF at 4.6%, And DOCX at 4.2%.
  • By file extension, html (22.9%), Js (14.9%), Exe (10.1%), And vbe (8.0%) Ranked among the top. A Pareto distribution was observed, with the top eight extensions accounting for 80% of the total.
  • The high number of script-based extensions—such as js, vbe, vbs, bat, and hta—indicates that script execution and LOLBins exploits are prevalent.
  • Korean-language attachment file names were found to masquerade as business documents, tax and payment receipts, and HR and contract documents.

Statistics on accounts of Korean industries exfiltrated via Telegram


  • Cases were confirmed where users were lured to login pages through phishing emails, malicious links, or the execution of HTML attachments, and the account IDs and passwords they entered were leaked to Telegram (via the Telegram API and message transmission service API).
  • During June, the quantity of domestic financial sector accounts leaked via Telegram accounted for 5% of the total.
  • Phishing campaigns using various keywords—such as “money transfer,” “receipt,” and “voicemail”—were employed as distribution methods.

Major Deep Web & Dark Web Issues in the Financial Sector


  • Database breaches are emerging as a major form of cybercrime, and the stolen data can be used as a foundation for identity theft, targeted phishing, and ransomware attacks.
  • In a post related to Santander (Banco Santander), bank account and card information was offered for sale, with the seller claiming to possess over 5,000 records. The post reportedly included IBANs, balances, card details, names, and phone numbers.
  • A post related to Alfa-Bank claimed that a “partial client database” was being sold, describing a CSV file containing 1,032,464 records with fields such as accountid, email, name, dob, cardnumber, primaryphone, and additionalcontacts.
  • In a post related to BlackRock, internal infrastructure documents for the Amelia platform were disclosed; these were confirmed to include internal hostnames, FQDNs, VPN tunnel addresses, and information on development, operations, and disaster recovery environments.
  • The UnSafe ransomware group claimed responsibility for a breach at Deutsche Bank and released SFTP login credentials, file transfer logs, internal directory paths, and CSV file movement records. A total of 5.5 GB of CSV data was mentioned.
  • The Everest ransomware group posted Liberty Mutual Insurance and Fiserv as victims. The Liberty Mutual Insurance data was claimed to include insurance policy documents, customer names, addresses, and insurance-related information, while the Fiserv data was claimed to include PDFs of bank statements, check images, transaction records, and customer financial information.
  • Some of the data also mentioned information related to Monson Savings Bank and Bank of Dudley.
  • Based solely on the information currently available, it has not been confirmed whether each case has been officially verified or what the exact scale of the data is.

Cyberattack Case


  • Pro-Russian and pro-Islamic hacktivist groups have been observed to carry out DDoS attacks against regions with conflicting political or religious views or with which they have geopolitical rivalries.
  • They used external services such as check-host.Net to test the availability of Attack Target websites and flaunted the success of their attacks by publishing screenshots.
  • On Hasan’s BreachForums, Gorz_Rostam claimed to be continuing a service disruption campaign targeting banking systems in the United Arab Emirates and the Gulf Region. He claimed that several bank servers were offline for several hours and also mentioned the ongoing “Operation Seven Stages.”
  • Regarding the Bahraini banking sector, GORZ ROSTAM claimed to have carried out a precision disruption attack on July 13, 2026, and warned of additional attacks. However, based on the information provided, no concrete evidence of damage confirming the success of the attack was found.