Security Issues in the Korean & Global Financial Sector in August 2026
Sep 08 2026
Statistics on Malware Distributed to the Financial Sector
Malware Distribution Trends.
In Attack Stage 1, phishing was the highest at 2.1, Up from 1.8 The previous month.
In Attack Stage 2, dropper/downloader was the highest at 1.1, Down from 3.2 The previous month.
In Stage 3 of the attack, Infostealers were the most prevalent at 0.3, Down from 0.4 The previous month.
WebShells, Backdoors, HackTools, Ransomware, and CoinMiners remained at low levels.
Malware Types and Attachment Distribution.
Phishing accounted for the highest share at 41.9%; The top three types—including Downloader at 17.6% And Unclassified at 12.1%—Accounted for approximately 72% of the total.
Types used for Initial Breach, such as Downloaders and Droppers, appeared alongside types used for persistent infiltration and data exfiltration, such as Backdoors and Infostealers.
This demonstrates that multi-stage attack chains—beginning with the initial lure (phishing), followed by the download of additional malware, the establishment of a backdoor, and finally information theft—have become commonplace.
In terms of file types, HTML accounted for the largest share at 29.1%, Followed by PE at 17.0%, PDF at 9.3%, JS at 7.6%, And VBS at 4.2%.
By file extension, html (30.0%), Js (19.4%), Pdf (11.7%), And exe (5.6%) Ranked highest.
With a high proportion of script-based formats such as JS, VBE, VBS, BAT, and HTA, as well as web document formats like HTML, HTM, and SHTML, the distribution of phishing pages, HTML smuggling, and the exploitation of LOLBins stood out.
Account Leaks and Deep Web/Dark Web Issues.
Cases were identified where user account information was leaked to threat actors via the Telegram API.
During August, the quantity of domestic financial sector accounts leaked via Telegram accounted for 3% of the total.
On the deep web and dark web, database leaks and the trade of credit card data were Major Issues.
On BreachForums, DarkForums, and RaidForums, finance-related databases and credit card records were sold or posted as alleged leaks.
Database Leakage Cases.
On alipay.Com, “mosad” claimed a leak of 820 million records under the title “[CHINA] 820 Million Alipay users LEAKED,” stating that the data included names, phone numbers, and gender information.
On robinhood.Com, RTX106 claimed a leak of 14,521,975 user records and posted that the data included names, email addresses, phone numbers, Social Security numbers (SSNs), addresses, bank account information, KYC status, and two-factor authentication status.
On bankofbaroda.In, a user named “moonfox” posted that they were selling the Bank of Baroda database; however, the actual scale and authenticity of the leak could not be verified based solely on the screenshot.
Ransomware and Data Extortion.
Ransomware groups such as CRPx0, Dysphor1A, LockBit 5.0, And LockBit targeted the financial sector and posted victims on DLS (Dedicated Leak Sites, public extortion sites).
CRPx0 claimed to have stolen 2.3 GB of sensitive HR data from the recruitment and evaluation system at qnbfinansbank.Com.
Dysphor1A claimed to have leaked data from an internal batch control system related to allianz.Co.Th, presenting a login screen and sample files.
LockBit listed usbank.Com as a victim and set a public disclosure deadline, but the actual scale of the leak and the breach path remain unverified.
Credit Card Data Leaks.
On BreachForums, Bfpussy posted an offer to sell 2.7 Million bank card records.
On RaidForums, Futanari posted an offer to sell over 2.5 Million card records.
In both cases, samples were provided that appeared to contain information such as card numbers, expiration dates, CVV or security codes, Region, issuing institution, and card brand.