Financial Services Cybersecurity: Threats and Controls 2026
目次
- Why financial institutions stay at the top of the target list
- Germany, Austria, and Switzerland in 2026
- The United States in 2026
- What attackers actually do: the six vectors to plan for
- The regulatory picture: DORA, NYDFS, and the SEC
- Where external threat intelligence fits in
- What the institutions holding up in 2026 are doing differently
In 2025, cyber incidents targeting financial services more than doubled, from 864 to 1,858 in twelve months. That is roughly 19% of all cyberattacks recorded globally, concentrated in one sector.
The pace has not slowed. Banks, insurers, and payment providers now operate under the most demanding regulatory environment in the industry’s history. At the same time, the groups targeting them (ransomware operators, state-sponsored actors, AI-assisted fraud networks) have adapted faster than the frameworks written to constrain them.
This guide covers what is actually happening in 2026, with a specific focus on Germany, Austria, Switzerland, and the United States, where the threat picture is sharpest and the regulatory pressure most acute.
Why financial institutions stay at the top of the target list
A bank breach does not stay contained to the bank. The Federal Reserve Bank of New York modeled what happens when a major US institution goes down and concluded that an attack on any one of the top five banks could disrupt up to 38% of the national financial network. That cascade risk is structural, and it is why attackers keep coming back regardless of how much the sector spends on defenses.
The average cost of a financial sector breach reached $5.56 million in 2025, $1.12 million above the cross-industry average, per IBM. Two thirds of financial services organizations were hit by ransomware in the same period, the highest rate Sophos has recorded. Banks and payment platforms now absorb 34% of all Layer 3 and 4 DDoS attacks globally, according to Akamai.
The motivations vary by attacker. Criminal groups want direct financial return, through ransomware, fraud, or selling stolen credentials and account data. State-affiliated actors are after pre-trade intelligence, M&A data, and the kind of market-moving information that does not need to be stolen if it can be read. And hacktivists, particularly in Europe, have made financial infrastructure a proxy for political messaging, targeting German banks not to steal from them but to disrupt them publicly. A Broadcom survey found that 25% of finance executives identified market data as the primary target of attacks against their organizations; that number would have seemed implausible five years ago.
Germany, Austria, and Switzerland in 2026
The DACH region is the most attacked part of Europe by incident volume, and financial institutions are at the center of it.
Cyberattacks across Germany, Austria, and Switzerland surged 124% in 2025, according to Check Point Software Technologies. Germany alone accounted for more than 80% of those incidents, a concentration that reflects its economic weight and its political positioning on Ukraine. By individual country share, Germany ranked ahead of France, Spain, and Italy across all tracked European cyberattacks.
In early 2026, that trajectory steepened. Black Kite’s European Cyber Risk Report recorded an average of 170 incidents per DACH country in January through April, more than four times the Benelux average. Germany sits at 370 total incidents for the continent, with the SafePay ransomware group directing 56.7% of its 80 European operations at German targets alone.
The pattern inside these numbers is worth understanding, because it shapes what defenses actually matter.
Large German and Swiss banks have hardened their perimeters significantly. Ransomware operators have noticed. Groups including SafePay have shifted focus toward regional banks, Sparkassen, and mid-sized insurance firms, institutions with smaller security teams, older infrastructure, and fewer resources to run continuous monitoring. One compromised managed service provider in 2025 cascaded into 32 financial institutions and generated over 2 TB of stolen data, according to Black Kite’s 2026 Financial Services Report. The attack did not target a bank directly. It targeted a vendor.
In Switzerland, FINMA flagged in early 2026 that the Swiss financial sector remains a preferred target, specifically calling out technological interconnectedness and third-party dependencies as the primary amplifiers of risk. The IMF’s November 2025 Financial Sector Assessment of Switzerland reached the same conclusion: both the Swiss National Bank and FINMA now treat cyber risk as among the most significant threats to Swiss financial stability.
Russian-linked hacktivist groups, primarily NoName057(16) and affiliated networks, have run sustained DDoS campaigns against German banks and payment infrastructure since 2023. These attacks rarely cause lasting operational damage. Their purpose is visibility and disruption: testing incident response capacity and generating public anxiety during politically sensitive moments. For security teams, the practical implication is that DDoS resilience is no longer optional infrastructure. It is a baseline.
The United States in 2026
US financial institutions are dealing with a different threat mix, though the underlying dynamic is identical: attackers target the gaps between institutions and their vendors.
Ransomware incidents against US financial firms rebounded sharply in 2025 after a brief decline following law enforcement action against ALPHV/BlackCat and LockBit. Direct incidents rose from 156 in 2024 to 202 in 2025. Q1 2026 recorded 65 finance-sector incidents, a 76% increase over the same period last year, per Black Kite.
The Marquis Software breach in 2025 illustrated the structural exposure clearly. A single third-party provider was compromised, and the result was 1.35 million customers exposed across 74 US financial institutions. The vendor problem runs deep. 76 of 140 core finance vendors globally carry at least one CISA KEV-listed vulnerability, and 109 of 140 have critical-level patch management failures, according to Black Kite’s 2026 Financial Services Report. These are not obscure vendors. They are the cloud providers, payment processors, and core banking platforms that the sector runs on.
Business email compromise continues to generate the highest fraud volumes. The FBI’s IC3 reported $2.9 billion in BEC losses in 2024, with wire fraud the dominant method. Financial institutions are targeted directly and also used as the infrastructure for fraud against their customers.
The threat that has moved fastest in 2026 is AI-assisted social engineering. In 2025, the FBI documented DPRK-linked operatives using AI face-swapping technology to pass remote hiring verification at US financial firms and gain legitimate insider access. CFO fraud via deepfake voice cloning (fabricated audio calls authorizing wire transfers) has been involved in multiple publicly disclosed incidents at US banks in the past eighteen months. NYDFS guidance updated in 2025 now explicitly requires institutions to address deepfake and AI-driven social engineering within their regular risk assessments.
What attackers actually do: the six vectors to plan for
Ransomware combined with data extortion. Two thirds of financial institutions were hit by ransomware in 2025. The operations with the most leverage now combine encryption with exfiltration. They take the data out before locking it, so paying the ransom no longer resolves the exposure. For DORA-regulated entities, a qualifying incident must be reported to the competent authority within 24 hours of classification. For US public companies, material incidents trigger SEC Form 8-K disclosure within four business days. The average breach lifecycle was 241 days in 2025, per IBM. Most institutions are notifying regulators about incidents that started months before anyone inside the organization noticed.
Phishing and credential theft. Financial services accounted for 27.7% of all observed phishing attempts in 2025. The goal is almost always credential harvest. Infostealers delivered via phishing generate credentials that reach dark web markets within hours, long before most institutions detect anything wrong in their systems.
In Germany, BaFin impersonation campaigns have targeted finance team members at insurers and regional banks, using fabricated regulatory requests to deliver keyloggers and credential stealers. In the US, regional credit unions have been hit with phishing campaigns mimicking their core banking vendors, designed to capture VPN credentials and internal system logins.
Third-party and supply chain compromise. The share of breaches involving a third party doubled to 30% across all industries in Verizon’s 2025 DBIR. For financial institutions operating dozens of cloud, payments, and fintech integrations, the exposure multiplies. DORA formalizes what has been a live threat for years: maintaining a full register of ICT third-party providers, monitoring their security posture continuously, and having contractual controls that include audit rights and incident notification requirements.
DDoS targeting availability. Banks and payment platforms absorb 34% of all observed Layer 3/4 DDoS attacks globally. In the DACH region, DDoS has been used both as a primary disruption tool and as a distraction layer run concurrently with other attack vectors. Swiss financial institutions reported a material increase in DDoS frequency in 2025.
AI-enhanced fraud. Attackers use large language models to generate highly personalized phishing content at scale. They use voice cloning to authorize fraudulent payments. They use AI-generated documentation to pass KYC checks. The speed advantage this gives attackers, in crafting convincing pretexts and iterating on what works, has no equivalent on the defensive side yet.
Credential abuse and insider exposure. Dark web markets actively trade financial sector employee credentials: VPN access, internal banking system logins, administrator accounts. The source is usually an infostealer infection on a personal device, a phishing campaign, or a breach of a third-party service where the employee reused their work password. Most institutions do not have visibility into this exposure until a credential is used.
The regulatory picture: DORA, NYDFS, and the SEC
DORA entered full enforcement on January 17, 2025. It applies to roughly 20 categories of financial entities and their critical ICT service providers operating in the EU. Non-compliance carries penalties of up to 2% of global annual turnover for financial entities and EUR 5 million for critical ICT service providers. For DACH institutions, DORA sits alongside Germany’s KRITIS-Dachgesetz. German entities were required to register with the BSI by April 2026. NIS2 obligations that vary by entity size and sector classification.
DORA’s practical requirements break into four areas: maintaining a comprehensive ICT risk management framework including full asset inventory and third-party mapping; reporting major incidents to the relevant competent authority within 24 hours; running documented resilience testing including threat-led penetration testing every three years; and maintaining contractual oversight of every critical ICT third-party provider with audit rights and exit strategies.
NYDFS 23 NYCRR Part 500, the most demanding state-level cybersecurity framework in the US, functions as a de facto national standard for financial institutions with New York activity. The 2023 amendments, now in full enforcement, require annual CISO certification of program effectiveness, mandatory MFA for all privileged accounts and remote access, encryption of all nonpublic information, and 72-hour notification to the NYDFS superintendent of any cybersecurity event that materially affects normal operations. The 2025 guidance update explicitly added AI risk, specifically deepfakes and AI-driven social engineering, to the scope of required risk assessments.
The SEC’s cyber disclosure rules require public financial companies to disclose material cybersecurity incidents within four business days on Form 8-K and to provide annual disclosures on cybersecurity governance. Regulation S-P compliance (covering customer data protection) applied to larger entities by December 2025 and smaller entities by June 2026. The combined effect is that cybersecurity is now a governance and investor-disclosure obligation, not just an operational one. CISOs are signing certifications. Boards are approving annual disclosures. The regulatory clock runs fast.
| Requirement | Where it applies | Status |
|---|---|---|
| DORA full enforcement | EU financial entities and critical ICT providers | In effect January 17, 2025 |
| BSI registration (KRITIS-Dachgesetz) | ドイツ | April 2026 deadline |
| NYDFS 500 CISO annual certification | New York-licensed institutions | Annual, enforced 2026 |
| SEC Form 8-K cyber disclosure | US public companies | 4 business days from material incident |
| Regulation S-P (larger entities) | US | December 3, 2025 |
| Regulation S-P (smaller entities) | US | June 3, 2026 |
| PCI DSS 4.0.1 all controls | Any institution handling card data | In effect 2025 |
| NIS2 transposition | EU member states | Varies by country |
Where external threat intelligence fits in
Regulation S-P, DORA, and NYDFS all converge on the same practical requirement: continuous, auditable evidence of control effectiveness. Annual penetration tests and quarterly vulnerability scans were the standard a few years ago. They are not the standard now.
The detection gap is the core problem. A 241-day average breach lifecycle means that by the time most institutions discover a compromise, the attacker has had eight months inside the environment. Closing that gap requires visibility into threats that develop outside your perimeter, on dark web markets where your credentials are being sold, in domain registries where your brand is being impersonated, in the vendor ecosystem where the initial access is often purchased.
CybelAngel scans billions of data points daily across the open web, deep web, dark web, and connected storage, and has analysts verify alerts before they reach your team. For financial institutions specifically, that translates to five concrete capabilities:
Credential monitoring. Employee credentials from financial sector organizations appear on dark web markets regularly, sourced from infostealers, third-party breaches, and credential stuffing campaigns. CybelAngel surfaces exposed credentials before they are used.
Brand protection. Lookalike domains, fake mobile applications, and fraudulent social media profiles targeting bank customers are active threats across both the US and DACH markets. CybelAngel detects new impersonation infrastructure within hours of registration and manages takedowns.
Asset discovery. Misconfigured cloud storage, forgotten subdomains, and shadow IT deployments are frequent sources of regulatory incidents. CybelAngel maps what your organization exposes externally, including assets your IT team does not know exist.
Third-party monitoring. DORA requires ongoing oversight of every critical ICT provider. CybelAngel extends monitoring to your vendor ecosystem, giving compliance and security teams the continuous visibility that manual quarterly reviews cannot provide.
Compliance evidence. Both DORA and NYDFS expect demonstrable, documented control effectiveness. Continuous external monitoring generates the audit trail that regulators are increasingly asking to see.
What the institutions holding up in 2026 are doing differently
The World Economic Forum’s data shows that minimum viable cyber resilience has dropped by 30% among small and medium financial institutions over the past three years. Given how interconnected the sector is, a regional bank with weak defenses is not just a risk to itself.
The institutions that are not showing up in breach reports share a few characteristics. They treat their vendor ecosystem as part of their attack surface, not a separate risk category. They have moved from point-in-time assessments to continuous monitoring, because their attack surface changes faster than any scheduled scan can track. They have aligned their detection timelines to their disclosure obligations. A 241-day breach lifecycle is not compatible with a 24-hour DORA reporting requirement, and they have built accordingly. And they present security investment to boards in terms of regulatory penalty exposure and financial impact, not CVSS scores.
The institutions not showing up in breach reports found their exposure before an attacker did. A compromised vendor credential, a forgotten subdomain, a lookalike domain registered against your brand: none of these announce themselves. CybelAngel scans billions of data points daily, verifies every alert before it reaches your team, and manages takedowns end to end.
Most organizations we onboard discover at least one critical external exposure they had no visibility into.
