Accessibility links
  • Skip to main content
News Icon NEWS FILTER
All News Scams & Phishing Security Education Videos Mobile Security Your Security Education Identity Theft Corporate Security
Search Icon SEARCH
 

Email Icon SUBSCRIBE TO WEEKLY NEWSLETTER
Financial Sector Faces New Targeted Phishing Attacks
Facebook   X   LinkedIn   Email

Financial Sector Faces New Targeted Phishing Attacks

December 17, 2025

Banks and other financial institutions are grappling with a new form of phishing attack that leverages the popular business networking website LinkedIn to reach potential victims. The two-stage attack is notable for its sophistication, but with a smidge of awareness and vigilance, the multi-stage threat can be managed. So let’s get to the information you need to know.

Details of the Attack

The criminals initiate the attack by creating fake LinkedIn profiles. These profiles are crafted to resemble colleagues or associates and sometimes even to impersonate financial institution employees.

Then, once the attackers have established these deceptive profiles, they proceed to contact employees of the targeted organization. Friendly messages or connection requests are sent to forge a relationship.

Following the connection, the attackers send links or attachments that may look essential but are, in fact, malicious. A click on these links sets off the two-stage attack, which goes like this:

Stage One: The system identifies the operating system of the targeted host machine and readies itself for further malicious action.

Stage Two: Malicious software is downloaded, capable of stealing login credentials from the organization’s website.

The attackers are known to use details that make them appear credible, including the name of the targeted financial institution. This is why you should limit the information provided on social media and networking sites to only what is necessary. Consider using vague details for your role at your company, regardless of what type of organization it is. While financial organizations are targeted frequently, even most often by attackers, other business types in any sector are also victims of this type of crime.

Protection Measures

What can you do to stay more secure? Well, we’ve got some tips. To protect against this threat, the following steps are advised:

  • Examine Profiles--Check LinkedIn profiles carefully when receiving connection requests from unfamiliar individuals. Verify with colleagues if necessary.
  • Be Cautious with Links--Do not click on links or download attachments from untrusted sources, regardless of how authentic they may appear. Also, don’t click these if you are not expecting to receive them.
  • Consult the IT Department--If you have concerns or believe you may have clicked a malicious link, contact your IT department right away. They possess the expertise and tools to assess the situation and take immediate action to safeguard your system and the organization's network.

The recent targeted phishing attacks on the financial sector highlight the importance of ongoing vigilance and careful scrutiny of online communications. Simple actions such as checking profiles, thinking before clicking, and communicating with IT professionals can significantly reduce the risk. With cybercriminals getting more tech-savvy and ingenious, staying informed and attentive is our best defense.


Shimming Right Along To Skim Your Payment Card Number

Education

Shimming Right Along To Skim Your Payment Card Number

By now, most of us have at least one or two EMV (Europay, MasterCard, Visa) cards. These are the payment cards that were touted as far more secure than the ones with the magnetic strips on the backs. And indeed, if you ask Visa these cards have resulted in a 75% decrease in fraud in the three years since they were introduced. Cybercriminals are of course finding ways to take advantage of the EMV cards too. Now, there are reports of a new way to skim. READ FULL STORY

Keeping Your Bank Account And Credit Cyber-Smart

Education

Keeping Your Bank Account And Credit Cyber-Smart

Financial institutions and hacking go hand-in-hand. Hacking banks and their account holders is the most direct cash infusion a hacker can get…and they know it. According to Kaspersky Lab, attacks on ATMs alone hit an all-time high in 2017 with malware-as-a-service (MAAS) opportunities. With this service, even hacking “hacks” who have no cybercrime experience can watch an instructional “how to” video on how to target an ATM successfully. Guarding our finances with common sense protection is something we all need to do. READ FULL STORY

Top Phishing Scams Continue To Improve And Grow

Education

Top Phishing Scams Continue To Improve And Grow

Much to our dismay, cybercrooks keep finding ways to better the phishing tools they have and find other ways to include new and sneakier methods of thievery. Organizations and individuals are targets and money, identities, credentials, and more are stolen from both every day. Even cyber-savvy users can get caught in phishing scams if they don’t pay close attention to the signs and signals that something isn’t quite right. Reviewing the most pervasive phishing scams is always recommended. READ FULL STORY

Gift Cards Being Used For Payment In BEC Scams, And What You Need To Know

Scams & Phishing

Gift Cards Being Used For Payment In BEC Scams, And What You Need To Know

Over the years, gift cards have become an enormous “go to” way of giving. Mageplaza found the purchase of gift cards this year will reach nearly $450 billion globally. And like many things involving monetary value and being human, cyber-scammers are exploiting gift cards for profit. They’re now combining gift card fraud with the world’s most lucrative cybercrime, business email compromise (BEC) attacks. According to researchers at Cofense, organizations are getting hip to more traditional BEC tricks and have bolstered protections against them. As a result, fraudsters needed a new lure and turned their attention to gift cards. READ FULL STORY








Close
Fraud News & Alerts!

Keep up with the latest cyber security news through our weekly Fraud News & Alerts updates. Each week you will receive an email containing the latest cyber security news, tips and breach notifications.



You're all set!

You will receive your first official security update email within the next week.

A welcome email has also just been sent to you. If you do not receive this email within the next few minutes, please check your Junk box or spam filter to confirm our emails are not being blocked.


 
Help  
Enter any word or words you like.        

The email newsletter will arrive from news@stickleyonsecurity.com


Loading
Please wait...