logo

Security Issues in the Korean & Global Financial Sector in June 2026

ID: 5f00633b-8b64-5728-a67b-9e20a42325f6

STIX ID: report--5f00633b-8b64-5728-a67b-9e20a42325f6

Feed Name: ASEC

Threat Score
75/100

Date Published: 2026-07-15

Date Updated: 2026-07-22

Author: ATCP

...
...

In June the financial sector saw multi-stage attacks led by phishing (stage 1) that used HTML attachments and links, droppers/downloaders in stage 2 to retrieve additional payloads, and infostealers in stage 3 to harvest account data. HTML-based phishing pages, HTML smuggling, and script-based attachments (html, js, vbe, vbs, bat, hta) were prominent; Korean-language lures mimicked business documents to increase trust. Cases of account information exfiltrated via the Telegram API accounted for ~5% of domestic financial-sector leaks. Dark web activity included large database leaks (e.g., Canada Life, Robinhood, Prudential) and ransomware/data-extortion claims (LAPSUS$, MORPHEUS, Qilin), plus marketplaces selling access credentials and stolen financial/customer data.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.