
Android work profiles can hide a cloned banking app
A banking Trojan can reportedly hide a cloned banking app inside an Android work profile, complicating routine checks for fraud or malicious software.
Digital banking risk sits at the intersection of cybersecurity, identity and fraud. This hub follows verified threats to banking channels, payments, customer accounts and fintech operations—and the controls that reduce loss.

A banking Trojan can reportedly hide a cloned banking app inside an Android work profile, complicating routine checks for fraud or malicious software.

Federal guilty pleas show how ATM malware can turn a familiar cash machine into a physically accessed fraud endpoint.

A loan app can look like help while quietly collecting the information needed to pressure or extort the borrower.

AI-agent payment records may help explain disputed transactions, but unverified provenance is not a substitute for customer authorization, limits or dispute controls.

A bulletin’s expired-card fraud claim is unverified; payment teams should test issuer, network and token behavior before changing controls or customer guidance.

Malwarebytes Labs reports that scientific research found the expiration date on some Visa credit cards could be manipulated in so-called Zombie Card attacks. This candidate is marked verified…

ThreatFabric researchers described Manic, an Android malware family combining banking-fraud capabilities with spyware and remote-control features. A notable design choice allows data to be relayed through Bluetooth, reducing…

U.S. Bank is investigating a LockBit claim involving stolen data, putting a major financial institution under extortion pressure while the alleged compromise remains under review.

Paying a bill online often begins with a search for the provider’s website. The US Federal Trade Commission warns that the first result may be a paid advertisement…

US senators are pressing regulators for stronger brokerage-account safeguards, highlighting how inconsistent fraud protections can leave investment customers exposed to account takeover and theft.

Monzo reported that card payments and transfers were restored after a service disruption affected customers. Although the event was operational rather than a confirmed cyberattack, it is relevant…

Scammers are imitating cryptocurrency anti-money-laundering services and using the appearance of a security check to obtain wallet permissions. Malwarebytes researchers documented sites that copied the branding and language…

Banks are confronting fraud in which criminals impersonate trusted institutions and persuade customers to complete legitimate authentication themselves. In an ISMG interview, American Bankers Association executive Paul Benda…

The ECB has chosen 36 payment service providers for its digital euro pilot, moving Europe’s central-bank digital currency project closer to real-world testing.

Criminals recruit people to open or surrender control of online betting accounts so illicit funds can be moved and the real bettor’s identity concealed. Malwarebytes described these “mule…

Operation First Light 2026 targeted social-engineering scams across 97 countries and intercepted about $293 million in illicit assets.

The US Justice Department seized cloud infrastructure allegedly used by businesses connected to the Huione Group to support online scams and illicit transactions. CyberScoop published the underlying report or notice on 2026-06-23, placing the

Europol said an international operation dismantled the AudiA6 cryptocurrency laundering service, which allegedly processed about €336 million connected to ransomware groups. Europol published the underlying report or notice on 2026-06-11, placing the event within

Proofpoint reported that suspected North Korean actors used fake recruitment and coding assignments to infect developers and steal cryptocurrency. Proofpoint published the underlying report or notice on 2026-06-09, placing the event within the month’s

The Consumer Financial Protection Bureau said it was working to ensure consumers affected by Bilt’s move to a new banking partner received appropriate remedies. Consumer Financial Protection Bureau published the underlying report or notice

On May 20, 2026, The Record reported that crypto atm scams caused millions in losses across us states. The account describes a concrete security, privacy or fraud consequence…

On May 5, 2026, Europol reported that authorities dismantled call centres tied to €50 million online fraud. The account describes a concrete security, privacy or fraud consequence rather…

FCC action targets phone networks carrying bank impersonation scams. FCC documented the development in April 2026. SecBriefs checked the central claim against a primary record or genuinely independent…

A Lloyds software update exposed private transaction details across customer accounts, creating privacy and impersonation risk without reported account takeover.
Today’s candidates point to practical security issues rather than a single incident pattern. Enterprise AI adoption is raising questions about where prompts and logs reside, while a reported dark-web service is offering a very large collection of driver’s-license images. X is investigating unsolicited password-reset messages after the launch of X Money, but the cause and impact remain unclear. Microsoft describes an active campaign using counterfeit software-download pages and altered installers to deliver malware. Separate research suggests AI may help adapt exploits against programmable logic controllers; it demonstrates capability, not an operational attack. Banks should focus on data-location guarantees, identity-proofing resilience, account-recovery controls, software provenance, and careful separation between research findings and confirmed incidents.
Today’s selected stories point to a practical shift in cybersecurity: organizations are being tested less by isolated technical flaws and more by whether everyday controls work when systems, suppliers, automated decisions, and public infrastructure are under pressure. Reported disruption at a UK power facility highlights the need to separate confirmed operational impact from still-limited attribution. Vulnerability reporting affecting Atlassian products and connected road systems reinforces the importance of accurate inventories, controlled remote access, segmentation, and evidence that patches were applied successfully. At the same time, AI-assisted software development and AI-agent payments raise a different control question: faster or more autonomous activity does not remove the need for ownership, approval limits, logging, rollback, and dispute handling. Ransomware reporting continues to focus attention on mid-market organizations and suppliers whose recovery capacity may be weaker than that of large enterprises. Finally, deepfake abuse and the Latvian CSDD breach show how exposed personal or payment-related information can create harm even when direct financial compromise has not been established. The central lesson is not to react to every headline equally, but to verify the claim, identify the affected business process, and test the control that should contain the damage.
The first full week of August highlighted the two sides of digital finance. UK identity-fraud reporting pointed to record pressure from stolen and synthetic identities, while Wero’s expansion plans showed Europe continuing to build alternative payment infrastructure.\n\nThe connection is simple: faster onboarding and payments increase the value of identity controls. If identity proofing, account recovery and transaction monitoring are designed as separate checkpoints, fraud can move between them.\n\nThe bottom line: payment innovation should be matched by equally modern identity and behavioral controls.
July moved cyber resilience closer to financial and public-policy strategy. UK regulators began direct oversight of critical technology providers serving finance, the ECB advanced the digital-euro pilot, and international fraud operations demonstrated the scale of industrialized social engineering. At the same time, water-utility attacks and ransomware-driven production shutdowns showed how cyber incidents can produce physical consequences.\n\nThe common thread is systemic dependency. Banks depend on a small number of cloud and technology providers; consumers depend on increasingly digital payment rails; utilities depend on exposed operational systems; and businesses depend on production technology that can become unavailable during containment.\n\nThe bottom line: July showed that resilience is no longer only an internal control issue. It is becoming a supervisory, infrastructure and business-model question. Organizations need to understand concentration risk, payment dependencies, fraud pathways and operational fallback together.