Site navigation

Report: DDoS Attacks Are Hammering Financial Firms

Tom Quinn

,

DDoS
New research shows financial firms are facing a steep rise in highly targeted DDoS attacks, with threat actors able to bypass automated defences.

Financial firms are facing a surge in highly targeted and sophisticated DDoS attacks, with new research revealing that threat actors are severely disrupting business operations, eroding profitability, and undermining customer trust.

The latest study from nonprofit cybersecurity group FS-ISAC and cloud firm Akamai has revealed that financial services firms were among those hit hardest by volumetric DDoS attacks last year, which aim to overwhelm victims with sheer traffic made up of hundreds, millions, or even billions of individual malicious requests.

The joint study, From Nuisance to Strategic Threat: DDoS Attacks Against the Financial Sector, found that these attacks against the financial sector have been growing for years, but 2024 saw a significantly sharp uptick compared to other industries, with a major spike in October that saw nearly 350 attack events.

The study also outlines a striking increase in DDoS attacks targeting APIs and customer-facing websites, with cyber-criminals mimicking real user behaviour to slip past defences. 

According to Akamai, application-layer DDoS attacks against the financial sector jumped 23% between 2023 and 2024 as the growing use of APIs continues to widen attack surfaces, while the data shows a 19% increase in DDoS attacks launched against user-facing components. 

Many of the attacks analysed in the report showed overlapping vectors, with the study suggesting that the most prolific threat actors may be the same groups, working together, or using shared infrastructure, such as DDoS-as-a-Service platforms.

The rise of DDoS-for-Hire services targeting the financial sector is making it harder to trace attackers or understand their motives, complicating efforts to respond and defend against future threats.

Threat actors’ tactics are shifting, too, with Akamai’s research finding an increasing sophistication among those triggering DDoS incidents.

Attackers were observed testing a broad range of attack vectors at low traffic volumes, allowing them to gather intelligence and slip past DDoS defences. 

These attackers also often targeted multiple financial organisations at the same time and were sustained over several weeks, or even months, which the research suggests indicates that the threat actors have significant resources at their disposal.

Attackers were able to cause widespread service disruptions by bypassing automated DDoS protections and disabling on-premise infrastructure such as proxies, firewalls, and load balancers, with some outages lasting for days, significantly impacting end users.

Rather than fighting fire with fire, the report stresses that tackling the rapidly evolving DDoS threat landscape calls for more than just automation, and requires a mix of proactive detection, behaviour-based analysis, along with a combination of automated and manual responses.

That includes some understanding of attacker behaviour, but more importantly, relies on noticing early signs of DDoS activity, often including unexpected traffic spikes, unusual request patterns, or spoofed and untrusted sources. 

Continuous monitoring and baselining of network traffic by both man and machine is essential for red-flagging and stopping DDoS attacks before they cause real disruption.


Recommended reading


“Threat actors will continue to leverage DDoS attacks to exploit the security of our institutions,” said Steve Winterfeld, advisory CISO at Akamai. 

“These attacks strive to exhaust an institution’s network infrastructure and, in turn, drain the resources used to defend against them. 

“The implementation of mitigation strategies, robust cyber hygiene fundamentals, and industry best practices can help the sector defend against the evolving risk.”

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data