Banking groups around the world are increasingly being hit by destructive malware attacks.
According to the new Modern Bank Heists 5.0 report from VMware, 63% of global financial organisations were hit by destructive cyber-attacks in the past year. This was a 17% increase compared to the previous year’s report.
Its findings are based on a poll of 130 financial-sector CISOs and security leaders.
Destructive malware attacks are designed to destroy, disrupt, or degrade systems, generally by encrypting files, deleting data, destroying hard drives, terminating connections, or executing malicious code.
While most criminals perform attacks as a way of stealing money, or data that they can sell or ransom, destructive attacks are designed to destroy evidence or make it harder for incident response teams to work.
But partly, they are launched for punitive reasons, as repercussions for failing to meet ransom demands or as part of a large geopolitical struggles.
“In fact, we’ve recently witnessed destructive malware like HermeticWiper being launched following Russia’s invasion of Ukraine. Notably, the majority of financial leaders I spoke to for this report stated that Russia posed the greatest concern to their institution,” said VMware head of cybersecurity strategy Tom Kellermann.
Recommended
- Bringing new tech talent into finance with the Unified Schools Programme
- UK DCMS invests £20mn in data professionals
- RegTech to account for 50% of compliance spending by 2026
In addition, 74% said that their organisation had experienced at least one ransomware attack over the past year. Of these, said that they had 63% paid the ransom.
With a mature ecosystem, ransomware attacks can be performed easily by hackers with little expertise, using cheap, readymade and tailored ransomware kits.
The report also found that the majority of financial institutions plan to increase their budget by 20-30% this year. The top investment priorities include extended detection and response (XDR), workload security, and mobile security.
However, around 70% of financial institutions interviewed for the report said they were not spending more than 12% of the overall IT budget on security.
In addition, 80% of CISOs at financial institutions surveyed still report to CIOs.
“In this age of anywhere work and heightened security risks, we must provide CISOs with a direct line of access to the CEO and greater authority and resources,” the report stated.
Get the latest news from DIGIT direct to your inbox
Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.
To subscribe, click here.





