Site navigation

Financial Services in ShinyHunters Crosshairs, Warn Security Pros

Tom Quinn

,

shinyhunters, shinyhunters scatered spider, financial services shinyhunters, financial services scattered spider
Hackers from the ShinyHunters and Scattered Spider groups could be pivoting from luxury brands to target financial services, leaving banks, insurers, and fintech firms at risk.

With global brands like Adidas, Chanel, Allianz and even airline Quantas still reeling from a campaign of orchestrated cyber-attacks linked to the now notorious Scattered Spider and ShinyHunters threat groups, new research warns they might be about to turn attention to financial services.

After a wave of attacks targeting high-profile Salesforce’s corporate customers, including Google, cyber firm ReliaQuest said that domain analysis suggests that financial services providers are the likely next target.

Following a deep dive into domain registrations, ReliaQuest’s researchers identified over 700 domains registered this year that match typical Scattered Spider phishing patterns, which have also recently been used by ShinyHunters actors in their attacks against Salesforce clients utilising malicious ‘connected apps’.

Detailing the findings in a blog post, ReliaQuest said that professional, scientific, and technical services organisations accounted for the largest share of these targets, but since July, the researchers saw domain registrations targeting financial companies in particular increase by 12%.  

“This shift suggests that financially motivated groups like ShinyHunters are now prioritising banks, insurance companies, and financial services, though technology and professional services remain at high risk due to the value of the data and access they provide,” said researchers. 

“These findings highlight the critical need for organisations to track impersonating domain threats, as these can serve as crucial early indicators of attacks by ShinyHunters, Scattered Spider, and similar threat groups.”

However, despite domain registrations targeting the technology sector falling by 5%, the security provider warned that there would be no respite for tech firms.

After the considerable success these criminal actors have recently enjoyed, widely used platforms like Salesforce and Okta are expected to continue to be heavily targeted.


Recommended reading


Researchers suggest that security teams prioritise hardening systems against social engineering, fortifying Salesforce access and data controls, as well as pivoting to more proactive strategies – like hunting out malicious domains using specific keywords.

“Looking ahead, our analysis of domain registration patterns and targeting trends suggests that banks, financial services organisations, and technology service providers are at heightened risk,” said the researchers.  

“The prevalence of phishing domains mimicking high-value brands and SaaS platforms indicates that attackers are prioritising organisations with monetizable data or those providing access to large client environments. 

“While luxury brands and technology firms have borne the brunt of recent attacks, the opportunistic nature of these campaigns means that no sector should consider itself immune.

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data