Cyber Attacks on Financial Institutions: Threats and Trends
This paper examines the growing threat of cyber attacks targeting financial institutions, tracing incidents from the 1998 Morris worm to sophisticated 2014 banking breaches affecting millions of accounts. It describes key attack methods—including phishing campaigns, infrastructure hijacking, Man-in-the-Browser malware, and identity theft exploiting mobile payment systems—and explains why banks are disproportionately targeted compared to other industries. The paper also highlights the reputational and financial damage these attacks cause, the coordinated responses of banks and regulators, and the broader societal consequences for consumers whose savings, retirement funds, and personal data are at risk.
- Introduction to Cyber Threats in Banking: Overview of phishing, mobile banking risks, infrastructure hijacking
- Historical Examples of Infrastructure Attacks: Morris worm and Georgian government hacking incidents
- Notable Bank Breaches and DDoS Threats: 2014 banking breaches and FBI phishing warnings
- Mobile Payment Vulnerabilities and Identity Theft: Identity theft exploiting mobile payment sign-up processes
- Man-in-the-Browser Attacks and Reputational Damage: Browser malware enabling unauthorized banking transactions
- Scale of Financial Sector Targeting and Broader Consequences: Banks targeted four times more than other industries
✍️ How to write this paper — guide, tools & examples ▾
What makes this paper effective
- The paper grounds abstract security concepts in concrete, named incidents—such as the 2014 JP Morgan breach and the Morris worm—making complex threats accessible to a general academic audience.
- It progresses logically from historical precedents to modern attack vectors, giving readers a sense of how cyber threats have evolved alongside banking technology.
- Citations from industry sources (Kaspersky Lab, FBI alerts, Websense Security Lab) lend credibility and reflect awareness of both technical and regulatory dimensions of cybersecurity.
Key academic technique demonstrated
The paper demonstrates expository synthesis: it gathers evidence from multiple authoritative sources—government alerts, security firm reports, and news investigations—and weaves them into a coherent narrative explaining how and why financial institutions are disproportionately targeted. Rather than arguing a single thesis, it maps a landscape of threats, which is an effective approach for survey-style research papers in applied fields like cybersecurity.
Structure breakdown
The paper opens with a framing overview of the financial sector's vulnerability, then moves chronologically through historical and recent attack cases. Subsequent sections isolate specific attack types (DDoS, mobile payment fraud, Man-in-the-Browser), before closing with industry-wide statistics and a call for stronger government protection. Each section is focused on a distinct threat category, allowing readers to locate specific topics easily.
Introduction to Cyber Threats in Banking
The finance industry has continued to receive increasingly targeted and sophisticated cyber attacks from criminals. These criminals often deploy phishing email campaigns aimed at customers, which have remained the most successful methods of targeting financial institutions. New innovations in banking—such as online and mobile banking—have continued to create new vulnerabilities for cyber thieves. To minimize the effectiveness of these attacks, banks have devised improved communication and educational tools for customers, as well as procedures for quick intervention in the event of an actual attack.
However, beyond simply creating harmful software intended to hack online banking credentials, criminals have found ways to subvert the software and servers owned by major financial institutions to make their phishing campaigns more effective. This technique is known as infrastructure hijacking (Pettersson, 2012). The scale and creativity of these attacks have made cybersecurity one of the most pressing concerns in the financial sector today.
Historical Examples of Infrastructure Attacks
One of the foremost early examples of infrastructure hijacking ever discovered is known as the Morris worm, which emerged in 1988. This worm spread to several computers, mostly located in the United States, and exploited weaknesses found in the UNIX system that allowed it to rapidly replicate itself. The worm slowed infected computers to the point where they could no longer be effectively used. Robert Tappan Morris created the worm and claimed he was only attempting to measure how vast the internet was. As a result, he became the first person in history to be convicted under the United States Computer Fraud and Abuse Act.
Georgian computer networks were also hacked by unidentified foreign intruders during a period in which the country experienced hostilities with Russia. Graffiti was posted on the websites of the Georgian government. Although little or no services were actually disrupted, the Georgian government believed these attacks were coordinated by Russian military officials. These historical episodes illustrate that state and criminal actors have long recognized digital infrastructure as a viable target.
Notable Bank Breaches and DDoS Threats
The FBI has stated that cybercriminals have devised new means of gaining access to the login credentials of banking employees by using phishing and spam emails, remote access Trojans, and keystroke loggers. Attacks of this nature were witnessed in September 2012 when Wells Fargo and Bank of America were both compromised (Fraud Alert, 2012). According to the Financial Services Information Sharing and Analysis Centre, the threat level was raised from "elevated" to "high" in response to reliable intelligence about potential distributed denial-of-service (DDoS) attacks against U.S. financial institutions (U.S. Financial Sector has raised its Cyber Threat Level from Elevated to High, 2012).
Cybercriminals carried out advanced offensive cyber attacks on banks in 2014. One of the most notable occurred in July of that year, when a massive regional banking network was compromised by an unidentified third party, placing the accounts of over 72,000 customers at risk of exposure. Investigations revealed that the intruder could have accessed customer information including names, account numbers, addresses, personal identification numbers, and account balances (Cordle, 2014).
A related cyber attack occurred a few weeks later involving a major American bank, resulting in one of the largest cybersecurity breaches in history: more than 76 million household bank accounts and over 7 million small business accounts were compromised. The attackers accessed bank servers hosting consumer account details. Due to the technique employed, the attack went undetected for nearly two months before the bank responded and shut down access points on more than 90 servers. The bank collaborated with law enforcement and banking regulators to uncover the method used and subsequently addressed the vulnerabilities in its network systems (Glazer, 2014).
References
Cordle, I. P. (2014, August 7). TotalBank responds to computer security breach. Miami Herald. Retrieved from http://www.miamiherald.com/news/business/article1978822.html
Crossman, P. (2015, March 5). Is Apple Pay a fraud magnet? Only if banks drop the ball. American Banker. Retrieved from
Dean, B. (2015, March 4). Why companies have little incentive to invest in cybersecurity. Retrieved from http://theconversation.com/why-companies-have-little-incentive-to-invest-in-cybersecurity-37570
Fraud Alert. (2012). Cyber criminals targeting financial institution employee credentials to conduct wire transfer fraud.
Glazer, E. (2014). J.P. Morgan's cyber attack: How the bank responded. WSJ. Retrieved from http://blogs.wsj.com/moneybeat/2014/10/03/j-p-morgans-cyber-attack-how-the-bank-responded/
Kaspersky Lab. (2015, February). Carbanak APT: The great bank robbery. Retrieved from
Korolov, M. (2015, June 23). The average number of attacks against financial services institutions is four times higher than other industries. CSO Online. Retrieved from
Mossburg, E. (2015). A deeper look at the financial impact of cyber attacks. Financial Executive, 31(3), 77–80.
Networks expose vulnerabilities to cyber-terrorism. (2004). Operations Management, 10(44), 2.
Paul Hastings. (2015, April 28). Caught in the crossfire: The rising threat of cyberattacks on financial institutions and the heightened expectations of financial regulators. Retrieved from
Pettersson, M. (2012). Banks likely to remain top cybercrime targets. Mountain View, CA: Symantec Corporation.
Reply. (2016, February 4). Underground security intelligence for financial institutions. Retrieved from http://www.reply.eu/en/content/underground-security-intelligence-for-financial-institutions
U.S. Financial Sector has raised its Cyber Threat Level from Elevated to High. (2012, September 21). Retrieved from Cyber Warzone:
Create your account
Always verify citation format against your institution’s current style guide requirements.