Skip to main content
Research Paper Undergraduate 1,504 words

Cyber Attacks on Financial Institutions: Threats and Trends

~8 min read 6 sections Technology · Computer Security
Abstract

This paper examines the growing threat of cyber attacks targeting financial institutions, tracing incidents from the 1998 Morris worm to sophisticated 2014 banking breaches affecting millions of accounts. It describes key attack methods—including phishing campaigns, infrastructure hijacking, Man-in-the-Browser malware, and identity theft exploiting mobile payment systems—and explains why banks are disproportionately targeted compared to other industries. The paper also highlights the reputational and financial damage these attacks cause, the coordinated responses of banks and regulators, and the broader societal consequences for consumers whose savings, retirement funds, and personal data are at risk.

Key Takeaways
  • Introduction to Cyber Threats in Banking: Overview of phishing, mobile banking risks, infrastructure hijacking
  • Historical Examples of Infrastructure Attacks: Morris worm and Georgian government hacking incidents
  • Notable Bank Breaches and DDoS Threats: 2014 banking breaches and FBI phishing warnings
  • Mobile Payment Vulnerabilities and Identity Theft: Identity theft exploiting mobile payment sign-up processes
  • Man-in-the-Browser Attacks and Reputational Damage: Browser malware enabling unauthorized banking transactions
  • Scale of Financial Sector Targeting and Broader Consequences: Banks targeted four times more than other industries
✍️ How to write this paper — guide, tools & examples

What makes this paper effective

  • The paper grounds abstract security concepts in concrete, named incidents—such as the 2014 JP Morgan breach and the Morris worm—making complex threats accessible to a general academic audience.
  • It progresses logically from historical precedents to modern attack vectors, giving readers a sense of how cyber threats have evolved alongside banking technology.
  • Citations from industry sources (Kaspersky Lab, FBI alerts, Websense Security Lab) lend credibility and reflect awareness of both technical and regulatory dimensions of cybersecurity.

Key academic technique demonstrated

The paper demonstrates expository synthesis: it gathers evidence from multiple authoritative sources—government alerts, security firm reports, and news investigations—and weaves them into a coherent narrative explaining how and why financial institutions are disproportionately targeted. Rather than arguing a single thesis, it maps a landscape of threats, which is an effective approach for survey-style research papers in applied fields like cybersecurity.

Structure breakdown

The paper opens with a framing overview of the financial sector's vulnerability, then moves chronologically through historical and recent attack cases. Subsequent sections isolate specific attack types (DDoS, mobile payment fraud, Man-in-the-Browser), before closing with industry-wide statistics and a call for stronger government protection. Each section is focused on a distinct threat category, allowing readers to locate specific topics easily.

Essay 1,504 words

Introduction to Cyber Threats in Banking

The finance industry has continued to receive increasingly targeted and sophisticated cyber attacks from criminals. These criminals often deploy phishing email campaigns aimed at customers, which have remained the most successful methods of targeting financial institutions. New innovations in banking—such as online and mobile banking—have continued to create new vulnerabilities for cyber thieves. To minimize the effectiveness of these attacks, banks have devised improved communication and educational tools for customers, as well as procedures for quick intervention in the event of an actual attack.

However, beyond simply creating harmful software intended to hack online banking credentials, criminals have found ways to subvert the software and servers owned by major financial institutions to make their phishing campaigns more effective. This technique is known as infrastructure hijacking (Pettersson, 2012). The scale and creativity of these attacks have made cybersecurity one of the most pressing concerns in the financial sector today.

Historical Examples of Infrastructure Attacks

One of the foremost early examples of infrastructure hijacking ever discovered is known as the Morris worm, which emerged in 1988. This worm spread to several computers, mostly located in the United States, and exploited weaknesses found in the UNIX system that allowed it to rapidly replicate itself. The worm slowed infected computers to the point where they could no longer be effectively used. Robert Tappan Morris created the worm and claimed he was only attempting to measure how vast the internet was. As a result, he became the first person in history to be convicted under the United States Computer Fraud and Abuse Act.

Georgian computer networks were also hacked by unidentified foreign intruders during a period in which the country experienced hostilities with Russia. Graffiti was posted on the websites of the Georgian government. Although little or no services were actually disrupted, the Georgian government believed these attacks were coordinated by Russian military officials. These historical episodes illustrate that state and criminal actors have long recognized digital infrastructure as a viable target.

Notable Bank Breaches and DDoS Threats

The FBI has stated that cybercriminals have devised new means of gaining access to the login credentials of banking employees by using phishing and spam emails, remote access Trojans, and keystroke loggers. Attacks of this nature were witnessed in September 2012 when Wells Fargo and Bank of America were both compromised (Fraud Alert, 2012). According to the Financial Services Information Sharing and Analysis Centre, the threat level was raised from "elevated" to "high" in response to reliable intelligence about potential distributed denial-of-service (DDoS) attacks against U.S. financial institutions (U.S. Financial Sector has raised its Cyber Threat Level from Elevated to High, 2012).

Cybercriminals carried out advanced offensive cyber attacks on banks in 2014. One of the most notable occurred in July of that year, when a massive regional banking network was compromised by an unidentified third party, placing the accounts of over 72,000 customers at risk of exposure. Investigations revealed that the intruder could have accessed customer information including names, account numbers, addresses, personal identification numbers, and account balances (Cordle, 2014).

A related cyber attack occurred a few weeks later involving a major American bank, resulting in one of the largest cybersecurity breaches in history: more than 76 million household bank accounts and over 7 million small business accounts were compromised. The attackers accessed bank servers hosting consumer account details. Due to the technique employed, the attack went undetected for nearly two months before the bank responded and shut down access points on more than 90 servers. The bank collaborated with law enforcement and banking regulators to uncover the method used and subsequently addressed the vulnerabilities in its network systems (Glazer, 2014).

3 Sections Hidden · 535 words
Mobile Payment Vulnerabilities and Identity Theft195 words
One unique type of cyber attack that reduces the effectiveness of monitoring and maintaining adequate cybersecurity protocols is that an attack can sometimes arise from traditional methods exploiting a normal process. As a result, network system vulnerability is not always obvious or…
Man-in-the-Browser Attacks and Reputational Damage155 words
Another issue of grave concern to financial institutions is the damage cybercrime can inflict on a company's reputation. Man-in-the-Browser attacks remain one of the most dangerous forms of malware…
Scale of Financial Sector Targeting and Broader Consequences185 words
While all organizations face the problem of cyber attacks, financial institutions face the largest risks because they hold funds and a significant amount of private data on both commercial entities and individual consumers. In recent years, cyber thieves have utilized online banking and payment…

References

Cordle, I. P. (2014, August 7). TotalBank responds to computer security breach. Miami Herald. Retrieved from http://www.miamiherald.com/news/business/article1978822.html

Crossman, P. (2015, March 5). Is Apple Pay a fraud magnet? Only if banks drop the ball. American Banker. Retrieved from

Dean, B. (2015, March 4). Why companies have little incentive to invest in cybersecurity. Retrieved from http://theconversation.com/why-companies-have-little-incentive-to-invest-in-cybersecurity-37570

Fraud Alert. (2012). Cyber criminals targeting financial institution employee credentials to conduct wire transfer fraud.

Glazer, E. (2014). J.P. Morgan's cyber attack: How the bank responded. WSJ. Retrieved from http://blogs.wsj.com/moneybeat/2014/10/03/j-p-morgans-cyber-attack-how-the-bank-responded/

Kaspersky Lab. (2015, February). Carbanak APT: The great bank robbery. Retrieved from

Korolov, M. (2015, June 23). The average number of attacks against financial services institutions is four times higher than other industries. CSO Online. Retrieved from

Mossburg, E. (2015). A deeper look at the financial impact of cyber attacks. Financial Executive, 31(3), 77–80.

Networks expose vulnerabilities to cyber-terrorism. (2004). Operations Management, 10(44), 2.

Paul Hastings. (2015, April 28). Caught in the crossfire: The rising threat of cyberattacks on financial institutions and the heightened expectations of financial regulators. Retrieved from

Pettersson, M. (2012). Banks likely to remain top cybercrime targets. Mountain View, CA: Symantec Corporation.

Reply. (2016, February 4). Underground security intelligence for financial institutions. Retrieved from http://www.reply.eu/en/content/underground-security-intelligence-for-financial-institutions

U.S. Financial Sector has raised its Cyber Threat Level from Elevated to High. (2012, September 21). Retrieved from Cyber Warzone:

Key Concepts in This Paper
Infrastructure Hijacking Phishing Campaigns DDoS Attacks Man-in-the-Browser Mobile Payment Fraud Data Breach Identity Theft Banking Malware Network Vulnerability Cybercrime Scale
Cite This Paper
PaperDue. (2026). Cyber Attacks on Financial Institutions: Threats and Trends. PaperDue. https://www.paperdue.com/study-guide/cyber-attacks-financial-institutions-threats-trends-2158841

Always verify citation format against your institution’s current style guide requirements.