Global fintech and funding innovation ecosystem

New Cyber Threats Financial Service Firms Need to Know

Cybersecurity | Nov 21, 2024

ASD 2023 2024 Annual Cyber Threat Report

Image: 2023-2024 Annual Cyber Threat Report (ASD)

Cybersecurity for Fintech Firms is No Longer Optional.  What You Need to Know Heading Into 2025

We all knew it was coming but it's finally arrived.  Cyber threats, cybersecurity, cyber attacks, scams, deepfakes, risks, rugpulls, ransomeware, social engineering, phishing etc are now considered a business critical priority.  Particularly financial service firms who interact with and manage high value and sensitive transactional data.  The Australian Signals Directorate recently published its annual 2023-2024 Cyber Threat Report (78 page PDF report) with insights into the evolving cyber threat landscape - what it looks like and how to build business resilience and fortify against it.

Australian Cyber Threat Landscape by the Numbers

Reported Attacks

  • Over 87,400 cybercrime reports were filed.  That's an average of 1 every 6 minutes.
  • The Australian Cyber Security Hotline took 36,700 calls across all industries for a 12% increase.

Financial Impacts

  • Average self-reported cost per cybercrime incident:
    • Small businesses $49,600 (up 8%)
    • Medium businesses $62,800 (down 35%)
    • Large businesses $63,600 (down 11%)
  • Total losses from business email's that get compromised was over $84 million with the average loss per incident being $55,000.

See:  FSB’s Warnings of Hidden Stakes of AI in Finance

Top 3 Types Targeting Businesses

  1. Email compromise without financial loss 20%
  2. Online banking fraud 13%
  3. Business email compromise resulting in financial loss 13%

Ransomware

  • 12% of all cybersecurity incidents involved ransomware where attackers control and/or steal data and extort victims for damage.
  • Cyber incidents where attackers focus solely on stealing sensitive data from a target without locking down or disrupting the victim's operations is becoming more popular.

AI-Driven Social Engineering

  • Attackers use AI to create realistic phishing emails, deepfake videos, and voice simulations to make scams more difficult to detect.
  • Vishing (video phishing) attacks are new and effective and have successfully tricked organizations into transferring millions of dollars.

Methods of Attack

  • Phishing (23%), software exploiting software/websites/services over the internet (21%), and brute-force attacks (15%) were the top methods used in breaches.
  • Government sponsored 'bad actors' are using more advanced technologies including Living Off the Land (LOTL) attacks where attackers use legitimate tools and techniques available within a tech environment to carry out malicious activities with behaviours that appear normal to the system.

Why Fintech Firms Are Prime Targets

  • They deal with sensitive information such as financial details, transaction records and personal data that is valuable to cybercriminals.
  • In today's complex world of finance, multiple platforms and third party providers can result in a high number of entry points for attackers.
  • Finance is quick to adopt new technologies which can be full of security gaps until they are discovered and patched.
  • Cyberattacks in finance are serious and can harm a company’s reputation, lead to legal fines and can cause large financial losses.

See:  Elon Musk’s X Challenges California’s Deepfake Law

Ways Fintechs Can Take Action

Strengthen Cybersecurity Foundations

    • Patch and update software regularly
    • Use multi-factor authentication (MFA)
    • Segment networks into sections to limit or contain breaches
  • Security First Design Practices
    • Prioritize cybersecurity during product/service development
    • Securely configure all systems and software by default

See:  FBI Raids Polymarket CEO’s Home After Election Prediction

Improve Staff Awareness and Knowledge

  • Train employees to identify and report phishing and other social engineering attacks
  • Organize regular cybersecurity drills to test readiness and reinforce best practices

Protect Key Systems and Data

  • Implement network segmentation to isolate sensitive systems
  • Use advanced endpoint detection and response (EDR) tools to identify and mitigate threats
  • Encrypt sensitive data when it's at rest AND in transit

Harden Authentication Processes

  • Use phishing-resistant MFA for all accounts
  • Encourage all staff to use password managers to create strong and unique credentials
  • Regularly audit and remove inactive user accounts to reduce entry points for attackers

Monitor and Manage Supply Chain Risks

  • Perform due diligence and monitor all third-party vendors and service providers
  • Regularly assess supply chain vulnerabilities and ensure all partners comply with cybersecurity best practices

See:  Key Findings from 2025 Advanced Payments and Fintech Survey

Use AI for Defence

  • AI can quickly detect any anomalies in a network's activity and assess potential threats
  • AI tools can preemptively identify phishing campaigns and suspicious behaviours

Be Prepared for an Incident and Act Quickly

  • Develop a Cybersecurity Incident Response Plan
    • Ensure all employees understand their roles in a potential breach scenario
    • Conduct routine 'fire drill' tests of the plan to identify weaknesses and build confidence
  • Back Up Data Regularly
    • Maintain encrypted backups of critical data systems and test recovery processes regularly
  • Collaborate and Partner with Threat Intelligence Networks
    • Share and receive threat intelligence to stay informed about the latest tactics and vulnerabilities

See:  Meta to Appeal €798M EU Fine for Antitrust Violations

Focus on Proactive Measures

  • Review and update systems for vulnerabilities continuously
  • Regularly simulate attacks, such as penetration testing, to identify weaknesses

Report and Respond

Cybersecurity is on Fire and Companies Need to Be Prepared

Fintech firms must manage cybersecurity as an ongoing business function instead of thinking about reacting to  one-off incident. Threats are becoming more sophisticated and frequent.  Companies need to take proactive steps now to protect their operations and data, and maintain the trust of their customers.

Learn more:  ASD Annual Cyber Threat Report 2023-2024


NCFA Jan 2018 resizeThe National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org

NCFA Financial Innovation MapNCFA Innovation Opportunity BriefsNCFA Fintech Insights
NCFA Fintech WhispererNCFA Fintech Fridays PodcastNCFA Weekly Newsletter

 

Leave a Reply

Your email address will not be published. Required fields are marked *