-

Filigran Report: 90% of Financial Sector Breaches Driven by Financial Gain as AI and Supply Chain Threats Escalate

Shadow AI, third-party compromise and double extortion ransomware converge as DORA makes intelligence-led resilience a regulatory requirement

PARIS--(BUSINESS WIRE)--Filigran, the European open-source threat management company, today released Cyberthreats in the Financial Sector, a report mapping the evolving threat landscape facing financial institutions and the regulatory shifts redefining how they must respond.

The report finds that 90% of breaches affecting financial institutions in 2025 were financially motivated, with data breaches accounting for 64% of incidents and ransomware 36%. The financial sector was the second-most expensive industry for data breaches, at $5.56 million per breach.

AI is compounding the risk. Shadow AI accounted for 20% of AI-related breaches, and 97% of affected organizations lacked adequate access controls. Supply chain compromise reached systemic levels, with third-party involvement in 30% of financial-sector breaches.

With the EU's Digital Operational Resilience Act (DORA) now enforceable, financial institutions must demonstrate intelligence-led risk management, threat-led penetration testing on live systems, and robust third-party oversight.

Download the full report at filigran.io.

FAQs

How can financial institutions prepare for DORA's threat-led penetration testing requirements?

DORA Articles 26 and 27 require intelligence-led penetration tests at least every three years on live production systems, with supervisors expecting measurable improvement across cycles. Filigran's XTM platform connects threat intelligence directly to attack simulation, enabling continuous, threat-led validation aligned with frameworks like DORA and CTEM.

How is ransomware targeting financial institutions differently?

Approximately 12.8% of B2B financial organizations experienced ransomware in 2025, with attackers increasingly combining encryption with data exfiltration in double-extortion tactics that trigger regulatory reporting obligations. Filigran's report found double-extortion is now the dominant ransomware tactic against financial institutions.

Why is third-party cyber risk now a systemic threat to financial institutions?

Third-party breaches like MOVEit continued to affect major banks into 2025, and the Bybit $1.5 billion theft exposed how supply chain weaknesses in transaction flows can lead directly to extreme loss. Filigran's research recommends continuous intelligence sharing and attack simulation across the vendor ecosystem.

About Filigran

Filigran, a cybersecurity company, offers an open-source, AI-powered, threat-informed approach to Continuous Threat Exposure Management (CTEM). Its eXtended Threat Management (XTM) platform delivers threat intelligence, exposure validation, and cyber risk reduction. Learn more: Website – Blog – LinkedIn – X

Contacts

Media Contact
Treble
McKenzie Covell
filigran@treblepr.com

Filigran


Release Versions

Contacts

Media Contact
Treble
McKenzie Covell
filigran@treblepr.com

More News From Filigran

Filigran Accelerates Global Enterprise Growth With Executive Leadership Expansion Across Americas Sales and Cybersecurity

PARIS--(BUSINESS WIRE)--Filigran, the European open-source threat management company, today announced two additions to its leadership team: Tim Durkee as senior vice president of sales, Americas, and Mathieu Rigotto as chief information security officer. The strategic hires come as Filigran experiences rapid international growth following record revenue and platform expansion. Durkee brings more than a decade of experience building enterprise sales organizations and taking cybersecurity and ent...

Filigran Partners with SEK to Bring Managed Threat Intelligence to Latin America

PARIS & SÃO PAULO, Brazil--(BUSINESS WIRE)--Filigran, the European open-source threat management company, today announced a partnership with SEK, one of Latin America's largest cybersecurity providers. SEK will build analyst-vetted intelligence and exposure validation into the managed security services it runs for enterprises in Brazil, Argentina, Chile, Colombia and Peru. OpenCTI supplies the intelligence layer, feeding threat context into the SOC workflows that SEK's analysts already run, rat...

Filigran Adds Attack Chaining to OpenAEV for Autonomous Penetration Testing and Red Teaming

PARIS--(BUSINESS WIRE)--Filigran, the European open-source threat management company, today announced Attack Chaining, an attack-path validation capability that automates penetration testing and red teaming with OpenAEV, the company's adversarial exposure validation product. The capability arrives today as part of OpenAEV v3.Adversaries do not run techniques in isolation. They chain them: reconnaissance surfaces a target, a credential dump yields a password, that password opens the next machine,...
Back to Newsroom