The financial sector has spent years hardening its own defenses. It worked. Direct ransomware attacks on financial institutions dropped from 191 confirmed incidents in 2023 to just 55 in the first half of 2025. Major threat groups have been disrupted by law enforcement, and the institutions themselves have invested heavily in detection and response capabilities. The attackers noticed. They didn't stop. They rerouted.
The vulnerability that remains sits inside the extensive network of third-party vendors that financial institutions depend on for core operations. TheBlack Kite Research Group™ analyzed 140 vendors with client bases comprising at least 10% financial sector customers. These vendors span payment infrastructure, data management, software development, and cloud services. They don't have the same regulatory pressure, security budgets, or board-level scrutiny that their financial institution clients do. And the data shows it.
A financial institution's own cyber rating tells you nothing about what its vendors look like from the outside. Among the 140 vendors in this sample, the average Ransomware Susceptibility Index® (RSI™) score was 0.437, placing the typical financial sector vendor squarely in the high-susceptibility range. Vendors scoring above 0.6 on the RSI are 96x more likely to experience a ransomware attack than those scoring below 0.2. The Snowflake breach, the Cleo Managed File Transfer campaign, and the Fiserv service outage each showed how a single vendor compromise translates into cascading exposure across dozens of financial institutions at once.
This report is your blueprint for identifying where vendor risk is concentrated, what the attack patterns look like from the outside, and what a proactive financial sector TPCRM program does differently.
Key Findings From the 2025 State of Financial Services Report
191 Confirmed Ransomware Incidents in 2023, Down to 55 by Mid-2025
The decline in direct attacks on financial companies is real, but it reflects a shift in attacker strategy more than a reduction in attacker capability. Threat groups that previously targeted banks and credit unions directly have fragmented and redirected toward the vendors those institutions rely on. Third-party and supply chain attacks are now the primary vector through which financial sector organizations face ransomware exposure. The institutions hardened their perimeter. The perimeter just moved.
Average RSI of 0.437 Puts Financial Sector Vendors in the High-Susceptibility Range
Among the top 20 vendors serving the financial sector, the average technical security score was B (85), which looks reasonable in isolation. The averageRansomware Susceptibility Index® (RSI™) for that same group was 0.387. That divergence is the core problem. A B-grade score does not mean low ransomware susceptibility. Across all 140 vendors, the RSI climbs to 0.437. Companies with RSI scores between 0.6 and 1.0 are 96x more likely to experience a ransomware attack than those below 0.2. That multiplier is not hypothetical. It reflects observed breach patterns across the sector.
31 Vendors Carry Unpatched Critical Vulnerabilities at CVSS 9 or Higher
Among the top 20 vendors, 9 had at least one critical vulnerability scoring 9 or above on the CVSS scale. Across all 140 vendors, 31 carried unpatched CVEs at CVSS ≥ 9. The average Data Breach Index (DBI) across the full vendor sample was 0.136, reflecting significant historical breach exposure concentrated in a subset of the group. The Cleo File Transfer campaign made the practical consequence of this visible. Vendors running widely used file transfer platforms with documented, unpatched vulnerabilities became the entry point into the financial supply chains those platforms served.
41% of Vendors Are Flagged on the Oracle Data Breach FocusTag®
FocusTags® surface active security events tied to specific vendors in a monitored ecosystem. The Oracle Data Breach FocusTag® emerged as the most widespread signal across the 140-vendor sample. 41% of vendors carried this tag, indicating systemic exposure to compromised credentials and vulnerable Oracle-dependent infrastructure. For financial institutions using Oracle-reliant vendors for data management, banking operations, or compliance workflows, that exposure doesn't surface through conventional point-in-time assessments. It requires continuous, intelligence-driven monitoring to catch.
Patch Management Failures Leave 65% of Financial Vendors Running Outdated Systems
Among financial sector vendors, 65% are not maintaining current patch levels. That means the majority of the vendor ecosystem is operating with known, fixable vulnerabilities still in place. Application security gaps compound the exposure: roughly 1 in 9 vendors carries critical application-layer weaknesses. The specific weaknesses documented across the sample include:
Unprotected login pages with no bot detection
Missing CSRF tokens on sensitive transaction interfaces
Exposed HTTP headers revealing server and framework details
Financial institutions that are themselves compliant can still be indirectly exposed through vendors that are not.
2025 Financial Services Report: Vendor Risk at a Glance
0
ransomware attacks hit the financial sector in 2023 · down to 55 by mid-2025
0
vendors analyzed with 10%+ financial sector client bases
0.000
Average RSI across all 140 vendors
0%
of vendors flagged with Oracle Data Breach FocusTag®
0
vendors carrying critical vulnerabilities at CVSS ≥ 9
0%
of vendors not maintaining current patch levels
0
vendors with Hacktivist Activity scores of D–F
Ransomware in Financial Services Has Shifted to the Vendor Layer
Declining Direct Attacks Reflect Attacker Adaptation
Ransomware incidents targeting financial companies fell from 191 in 2023 to 156 in 2024 and 55 confirmed cases through mid-2025. The Depository Intermediation subindustry still accounts for 27.4% of attacks within the sector, the highest concentration of any subindustry, but that share is declining as attackers move toward softer targets elsewhere in the financial ecosystem. Disruption of major groups by international law enforcement contributed to the drop. What it didn't do was eliminate the threat. Smaller, newer groups absorbed displaced operators and picked up where the dismantled organizations left off.
LockBit 3.0 and CL0P Lead a Fragmenting Attacker Landscape
Three groups account for the majority of tracked ransomware incidents in the financial sector. LockBit 3.0 holds 12.6% of attributed attacks, CL0P holds 13.7%, and AlphVM (BlackCat) follows closely. The most significant figure is the 26.9% attributed to the "Others" category, which captures dozens of emerging and short-lived groups that don't yet appear in standard threat actor watchlists. That fragmentation creates a practical monitoring problem.Threat actor monitoring built around a fixed list of named groups misses the majority of active threat activity targeting the financial sector today.
The U.S. Accounts for 44% of Incidents, but the 'Others' Geography Is Growing
U.S. financial companies represent 44% of global ransomware incidents in the sector, reflecting both the concentration of high-value targets and the digital maturity that makes American institutions attractive. The "Others" geography category sits at 30.4%, a share that reflects financially motivated actors expanding into markets with less regulatory oversight and less mature security postures. Financial institutions with vendor relationships outside of the traditional targeted geographies should treatgeopolitical monitoring as a live input to vendor risk decisions, not a supplementary dashboard.
Institutional Defenses Are Strong; Vendor Defenses Are Not
The gap between how well financial institutions protect themselves and how well their vendors do is the central finding of this report. Banks have Chief Information Security Officers, dedicated security budgets, regulatory examinations, and law enforcement collaboration. The vendors serving them frequently have none of those things at the same level.Nth-party visibility into the full vendor ecosystem is the structural gap most third-party risk management solutions haven't closed. Compromising a bank directly has become significantly harder. Compromising a vendor the bank trusts has not.
Systemic Vendor Vulnerabilities Are Putting Financial Institutions at Risk
Credential Exposure Is Pervasive and Often Predates the Breach by Months
Credential theft is the most consistently exploited attack vector in vendor-originated financial sector breaches. It doesn't require technical sophistication. A valid set of employee credentials from a stealer log is enough to gain initial access to vendor systems without triggering any technical detection. Among the 140 vendors analyzed, 13 received Hacktivist Activity scores of D or F. The more telling signal is that 30 vendors had employee credentials appearing in stealer logs. Those credentials were available to threat actors before any breach was disclosed. Vendor employees compromised through phishing campaigns months before an incident appears in public reporting are one of the most reliable early indicators of a coming financial sector third-party event.
Five Vendors Were Actively Flagged in the Cleo File Transfer Campaign
The Cleo MFT exploitation is the clearest example in this report of how an unpatched vendor CVE becomes a financial sector breach. CL0P targeted vulnerabilities in Cleo's file transfer products used across logistics and financial services supply chains. Five vendors in this report's sample were flagged with a Cleo File Transfer FocusTag®. The attack affected organizations using three distinct Cleo products. The institutions most exposed were those whosevendor risk monitoring programs depended on vendor self-reporting rather than external intelligence. By the time vendors disclosed the issue, operational disruption had already occurred.
Application Security Gaps Create Entry Points Into Financial Institution Data
Web application vulnerabilities are particularly dangerous for financial sector vendors because they sit at the interface between vendor systems and financial institution clients. Among the 140 vendors, roughly 1 in 9 carries at least one critical application-layer weakness. The pattern of weaknesses documented in this report points to vendors that have not invested in application security at a level commensurate with the sensitivity of the data and systems they touch. For vendors handling payment processing, settlement services, or customer data on behalf of financial institutions, those gaps are not contained to the vendor's own environment. They extend directly to the financial institution's data and regulatory exposure.
31 Vendors Create DDoS Risk Through DNS Amplification Vulnerability
31 vendors in the analyzed sample are vulnerable to DNS amplification attacks. DNS amplification is a technique threat actors use to generate large-scale traffic floods against target infrastructure. For cloud-based financial services platforms, SaaS providers, and payment infrastructure companies, this creates a service availability risk that most vendor risk programs don't model. The risk isn't only to the vendor. A vendor whose infrastructure can be weaponized as a DDoS amplification node creates operational continuity risk for every financial institution that depends on their services.
South Korea recorded zero finance-sector disclosures in both 2023 and 2024, then recorded 32 in 2025. Nearly all fell in a single month, nearly all from Qilin's campaign against one managed service provider.
The incident illustrates how vendor concentration can transform anentire national financial sector into a single attack surface.
Finance's Vendor Ecosystem Grew More Vulnerable at Every Layer in 2025
Finance's Top 20 Vendors Carry Four Times the C-Band Cyber Ratings Than the Broader Ecosystem
Security posture degrades with proximity to the financial sector. Across the broader sample of 17,000+ finance-related vendors, 60% earn an A-band Cyber Rating. Within the 140 most concentrated vendors, that share falls to 36%. Among the Top 20 most relied-upon vendors, only 32% reach the A band, while 11% fall into the C band. That is four times the C-band share of the broader ecosystem.
Confirmed Breaches Across 140 Vendors Grew From 6 to 39
Topline RSI™ scores held broadly steady across vendor pools, but breach history accelerated. Within the 140 vendors, confirmed breaches climbed from 6 to 39 in twelve months. Among the Top 20, the number with a confirmed breach rose from 1 to 7, a sevenfold increase in the segment carrying the highest exposure sensitivity. The cyber risk intelligence gap between stable scores and rapidly expanding breach records is the defining tension in this year's data.
57.9% of Finance's Core Vendors Already Have Attacker Phishing Infrastructure Targeting Them
Control-level findings reveal active threat indicators, not just theoretical exposure:
57.9% carry active phishing infrastructure already impersonating those vendors
46.4% show signs of communication with known malicious IP addresses
42.1% have employee credentials in stealer logs
These are not latent risks. They are confirmed signals that finance's core vendors are already embedded in attacker workflows.
Marquis Software's RSI™ Flagged 11.6x Elevated Attack Likelihood One Month Before the Breach
One month before the August 2025 attack, Marquis Software Solutions carried an RSI™ of 0.437, sitting above both the broader vendor sample average (0.351) and the 140-vendor finance average (0.404). The institutions running continuous monitoring against that score had a materially different window to act than those waiting on the breach notification, which arrived 10+ weeks after initial intrusion.
The 2026 Financial Services Data Makes the Case for Predictive Vendor Defense
Map Every Nth-Party Dependency Before the Next Vendor Compromise Reveals One You Didn't Know You Had
Korean Leaks and Marquis Software share a root cause: incomplete visibility into the vendor relationships that ultimately created the exposure. Nth-party visibility, mapping the vendors your vendors depend on, is the precondition for every other action a third-party cyber risk management program takes.
Replace Annual Reviews With Continuous Monitoring. Vendor Exposure Can Quadruple in 12 Months.
Inside twelve months, the 140-vendor pool's exposure profile changed fundamentally:
Vendors carrying critical CVEs grew 4.9x
KEV-tagged vendors more than doubled
Confirmed breaches climbed sixfold
A vendor that earned a clean rating at last year's review may carry an actively exploited weakness today. Continuous, automated monitoring across Black Kite's 20 risk categories surfaces those changes when they happen, not at the next assessment window.
Surface Affected Vendors the Moment a New Vulnerability Is Disclosed, Before the Vendor Knows It
Over 48,000 CVEs were published globally in 2025, an 18% increase, and AI-assisted discovery tools entering in 2026 are positioned to accelerate that volume further. The 2026 Supply Chain Vulnerability Report documents how FocusTags® surface the precise vendors in an institution's ecosystem affected by each new disclosure, often before the vendor has issued its own advisory.
Centralize Vendor Engagement So Fast Detection Leads to Fast Resolution
Identifying a vendor vulnerability is only the first step. The Bridge™ replaces email threads and manual follow-up with a centralized workspace where vendors receive asset-level findings, see real-time ratings impact, and respond directly to outstanding items. The result is a single auditable view of remediation progress across the full vendor ecosystem.
Translate Vendor Cyber Risk Into Probable Financial Exposure So Boards and Regulators Act on It
Boards do not act on technical scores. They act on financial exposure. Black Kite's Financial Cyber Risk Quantification, built on Open FAIR™ modeling, translates each vendor's cyber posture into probable financial impact denominated in dollars, bridging the gap between technical findings and the executive conversations that determine remediation priority and budget.
Automate DORA, GLBA, and FFIEC Compliance Mapping So Vendor Evidence Review Takes Minutes, Not Weeks
Black Kite's AI-powered assessments read vendor documentation including SOC 2 reports and questionnaires, extract verbatim evidence, identify gaps, and map findings directly to the regulatory frameworks (DORA, GLBA, FFIEC, NYDFS, PCI-DSS, and more) against which financial institutions are held. What previously took analysts weeks resolves in minutes.
How Black Kite Built the 2026 Financial Services Cybersecurity Report
Three Years of Verified Finance-Sector Ransomware Disclosures
The ransomware dataset draws from public extortion sites and verified incident records, covering only confirmed victims where both encryption and data exfiltration were verified and attribution to a known group was clearly established. To prevent data inflation, chain and network attacks were counted as a single incident unless distinct disclosures existed.
The 140-Vendor Pool Had One Qualification: 10% or More Revenue From Financial Clients
Vendor selection was governed by a single threshold: any vendor whose client base includes at least 10% financial sector customers qualified for the 140-vendor pool. The Top 20 represents the vendors most relied upon by financial institutions, ranked by breadth of financial-sector customer base. The broader sample of approximately 17,000 vendors represents companies actively monitored by Black Kite's financial sector customers, serving as a representative baseline.
Insurance Carriers (NAICS 524) Were Excluded. Insurance Benefit Funds Were Retained
Industry classifications align to NAICS codes for analytical consistency. Code 524 was excluded due to its structural and regulatory segmentation from the core financial sector. Code 5251 was retained, as these entities function as financial investment mechanisms. 52 NAICS codes were reviewed in total.
Pre- and Post-Incident Posture Assessments Power the RSI™ Predictive Analysis
The Black Kite platform assessed each organization's posture at pre-incident and post-incident windows, enabling comparative susceptibility analysis. The findings reflect only publicly disclosed ransomware incidents and observable vendor risk indicators. The figures presented represent a conservative lower bound of systemic third-party risk exposure in the financial sector.
Four Shifts That Replace a False Sense of Security in Financial Sector TPCRM
1. Enhance Visibility Into the Full Nth-Party Ecosystem
Most financial institutions can tell you who their direct vendors are. Far fewer can tell you what those vendors depend on in turn. That second layer is where the Snowflake incident began. The breach didn't start at a bank. It started at a cloud platform that banks accessed through their vendor relationships.Nth-party visibility into fourth- and fifth-party dependencies is not an advanced capability for large institutions only. It's the baseline required to detect the cascading risks this report documents. Every entity contributing to critical financial operations needs to be in scope.
2. Replace Point-in-Time Assessments With Continuous Vendor Risk Monitoring
An annual questionnaire completed in January doesn't detect a patch cycle that slipped in March, a new Known Exploited Vulnerability added to CISA KEV in June, or employee credentials that appeared in a stealer log in September.Continuous monitoring of vendor cyber posture closes the window between those events and your awareness of them. The risk signals documented in this report did not wait for a scheduled review cycle to appear. They surfaced between assessments, in real time, in vendors that looked acceptable on paper.
3. Build a Ransomware Susceptibility Program Specifically for Vendor Risk
The RSI divergence documented in this report is the practical argument for this shift. A vendor scoring B on technical ratings but 0.437 on RSI is not a low-risk vendor. It's a vendor whose ransomware exposure is significantly higher than its overall security posture suggests. Financial institutions should incorporateRansomware Susceptibility Index® (RSI™) thresholds directly into vendor criticality tiers. Vendors above 0.6 warrant enhanced monitoring cadences, accelerated remediation requirements, and explicit incident response coordination agreements before an event occurs.
4. Collaborate With Vendors to Resolve Risk, Not Just Document It
Vendor evaluation produces findings. What it doesn't automatically produce is remediation. The gap between identifying a vulnerability in a vendor and having that vendor fix it is where most third-party risk programs stall. Financial institutions that share specific intelligence with vendors, align on remediation timelines, and establish clear accountability for supply chain security get faster and more complete resolution than those that deliver findings reports and wait.The Bridge™ provides the collaborative workspace that makes that engagement structured and trackable rather than reliant on email threads and manual follow-up.
How Black Kite Built the 2025 State of Financial Services Report
140 Vendors Selected Based on a 10% Financial Sector Client Threshold
The vendor sample in this report was built around a specific criterion: vendors whose client base is at least 10% financial sector customers, regardless of company size. That threshold produced a 140-vendor set with genuine exposure relevance to the financial services supply chain. The sample spans four primary NAICS categories:
Professional, Scientific and Technical Services (NAICS 54)
Computer Systems Design and Related Services (NAICS 541)
Software Publishers (NAICS 5112)
Manufacturing (NAICS 33)
Company size was estimated using public financial disclosures, third-party organizational databases, and benchmarking against industry standards.
Multi-Source Intelligence Curated by Black Kite Research Group™ From January 2023 Through May 2025
All ransomware data in this report reflects only confirmed victims where both encryption and data exfiltration were independently verified and attribution to a known ransomware group was clearly established. The Black Kite Research Group™ aggregated threat intelligence, ransomware tracking data, vendor ecosystem telemetry, and cyber risk signals across surface, deep, and dark web sources over a 28-month window.
Industry classifications follow NAICS codes. NAICS 524 (Insurance Carriers) was excluded for structural segmentation reasons. NAICS 5251 (Insurance and Employee Benefit Funds) was included as it represents financial investment mechanisms rather than insurance providers.
RSI™, DBI, CVSS, and FocusTag® Data Applied Across All 140 Vendors
Each vendor in the sample was assessed using Black Kite's full technical rating suite. Scores were generated across 20 risk categories, translated into letter grades (A through F), and supplemented with the Ransomware Susceptibility Index® (RSI™), Data Breach Index (DBI), and active FocusTag® intelligence. The standardized victim counting methodology used throughout prevents data inflation by counting clinic chains, dealer networks, and holding structures as single incidents unless separate disclosures exist for each.
Extended Risk Intelligence Added Control-Based Findings Across the Full Vendor Sample
The technical rating data is supplemented in this report by control-based findings that surface risks the numerical scores don't fully capture. Across the 140-vendor sample, Black Kite Research Group™ documented the following:
30 vendors with employee credentials appearing in stealer logs
109 of 140 vendors with missing or invalid DMARC records
31 vendors vulnerable to DNS amplification attacks
Multiple vendors with cross-site request forgery and phishing domain exposure
Together with therisk management methodology underlying the Black Kite platform, these findings provide a more complete picture of vendor-side exposure than technical ratings produce in isolation.