Software Flaws Overtake Stolen Credentials as Banks’ Top Cyber Threat
Banks have traditionally treated stolen credentials as the main route into their systems, but the rapid adoption of cloud services, third-party software and interconnected suppliers has widened the attack surface. Verizon’s 2026 Data Breach Investigations Report says unpatched software has now overtaken compromised credentials as the leading entry point for attackers targeting banks, elevating patch management from a routine technology task to a core financial-security priority.
The 2026 Verizon report found that 98% of attacks affecting the financial-services industry were financially motivated, underscoring banks’ continued appeal to ransomware operators, fraud groups and data thieves. It also identified a significant rise in risk linked to third-party suppliers, which can expose multiple institutions through a single weakness. No specific loss amount was disclosed for the trend, but the findings increase pressure on banks to accelerate software updates and tighten vendor oversight.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.