Financial sector: Attacks on banking
service availability and advanced fraud
targeting banking clients
The financial sector, like the public sector, has experienced a rise in DDoS attacks conducted by Russian-affiliated hacktivists over the past year. For the financial sector,
particularly banks, this was a new trend linked to the conflict in Ukraine.
Number of financial sector respondents who reported different forms
of phishing or availability attacks (% of respondents)
2022
2023
84 %
Fraudulent email
100 %
89 %
Phishing
95 %
68 %
Spearphishing
86 %
68 %
Denial of Service
86 %
50 %
The number
of respondents
who experienced
DDoS attacks in 2023
increased
by nearly 20 %
60 %
70 %
80 %
100 %
Figure 18
Nearly two thirds of respondents from the financial sector reported that these attacks
impacted the availability of services, particularly affecting banking apps and websites, although disruptions generally lasted no more than an hour. Approximately half
of the entities reported a DDoS attack as the most serious incident of the year.
Fraudulent phone call campaign
impersonating NÚKIB and others
In August 2023, a fraudulent campaign was brought to NÚKIB’s attention involving the impersonation of NÚKIB and several banking institutions. Attackers either
directly impersonated NÚKIB employees, spoofing their phone numbers, or posed
as banking institution employees referring to NÚKIB staff. In both cases, fraudsters
pressured victims using various threats to transfer money from their bank accounts
to a ‘reserve back-up account’, claiming the transaction was supervised by NÚKIB.
To increase their credibility, the attackers used the names of actual NÚKIB staff
obtained from publicly available sources. They exploited the fact that these names
could be verified to support their deceptive claims by calling NÚKIB or searching
publicly available information.
32
90 %
Various forms of phishing and fraudulent
emails pose another ongoing threat to
the financial sector. This threat affects
both the organisations’ employees and
their clients, with many respondents
confirming an increase in the volume
and sophistication of phishing attacks
designed to extract funds from victims.