FinAi News

No products in the cart.

Subscribe
  • News
  • AI News Tool
  • Data
  • Transactions
  • Events
    • FinAi Banking Summit
    • FinAi Lending Summit
  • Podcast
  • WEBINARS
    • Webinar Library
Log In
No Result
View All Result
  • Banking
  • Lending
  • Payments
  • Risk & Security
  • Strategy
FinAi News
  • News
  • AI News Tool
  • Data
  • Transactions
  • Events
    • FinAi Banking Summit
    • FinAi Lending Summit
  • Podcast
  • WEBINARS
    • Webinar Library
BAN PLUS
Log In
No Result
View All Result
FinAi News
No Result
View All Result

Financial services firms face high incidence of phishing attacks

HSBC, PayPal, Credit Agricole and Wells Fargo feature among most targeted financial service providers

Jaspreet KalrabyJaspreet Kalra
August 31, 2021
in Strategy
Reading Time: 3 mins read
0
Share on Facebook

As financial institutions lean on digital channels to keep pace with customer requirements during the pandemic, cyberattackers have multiplied their efforts to gain access to user credentials via phishing attempts.

Image by CanStock

Financial services accounted for eight among the top 25 firms targeted most often by such attacks, according to a recent report from cybersecurity firm Vade. Topping the list of brands targeted by phishing attacks is the France-based $2 trillion Credit Agricole. The list is compiled from Vade’s own detection system, which found 17,755 unique phishing URLs between Jan. 1 and June 30 of this year.

Other sectors targeted by phishing campaigns include social media, cloud computing, e-commerce, telecommunications and government websites, the report noted. However, the number of incidences of Credit Agricole being targeted was so high that it inched out tech companies like Facebook and Microsoft as likely targets for impersonation. The list was compiled based on the number of newly created web pages per brand, as detected by Vade, Adrien Gendre, chief product officer at Vade, told Bank Automation News.

Vade offers security services for enterprise email inboxes and identified the phishing URLs by analyzing emails and links contained in them. With a phishing attack, usually “the goal is to capture user’s credentials,” Gendre said.

Phishing attacks can also be used to plant malware into a recipient’s computer, Gendre added. Quite often an email becomes the attack vector for such an attempt and eventually redirects the user to a fraudulent web page, designed to look like the original, that will capture the user’s credentials for subsequent use by the attacker. “Phishers continue to rely on recognizable domains from which to deliver phishing emails, with Google being the most popular service,” the report noted.

Overall, financial services companies represented 36% of all malicious URLs detected by Vade. The report noted that some of this increase in phishing activity could be attributed to the rise in loan applications for government-backed credit and moratorium programs established to manage the economic ripple effects of the pandemic.

Of the financial institutions that fall into the top 25 most target companies:

  • La Banque Postale ranked No. 5 with 7,180 URLs;
  • PayPal ranked at No. 9 with 2,601 URLs;
  • Chase ranked at No. 10 with 2, 537 URLs;
  • Wells Fargo ranked at No. 15 with 1,564 URLs;
  • Square ranked at No. 22 with 786 URLs;
  • HSBC ranked at No. 24 with 699 URLs; and
  • Banque Populaire ranked at No. 25 with 695 URLs.

Three types of phishing attacks are usually discovered in operation: generic, customized, and in-between, the Gendre noted. “Some are very generic, they don’t try to customize the [e-mail] blast. Some are very customized and targeted, built for a specific company,” he said.

While the use of additional security measures like two-factor authentication should notionally have helped stem the tide of these attacks, Gendre said Vade has observed attackers absorbing those techniques into their operations and often redirect to pages that ask for the second password layer as well.

Financial institutions can adopt some technical solutions to prevent their domain names from being replicated, “the most effective and long-term way is to the educate [the] user,” Gendre said. Such education should include clear communication on issues like how the bank normally communicates with clients, and that a financial institution is unlikely to request user credentials via email.

The Bank Automation News webinar on automation technology for exceptional bank cybersecurity and ID verification takes place on Thursday, Sept. 9, at 11:30 a.m. ET. Register here. Attendees will be able to ask questions via chat.

Tags: cybersecurityHSBCJPMorgan ChasephishingWells Fargo
Previous Post

Big Canadian banks dismissive of potential risks from open data regime

Next Post

Movers and Shakers: Bank of America’s vice chair Anne Finucane and COO Thomas Montag to retire

Related Posts

Strategy

BMO, IBM weigh in on agentic AI-quantum synergy

July 20, 2026
A data graph tracks the movement of stocks on the stock exchange in Germany. Photographer: Bloomberg Creative Photos/Bloomberg Creative Collection
Strategy

Tradeweb, 3forge embedding AI to make trading easier

July 20, 2026
To celebrate the launch of its free financial wellness program Money Roots™, Ally planted a literal money tree in New York City to give away $100,000 – both in person and online – to those who share their money story, ultimately easing financial stress nationwide. Courtesy/Ally
Strategy

Sathish Muthukrishnan leaving Ally

July 20, 2026
Next Post
Game pieces

Movers and Shakers: Bank of America’s vice chair Anne Finucane and COO Thomas Montag to retire

EMERGING FINTECH DIRECTORY

Emerging Fintech Directory

The Buzz Podcast

SPONSORED

Build an Antifragile Strategy to Outperform the Market

July 14, 2026

How AI and Product Experts Turn Fuzzy Requirements Into Focused Dev-ready Roadmaps

April 19, 2026

Is Your Technology Supplier There for You?

April 1, 2026

  • About Us
  • Help Center
  • Contact Us
  • Privacy Terms
  • ADA Compliance
  • Advertise

 [wt_cli_manage_consent]

Connect

twitter linkedin podcast podcast podcast
© 2026 Royal Media
No Result
View All Result
  • NEWS
    • All News
    • Banking
    • Lending
    • Payments
    • Risk & Security
    • Strategy
  • AI News Tool [Beta]
  • DATA
  • TRANSACTIONS
  • EVENTS
    • FinAi Banking Summit
    • FinAi Lending Summit
  • PODCAST
  • WEBINARS
    • Webinar Library
  • SUBSCRIBE
  • Log In / Account

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Unlock This Article

Create your free FinAi News account to access this article and stay informed on how AI is transforming financial services including banking, lending, payments, and risk.

Yes, I'd like to receive FinAi News updates, breaking news, and exclusive AI insights for financial services leaders.

Continue Reading with FinAi News Premium - Less than $2/Day

Upgrade to FinAi News Premium for unlimited access to news, insights, trends, and intelligence on how AI is transforming financial services including banking, lending, payments, and risk.
Upgrade to FinAi News Premium Subscription
No Result
View All Result
  • NEWS
    • All News
    • Banking
    • Lending
    • Payments
    • Risk & Security
    • Strategy
  • AI News Tool [Beta]
  • DATA
  • TRANSACTIONS
  • EVENTS
    • FinAi Banking Summit
    • FinAi Lending Summit
  • PODCAST
  • WEBINARS
    • Webinar Library
  • SUBSCRIBE
  • Log In / Account