FinAi News

No products in the cart.

Subscribe
  • News
  • AI News Tool
  • Data
  • Transactions
  • Events
    • FinAi Banking Summit
    • FinAi Lending Summit
  • Podcast
  • WEBINARS
    • Webinar Library
Log In
No Result
View All Result
  • Banking
  • Lending
  • Payments
  • Risk & Security
  • Strategy
FinAi News
  • News
  • AI News Tool
  • Data
  • Transactions
  • Events
    • FinAi Banking Summit
    • FinAi Lending Summit
  • Podcast
  • WEBINARS
    • Webinar Library
BAN PLUS
Log In
No Result
View All Result
FinAi News
No Result
View All Result

Stealthy browser attacks can put FI networks at risk

Part 1: Bad actors can spoof trusted websites, browser extensions, CAPTCHA prompts

Yael KatzwerbyYael Katzwer
September 3, 2026
in Risk & Security
Reading Time: 3 mins read
0
Share on Facebook

For years, standard cybersecurity advice for browser users has been “don’t click on fishy links” and “don’t download anything.”

But today, browser-based attacks allow bad actors to gain access to a network without a user taking any action at all.

Sometimes just visiting a malicious website is enough to inadvertently grant access to a company’s system, Lionel Litty, chief information security officer at browser security company Menlo Security, told FinAi News.

“They may, at this point, be able to run code in the browser and, from there, potentially on your endpoint device,” Litty said.

FIs can be particularly vulnerable to this kind of attack because “they communicate with the outside world a lot,” Litty said. “They have analysts that need to do research and browse the internet. Sometimes they end up on websites that may be risky.”

Browser attacks are more widespread and harder to detect thanks to AI tools, with bad actors using AI to create credential-stealing pages and lure users to them, Karthik Vaidyalingam, field chief technology officer at data and AI security platform Varonis, said in a Sept. 1 webinar.

Convincing imitations

Mimicry has long been a strong tool in a cybercriminal’s arsenal. They can create malicious websites that resemble legitimate ones with similar URLs and they can build malware that looks like legitimate browser extensions.

IBM cybersecurity software IBM Trusteer identified one such fake Chrome extension, UnregStealer, in May.

UnregStealer looks like a legitimate Chrome extension. Once installed, it allows a cybercriminal to watch a victim’s browser activity in real-time, stealing information as the victim types it. UnregStealer targeted Latin American banks, according to IBM.

“The extension stays silent, leaves no trace and triggers no alert,” Itzhak Chimino, senior threat researcher at IBM, said in a June 16 blog post. “When the operator sees a session worth targeting — maybe a login page, payment confirmation or [money] transfer in progress — the attacker flips a switch.”

Even some of the most trusted websites can be convincingly spoofed. The FBI issued a warning on July 20 that cybercriminals have been spoofing its Internet Crime Complaint Center (IC3) website.

These sites “trick users into reporting crimes directly to attackers, but with additional details about their accounts and identities,” Varonis’ Vaidyalingam said in the webinar. “Because IC3 is normally considered a trusted reporting hub, it makes an ideal target.”

Fake security

Bad actors will even mimic browser security protocols to trick users into manually copying and pasting harmful system commands into their computers. These are called ClickFix attacks.

For example, a malicious site will mimic a CAPTCHA verification prompt to trick users into taking detrimental actions, Litty said.

a fake CAPTCHA being used to introduce malware to a victim's computer
(AI generated)

“Attackers are playing on users’ frustrations,” he said. “The user thinks, ‘Oh, I have to solve this damn CAPTCHA to get to this content. It’s telling me I need to just hit Ctrl+V to paste this string and then I can get through the CAPTCHA.’

“But what happened behind the scenes is that now the attacker was able to run content on your endpoint that they should not have been able to run and you may end up having installed malicious software and be at the mercy of an attacker now.”

People spend upward of 80% to 90% of their computer time in a browser, making browser attacks highly attractive to cybercriminals, Litty said.

FinAi Lending Summit, set for Oct. 7-8 in Las Vegas, will include speakers from Fifth Third and Capital One as well as a fireside chat with Piermont Bank founder and Chief Executive Wendy Cai-Lee. To learn more about the 2026 event and register for early-bird pricing through Sept. 4, visit here.

Tags: cybersecurityFBIIBMMenlo SecurityNewsPremium
Previous Post

Truist names Sumit Sukhramani head of lending technology

Related Posts

fraud
Risk & Security

Fraudsters hiring bankers to commit fraud; AI can help stop it

September 3, 2026
Palo Alto Networks sign
Risk & Security

Palo Alto Networks: ‘Platformization’ fused with frontier AI critical to cybersecurity

September 2, 2026
BMO headquarters in Toronto
Risk & Security

5 questions with … BMO Head of Enterprise Fraud Management Spencer Shea

September 1, 2026

EMERGING FINTECH DIRECTORY

Emerging Fintech Directory

FinAi Podcast

SPONSORED

Build an Antifragile Strategy to Outperform the Market

July 14, 2026

How AI and Product Experts Turn Fuzzy Requirements Into Focused Dev-ready Roadmaps

April 19, 2026

Is Your Technology Supplier There for You?

April 1, 2026

  • About Us
  • Help Center
  • Contact Us
  • Privacy Terms
  • ADA Compliance
  • Advertise

Connect

twitter linkedin podcast podcast podcast podcast
© 2026 Royal Media
No Result
View All Result
  • NEWS
    • All News
    • Banking
    • Lending
    • Payments
    • Risk & Security
    • Strategy
  • AI News Tool [Beta]
  • DATA
  • TRANSACTIONS
  • EVENTS
    • FinAi Banking Summit
    • FinAi Lending Summit
  • PODCAST
  • WEBINARS
    • Webinar Library
  • SUBSCRIBE
  • Log In / Account

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Unlock This Article

Create your free FinAi News account to access this article and stay informed on how AI is transforming financial services including banking, lending, payments, and risk.

Yes, I'd like to receive FinAi News updates, breaking news, and exclusive AI insights for financial services leaders.

Continue Reading with FinAi News Premium - Less than $2/Day

Upgrade to FinAi News Premium for unlimited access to news, insights, trends, and intelligence on how AI is transforming financial services including banking, lending, payments, and risk.
Upgrade to FinAi News Premium Subscription
No Result
View All Result
  • NEWS
    • All News
    • Banking
    • Lending
    • Payments
    • Risk & Security
    • Strategy
  • AI News Tool [Beta]
  • DATA
  • TRANSACTIONS
  • EVENTS
    • FinAi Banking Summit
    • FinAi Lending Summit
  • PODCAST
  • WEBINARS
    • Webinar Library
  • SUBSCRIBE
  • Log In / Account