
The attacker who hit the most financial services organizations over the past 12 months never phished a password. They called an IT support line, convinced an employee to reset their MFA, and registered their own device on the network.
CrowdStrike’s 2026 Financial Services Threat Landscape Report, covering activity from April 2025 through March 2026, identified Mutant Spider as the single most active threat to the sector. The group’s primary technique was voice phishing over Microsoft Teams. Operators impersonated internal IT support, convinced employees to reset credentials and multifactor authentication, then registered their own devices on corporate networks. The security control worked exactly as designed — and that was the problem.
Within days, the FBI published a public service announcement warning about Kali365, a phishing-as-a-service platform sold on Telegram for as little as $250 a month. It captures Microsoft 365 OAuth tokens through the legitimate device code authentication flow. MFA fires on the victim’s device, not the attacker’s. The token grants persistent access to Outlook, Teams, and OneDrive without triggering another MFA prompt.
Verizon’s 2026 Data Breach Investigations Report confirmed that credential theft dropped to 13% of breach initial access vectors. Vulnerability exploitation took the top position at 31%, displacing what the report called the longtime leading initial-access category.
Three independent sources, same structural finding. MFA protects password-based authentication, but the attacks dominating financial services increasingly bypass password theft through resets, token grants, and exploitation.
The numbers behind the shift
The sector ranked as the fourth most targeted by Q1 2026, accounting for 12% of all observed adversary activity, according to the CrowdStrike report. Globally, financial institutions faced 43% more hands-on-keyboard intrusions in 2025 compared to two years earlier. In North America, that figure was 48%.
Big game hunting operators named 423 financial services entities on dedicated leak sites during the reporting period. That is a 27% increase from the 334 entities named the prior year. REVENANT SPIDER, which operates the Qilin ransomware-as-a-service program, posted the most victims in the sector of any e-crime adversary. The group’s victim count jumped from 14 to 97 over the reporting period.
Related: AI helps cut retrieval costs by 30 percent
E-crime actors drove 75% of hands-on-keyboard intrusions against the sector. State-sponsored adversaries accounted for the remaining 25%. That ratio has not moved since 2023. What changed is the total volume and the sophistication of the access techniques.
How Mutant Spider operates
Mutant Spider’s vishing campaigns over Microsoft Teams represent a structural shift in initial access. They impersonate IT support, manipulate employees into resetting MFA, then deploy custom post-access tools including PrionFlaire, SocksLoader, and SleepyMutagen. The company believes the group sells that access to ransomware operators.
“No zero day is needed if all an attacker has to do is call the help desk and say they forgot their password,” Adam Meyers, senior vice president of counter adversary operations at CrowdStrike, told the outlet.
Scattered Spider returned to aggressive ransomware operations against insurance companies from April through July 2025, following a significant operational pause. The group ran the same playbook: help desk social engineering; credential and MFA reset requests; then lateral movement through integrated SaaS applications. In September 2025, the U.K.’s National Crime Agency arrested and charged two members for allegedly targeting Transport for London. The U.S. Department of Justice separately charged one of them in connection with multiple cyberattacks against U.S. critical infrastructure.
State-sponsored threats compound the problem
DPRK-nexus adversaries stole $2.02 billion in digital assets in 2025, a 51% increase from the prior year. In February 2025, Pressure Chollima executed the largest single theft ever reported, stealing $1.46 billion in cryptocurrency by compromising Safe{Wallet}, a digital asset management platform supporting the Bybit exchange, after a developer’s machine was infected through a trojanized Python project.
China-nexus groups conducted sustained campaigns against financial institutions across multiple continents. Hollow Panda exploited Check Point VPN appliances to target banks in the Philippines, Indonesia, and Brazil. Vault Panda gained initial access through compromised VPN and firewall appliances across four continents. Every state-sponsored campaign the company documented shared a common thread. The adversary’s first move targeted an identity, a credential, or a trusted access path.
The Kali365 attack path
The FBI’s May 21 public service announcement on Kali365 confirmed the second attack path. The platform exploits Microsoft’s OAuth 2.0 device authorization grant flow, a mechanism designed for devices like smart TVs and conference room systems that cannot support interactive login. It sends phishing emails impersonating trusted services like Adobe Acrobat Sign, DocuSign, and SharePoint. The email contains a device code and instructions to visit a legitimate Microsoft verification page. The victim authenticates normally. MFA fires. The token goes to the attacker.
Related: Why You Should Invest in Network Today: Your Blueprint for Unstoppable Success
Arctic Wolf documented a three-tier commercial structure for Kali365: an admin tier for the developers, an agent tier for resellers, and a client tier for paying affiliates. Subscription pricing runs from $250 for 30 days to $2,000 for a year. The platform supports 14 languages and includes AI-generated phishing lures, automated campaign templates, and a real-time tracking dashboard.
The device code flow is not a vulnerability. It is a feature. The company designed it for devices that cannot support interactive login. The problem is that default Entra ID configurations do not restrict its use, and most organizations have never audited whether any legitimate workflow actually requires it.
What the Verizon DBIR adds
The DBIR analyzed more than 22,000 confirmed breaches across 145 countries. Vulnerability exploitation at 31% now leads credential abuse at 13%. The median time for full patching increased to 43 days, up from 32. Organizations patched only 26% of critical flaws in CISA’s Known Exploited Vulnerabilities catalog, down from 38% the prior year.
Mike Riemer, SVP and field CISO at Ivanti, told the outlet that the speed problem compounds the budget misalignment. “Threat actors are reverse engineering patches, and the speed at which they’re doing it has been enhanced greatly by AI,” Riemer said. “They’re able to reverse engineer a patch within 72 hours. If I release a patch and a customer doesn’t patch within 72 hours of that release, they’re open to exploit.”
Elia Zaitsev, CrowdStrike’s CTO, said traditional defense models are being outpaced. “People are forgetting about runtime security,” Zaitsev said. “We’ve done this before, with endpoint and virtualization and cloud. People really focused on, hey, let’s patch all the vulnerabilities. Impossible.”
The industry has spent two decades building defenses against credential theft. The attacks that are actually working in the sector either remove MFA through social engineering or capture tokens through legitimate authentication flows where the system does not protect the attacker’s session. Security directors need to run an audit against their environment this week.

