Key Takeaways
- Financial motives drive 90% of breaches in the sector, and financial services accounts for roughly a third of all phishing volume tracked globally.
- BEC and wire fraud remain the costliest attack type, with $2.77 billion in verified US losses in 2024, and vendor impersonation is now overtaking classic CEO fraud.
- AI-generated phishing is the clearest emerging threat, with over 80% of phishing emails in a recent analysis using AI.
- High DMARC adoption without enforcement is the sector’s core paradox, and almost no institution has closed the separate MTA-STS encryption gap.
- Operational defenses like out-of-band payment verification and DMARC enforcement stop more real losses than generic awareness training.
- PowerDMARC helps financial institutions close the enforcement and encryption gaps with guided migration to p=reject, SPF record optimization, and hosted MTA-STS.
Financial services is one of the most regulated, audited, and security-mature industries in the world. It still absorbs one of the largest shares of global phishing volume of any sector, quarter after quarter.
While Banks, insurers, and fintechs spend more on security controls than almost anyone outside government and defense, phishing in financial services keeps producing headline losses, regulatory notices, and compromised customer accounts. The financial services cybersecurity statistics from 2025 and 2026 tell a consistent story: this sector isn’t targeted because its defenses are weak. It’s targeted because it sits closest to the money, and attackers have adapted faster than most institutions’ controls.
This piece walks through why finance draws this level of attention, the specific attack types that actually work against it, what those attacks cost in verified dollars and real cases, and what a modern defense stack looks like heading into 2026.
Why Financial Services Is the #1 Target for Phishing
In Verizon’s 2025 Data Breach Investigations Report, which analyzed 3,336 security incidents and 927 confirmed breaches in the Finance and Insurance sector, financial gain was the driving motive in 90% of breaches. Espionage-motivated attacks are also climbing in this sector, rising from 5% to 12% year over year, a sign that state-linked actors are taking an interest alongside financially motivated criminals. External attackers were responsible for 78% of breaches, and System Intrusion, Social Engineering, and Basic Web Application Attacks together accounted for 74% of all breaches in the sector.
The Anti-Phishing Working Group’s Q1 2025 report logged 1,003,924 phishing attacks in the quarter, the largest volume since late 2023, and found that online payment and financial (banking) sectors together accounted for 30.9% of all attacks.
The targeting isn’t limited to email, either. In the same DBIR dataset, Finance was the single most-targeted industry for Layer 3 and 4 Denial of Service attacks, absorbing 35% of them, ahead of Manufacturing and Professional Services. Attackers are working every channel that leads to money or data, and phishing happens to be the cheapest and most reliable one.
How Phishing Attacks Against Financial Institutions Actually Work
Generic phishing advice doesn’t map well onto how finance actually gets hit. The attack types below are the ones showing up in current data and real incidents.
Credential Phishing Against Online Banking
Fake login pages remain a workhorse attack, aimed at both customers and employees. A convincing clone of an online banking portal, sent through a spoofed or lookalike domain, only needs a small fraction of recipients to enter their credentials before an attacker has account access. Because these pages are cheap to stand up and easy to iterate, they remain a constant background threat even as more sophisticated attack types get the headlines.
Business Email Compromise and Wire Fraud
According to the 2025 AFP Payments Fraud and Control Survey, sponsored by Truist, business email compromise was the top fraud vector cited by 63% of organizations in 2024, and wire transfers reclaimed the top spot as the payment method most frequently targeted by BEC scammers. The tactics are shifting too: classic CEO-impersonation scams, where a fraudster poses as an executive and orders an urgent transfer, declined from 57% to 49% of reported BEC incidents, while vendor impersonation, where attackers pose as a legitimate supplier and redirect a payment, rose to 60%. Attackers are moving away from authority and toward trust in existing business relationships.
The FBI’s 2024 Internet Crime Report recorded $2.77 billion in BEC losses across 21,442 complaints, a slight decline from $2.9 billion in 2023, bringing cumulative BEC losses for 2022 through 2024 to nearly $8.5 billion.
Read more on the mechanics of this attack type in our guide to what business email compromise is and how it differs from ordinary phishing.
Vishing and Callback Phishing Impersonating Financial Brands
Callback phishing, where a fraudulent email or text convinces the victim to call a number staffed by the attacker, has become a favored route into financial accounts.
Hoxhunt’s phishing trends research found that 27.1% of callback phishing campaigns tracked between late 2025 and early 2026 impersonated financial services brands specifically, more than any other category, with PayPal, Venmo, and major retail banks among the most frequently spoofed names. These campaigns typically threaten a bogus charge or account problem and pressure the victim to call immediately, at which point a human operator walks them through handing over credentials or one-time passcodes.
AI-Generated and Deepfake Phishing
This is the clearest differentiator in the current threat landscape. CybelAngel’s 2026 analysis found that 82.6% of phishing emails detected between September 2024 and February 2025 used AI generation, a 53.5% year-on-year jump. Separately, Darktrace’s own telemetry across its financial-sector customer base logged 2.4 million phishing emails in the first half of 2025, with nearly 30% specifically aimed at VIP users such as executives and finance staff with payment authority, rather than the general employee population.
That pattern matters: attackers are increasingly choosing quality of target over sheer volume. Voice cloning adds another layer, with documented 2025 incidents involving bank employees receiving calls that convincingly mimicked an executive’s voice authorizing a wire transfer.
Account Takeover via Harvested Credentials
Account takeover looks different from the BEC pattern above. Instead of one large, dramatic loss, it shows up as many smaller, automated attempts. Proof’s ATO research, published as part of its May 2026 fraud analysis, tracked average fraudulent disbursement requests falling from $182,000 in 2022 to $118,000 in 2024, with a projected $88,500 by 2026. Fraudsters appear to be deliberately targeting amounts just under the thresholds that trigger manual review at many institutions, trading size for frequency and automation.
What Financial-Sector Phishing Actually Costs
CybelAngel puts the average financial-sector data breach at $5.9 million per incident, a figure that doesn’t include regulatory penalties or reputational damage. Combined with the $2.77 billion in annual BEC losses cited above, the picture is one of both large, concentrated losses and a steady drip of smaller ones.
Crelan Bank, January 2016
The best-documented case of a financial institution losing money to BEC is also one of the largest. Fraudsters impersonated or compromised a senior executive’s email at the Belgian bank and convinced the finance department to move funds. An internal audit later discovered that roughly €70 million, about $75.8 million, had gone missing. Multiple contemporaneous outlets, including Help Net Security, confirmed the amount and the mechanism.
It’s a decade-old case, but the pattern it illustrates, an urgent, quietly worded email routed to someone with payment authority, is still the backbone of BEC today.
Massachusetts, Connecticut, and Rhode Island identity fraud ring
A more recent and much smaller-scale case shows a different pattern still active at regional institutions. Federal prosecutors charged and later secured guilty pleas against multiple defendants who used stolen customer names, Social Security numbers, and account details to create fake identification documents, then had accomplices pose as real customers at bank branches to withdraw funds.
Two of the defendants pleaded guilty in May 2026 in connection with a scheme in which stolen identities were used to withdraw more than $1 million from accounts at banks across the three states. It’s not a phishing case in the classic sense, but it’s a direct illustration of what happens once customer data is out in the wild: it gets weaponized into account fraud, often through a completely different channel than the one that originally exposed it.
Marquis Software Solutions, 2025
In August 2025, a ransomware attack on Marquis Software Solutions, a vendor providing data analytics, CRM, and compliance tools to hundreds of banks and credit unions, exposed personal and financial data tied to at least 74 institutions. Breach notifications filed with state attorneys general beginning in December 2025 put the number of affected individuals at more than 400,000, with some filings citing figures closer to 780,000. BleepingComputer’s reporting indicates the attackers gained initial access through a vulnerability in the vendor’s firewall rather than through phishing.
The reason it belongs in this piece isn’t that it was a phishing attack itself. It’s that stolen Social Security numbers and account data from breaches like this routinely resurface months later as the raw material for targeted phishing and account-takeover attempts against the same customers.
Why This Keeps Happening in One of the Most Security-Mature Industries
Financial services has some of the highest DMARC adoption of any industry studied, yet enforcement at p=reject, the setting that actually blocks spoofed mail rather than just monitoring it, still lags at a large share of institutions, including some of the biggest names in the sector. We cover that adoption-versus-enforcement gap in detail in our blog on financial institutions and DMARC.
A few structural reasons explain the gap:
- Operational complexity: Large banks may have hundreds of legitimate third-party senders, from statement providers and marketing platforms to loan servicers. Authenticating every one of them correctly before moving to enforcement is a significant undertaking.
- Risk aversion: Security teams are often more concerned about accidentally blocking legitimate emails, such as payroll notices or loan documents, than closing the spoofing gap, even when attackers are actively exploiting it.
- AI-driven phishing: AI-generated phishing attacks are evolving faster than many legacy email filters can adapt. Institutions that once relied on typo detection and reputation scoring now need stronger authentication- and behavior-based controls instead.
DMARC Adoption and Enforcement in Financial Services: A Country Comparison
Financial regulators around the world have pushed banks toward setting up DMARC. Far fewer have pushed them toward actually turning it on. That gap between adoption (having a DMARC record) and enforcement (setting that record to p=reject, which blocks spoofed mail outright rather than just logging it) is the clearest evidence that the sector’s phishing exposure is a policy choice as much as a technical one.
PowerDMARC’s country-level email security adoption reports break this down by sector. Here’s how the financial sector compares across seven markets as of their most recent published analysis:
How Financial Institutions Can Defend Against Phishing in 2026
1. Enforce DMARC
Set DMARC at p=reject on every sending domain, including parked and defensive ones, alongside SPF and DKIM. This is now a compliance floor as much as a security measure. PCI DSS v4.0.1 Requirement 5.4.1, mandatory since March 31, 2025, requires processes and automated mechanisms to detect and protect personnel against phishing, and the PCI Security Standards Council’s own guidance names DMARC, SPF, and DKIM as example controls. Our guide to PCI DSS email compliance covers the requirement in more detail, and our FTC Safeguards Rule guide covers the equivalent expectation for non-bank financial firms.
2. Require out-of-band payment verification
Require out-of-band, multi-person verification for any wire transfer or payment-detail change, no matter how convincing the request sounds. This single control would have stopped both the Crelan Bank loss and the vendor-impersonation pattern now overtaking classic CEO fraud in AFP’s survey data.
3. Deploy phishing-resistant authentication
Specifically FIDO2 or hardware security keys, on any account with payment authority. Credential harvesting and AiTM attacks can defeat SMS codes and even some app-based MFA. They can’t defeat authentication that’s cryptographically bound to the legitimate domain. Our breakdown of MFA fatigue and push bombing covers why weaker MFA methods are increasingly being routed around rather than broken.
4. Build AI phishing detection
Build specific detection capability for AI-generated phishing rather than relying on legacy signature-based filters. Only 17% of organizations affected by payments fraud in 2025 had deployed AI-aware defenses, according to the AFP’s 2026 survey data. That’s a wide gap between the threat and the response.
5. Focus on staff training
Train staff on the specific patterns behind real losses, not generic phishing awareness. CEO fraud, vendor impersonation, and callback-phishing scripts are the patterns actually showing up in the data above. Training built around those specific scenarios holds up far better than a once-a-year “spot the phishing email” module.
6. Track third-party and vendor exposure
The Marquis Software case shows how a single vendor compromise can hand attackers the raw data needed for months of downstream phishing and account-takeover attempts against customers who never interacted with the vendor directly.
How PowerDMARC Helps Financial Institutions Close This Gap
Everything above points to the same conclusion: financial services doesn’t have a visibility problem. Most institutions can already see who’s spoofing their domain. What they lack is a fast, low-risk path from that visibility to actual enforcement, and the transport-layer protection to go with it.
PowerDMARC is built specifically to close that gap for banks, credit unions, insurers, and fintechs:
- Guided migration to p=reject: Moving from monitoring to enforcement is the step most institutions stall on for fear of blocking legitimate mail. PowerDMARC automates enforcement in a safe, guided environment, offering continuous visibility across your email channels.
- SPF record optimization: Large financial institutions routinely exceed the 10-DNS-lookup limit once every third-party vendor is accounted for, which is exactly the kind of silent failure that breaks legitimate email. PowerSPF compresses these records automatically so authentication doesn’t collapse as the vendor list grows.
- Hosted MTA-STS and TLS-RPT: As the country data above shows, almost no financial institution anywhere has closed the transport-layer encryption gap. PowerDMARC’s hosted MTA-STS forces inbound mail into encrypted channels without the manual policy-file management that keeps most teams from ever getting to it.
- Regulatory alignment: PCI DSS v4.0.1 Requirement 5.4.1, FTC Safeguards Rule expectations, and equivalent frameworks in other markets all point toward the same set of email authentication and anti-phishing controls. PowerDMARC’s full stack email authentication suite is built to support compliance directly.
- Threat intelligence to flag financial-sector risk: Vendor breaches like the Marquis Software incident show how exposed data resurfaces as targeted phishing months later. Our DMARC threat intelligence flags spoofing attempts tied to your brand before they reach a customer’s inbox.
See where your institution stands right now. Run your domain through the free Domain Analyzer for an instant read on your current SPF, DMARC, and MTA-STS posture!
The Bottom Line
Financial services isn’t targeted by phishing because it’s careless. It’s targeted because it’s where the money is, and because of the attack types working against it right now like AI-generated lures, callback phishing, and vendor impersonation. These are evolving faster than most institutions’ defenses. The sector’s high DMARC adoption but low enforcement rate is a good example of the gap between having a control in place and actually using it to block anything.
Frequently Asked Questions
Why is the financial sector the most targeted by phishing?
Financial gain is the motive in roughly 90% of breaches in the sector, per Verizon’s 2025 DBIR, because stolen credentials and successful wire fraud attempts convert directly into money. Financial institutions also sit at the center of legitimate payment flows, giving attackers a plausible cover story for nearly any request.
What is the difference between phishing and business email compromise?
Phishing is a broad category covering any attempt to trick someone into revealing credentials or clicking a malicious link. Business email compromise is a specific, usually more targeted form of phishing that impersonates a trusted party, often an executive or vendor, to redirect a real payment or sensitive data transfer.
How much do phishing and BEC cost financial institutions?
The FBI’s 2024 Internet Crime Report recorded $2.77 billion in BEC losses across 21,442 complaints in the US alone. CybelAngel separately puts the average financial-sector data breach at $5.9 million per incident, not including regulatory penalties.
What is vishing/callback phishing, and why does it target banks specifically?
Callback phishing uses a fraudulent email or message to get the victim to call a phone number, where a human operator then talks them into handing over credentials or one-time codes. Financial brands are impersonated more than any other category in current callback-phishing data, since a fake fraud alert from a bank creates urgency that’s easy to exploit.
Can DMARC stop phishing attacks against a financial institution?
DMARC stops attackers from spoofing your own domain in emails sent to customers and partners, which closes off one major phishing vector. It doesn’t stop every phishing attack, including ones that use lookalike domains or target your customers’ inboxes directly, so it works best as one layer in a broader defense stack.
What is the single most effective defense against BEC in financial services?
Out-of-band, multi-person verification for any payment or payment-detail change request is the control most directly tied to stopping real BEC losses, since it removes the single point of failure that email-based social engineering relies on.
- Phishing in Financial Services: Attack Trends, Costs & Defense in 2026 - August 7, 2026
- Top Email Reputation Services in 2026 - August 6, 2026
- Fax Security: A Complete Guide to Protecting Sensitive Documents in 2026 - July 30, 2026