
India’s BFSI sector is facing a progressively complex cyber-threat environment in which targeted intrusion, ransomware, data exposure, digital-payment fraud, identity compromise and third-party risk are converging across the financial ecosystem. The observed 2026 activity indicates that attackers are increasingly exploiting employees, customers, cloud services, payment workflows and interconnected technology providers rather than relying solely on direct compromise of banking infrastructure.
APT-linked campaigns demonstrate the use of recruitment, tax and regulatory-themed social engineering, legitimate RMM tools, PowerShell, malicious documents and cloud/SaaS platforms for persistence, command-and-control and data collection, while ransomware remains a multi-actor threat with direct and third-party implications for financial institutions. At the same time, data breaches, data leaks and credit-card incidents represent the largest observed categories of finance-sector cyber activity, increasing downstream risks such as fraud, account takeover and customer impersonation. The threat landscape is further evolving through AI-assisted phishing, vishing, deepfake impersonation, UPI and mobile-banking abuse and exploitation of legitimate cloud infrastructure.
For BFSI leadership, the strategic priority is therefore to move from predominantly perimeter-focused security toward an integrated resilience model that connects cyber defense, fraud prevention, identity protection, third-party risk management, privacy and regulatory response.
The quantitative findings in this report reflect CYFIRMA-validated activity from surface-, deep-, and dark-web sources plus CYFIRMA’s internal research (specific windows: March–August 2026 for finance-sector incident counts; Jan 2025–August 2026 for ransomware), combining public and internal findings as noted in context.
Figures are indicative of observed trends within the stated periods and sources, not a complete census of BFSI-sector cyber activity.
Operation Shadow Recruit is a multi-stage malware campaign targeting Indian government job seekers by abusing a legitimate recruitment notification as a social-engineering lure. The infection begins with a ZIP archive disguised as a document-verification package. The archive contains a malicious LNK shortcut, PowerShell script, and executable, with the latter two hidden from the victim. The LNK uses a legitimate browser icon and launches the PowerShell script in hidden, non-interactive mode, initiating the subsequent infection stages.
The PowerShell script executes a Base64-encoded command that downloads and installs a legitimate remote monitoring and management (RMM) agent using attacker-controlled enrollment parameters. This provides the threat actor with potential persistent remote access and capabilities such as command execution, file transfer, and system monitoring. Following installation, the script executes a . NET-based dropper that creates a Windows-like directory under %APPDATA% and extracts the final payload and decoy document components.
The .NET dropper establishes persistence through a scheduled task configured to execute the malware at user logon and periodically thereafter. If task creation fails, it uses a Startup-folder shortcut as a fallback. It also creates temporary scripts to generate the persistence shortcut and employs Windows-like naming to blend into the environment. Concurrently, a decoy PDF containing a government recruitment notice is downloaded from attacker-controlled infrastructure and displayed to the victim to conceal the malicious activity.
The final payload, SheetAgent RAT, is a custom NET-based remote access trojan that uses Google Sheets and Google Drive APIs as a backup C2 mechanism. Hardcoded service-account credentials, including an RSA private key, enable authentication to attacker-controlled cloud resources. A structured spreadsheet tracks infected hosts, commands, command output, public IP addresses, status information, alerts, and URL-monitoring data, effectively converting the spreadsheet into a lightweight C2 channel.
SheetAgent also implements extensive anti-analysis capabilities, including virtualization, sandbox, process, registry, driver, MAC-address, and environment checks. When an analysis environment is detected, it triggers a cleanup routine that deletes its executable, configuration, and temporary files. The campaign infrastructure additionally includes multiple authenticated web-based management panels. Based on the targeting, infection chain, Google Sheets C2, persistence mechanisms, and similarities to previously documented activity, the campaign is assessed with moderate confidence as associated with APT36.
This campaign presents a relevant risk even though the observed activity primarily targets government job seekers. The same recruitment-themed social-engineering approach could be adapted to target banking and financial-services employees, applicants, contractors and third-party personnel, particularly through fake recruitment, employment-verification or regulatory documents.
Successful execution could provide attackers with persistent remote access through the abused RMM tool, followed by deployment of the custom RAT for command execution, system monitoring, data collection and access to internal resources. The use of Google Sheets as a C2 channel may also blend malicious communications with legitimate cloud-service traffic, potentially complicating detection.
Within BFSI environments, compromised endpoints could serve as an entry point for credential theft, internal reconnaissance, lateral movement, sensitive financial-data exposure, and further compromise of connected systems or third-party services. The campaign therefore highlights the need for BFSI organizations to monitor unauthorized RMM enrollment, suspicious PowerShell and LNK execution, abnormal use of Google APIs, persistence mechanisms, and recruitment-themed phishing activity.
IOCs: The full indicator set is available in the CYFIRMA platform for deployment across your security controls. (Source: Surface Web)
The Gopher Strike and Sheet Attack campaigns represent a multi-stage intrusion activity targeting Indian government entities, with the threat actor leveraging spearphishing, malicious documents, cloud services, custom backdoors, and post-compromise tooling. The initial infection commonly begins with a PDF lure containing a blurred or redacted government-related document and a fake “Download Document” or software-update prompt. Clicking the lure redirects victims to attacker-controlled infrastructure that selectively delivers malicious ISO or ZIP archives based on geographic and User-Agent filtering, primarily restricting delivery to Windows systems located in India. This targeting mechanism helps limit exposure of the payload to automated analysis environments and unintended users.
In the Gopher Strike campaign, the delivered payload includes GOGITTER, a Golang-based downloader that creates a VBScript and establishes persistence through a dynamically named scheduled task. The script periodically communicates with attacker-controlled infrastructure to retrieve and execute commands. GOGITTER also downloads additional payloads from a private repository using an embedded authentication token. The resulting GITSHELLPAD backdoor uses a private repository as a C2 channel, registering compromised systems and periodically retrieving Base64-encoded commands. It supports directory navigation, command execution, file upload and download, while storing command results in the repository.
Operators subsequently deployed additional post-compromise tools, including GOSHELL, a Golang-based loader that uses hostname-based execution restrictions, multiple decoding stages, and shellcode execution to deploy a Cobalt Strike Beacon. The loader is also artificially inflated with junk data, likely to hinder security scanning.
The Sheet Attack campaign expands this cloud-based C2 approach by abusing legitimate services including Google Sheets, Firebase, and Microsoft Graph API. The SHEETCREEP backdoor uses encrypted configuration data and Google Sheets to register victims, receive commands, and return command output. FIREPOWER, a PowerShell-based backdoor, uses Firebase Realtime Database to maintain victim identifiers, execute commands, download files, and collect directory information.
MAILCREEP uses Microsoft Graph API and email folders for command-and-control, while an additional PowerShell-based stealer searches Desktop, Documents, and OneDrive locations for targeted file types and uploads collected data to attacker-controlled infrastructure.
The campaigns also demonstrate persistence, reconnaissance, execution, collection, defense evasion, and data exfiltration capabilities, alongside server-side filtering designed to restrict payload delivery. Analysis of the malware revealed indicators consistent with generative-AI-assisted development, including verbose comments and unusual coding patterns, although manual development was also evident. Observed operator typos and repeated interactive commands indicate hands-on-keyboard activity. Based on victimology, Pakistan-associated infrastructure indicators, cloud-based C2 techniques, phishing similarities, and partial tooling overlap, the activity is assessed with medium confidence as potentially linked to APT36 or a closely aligned Pakistan-linked subgroup, rather than being conclusively attributed to APT36.
For the Indian BFSI sector, the Gopher Strike and Sheet Attack campaigns demonstrate a significant potential risk because the same phishing, cloud-based C2 and post-compromise techniques could be adapted to target banks, financial institutions, fintech organizations and their employees. Recruitment, regulatory, financial or customer-service themed PDF lures could be used to deliver malicious archives, LNK files, PowerShell payloads or backdoors, while GitHub, Google Sheets, Firebase and Microsoft Graph API could provide covert C2 channels that blend with legitimate business traffic.
Once an endpoint is compromised, attackers could perform system and network reconnaissance, execute commands, download additional tools, collect sensitive documents from local and cloud-synchronized folders and potentially deploy Cobalt Strike for deeper intrusion and lateral movement. In BFSI environments, this could expose customer and financial information, employee credentials, internal documents, cloud resources and connected third-party systems, potentially enabling fraud, account compromise, espionage or further network intrusion.
The use of legitimate cloud services also increases the detection challenge, making monitoring for abnormal PowerShell and LNK execution, unauthorized scheduled tasks, suspicious GitHub/Google/Firebase activity, unusual Microsoft Graph API usage and unexpected outbound cloud communications particularly important.
IOCs: The full indicator set is available in the CYFIRMA platform for deployment across your security controls. (Source: Surface Web)
The Silver Fox campaign represents a multi-stage phishing operation targeting organizations in India, Russia, Indonesia, South Africa, Cambodia and Japan, with India among the most heavily affected regions. The campaign primarily abuses tax-themed lures impersonating government tax authorities, using malicious PDF documents, external download links and compressed archives to persuade users to execute seemingly legitimate tax-related files. The use of links embedded within PDFs can also reduce the likelihood of detection by email security controls because the initial attachment itself does not directly contain executable code.
The initial payload is a customized Rust-based loader, referred to as Silver Fox RustSL, which incorporates payload encryption, encoding, environment checks, country-based geofencing, and anti-analysis capabilities. The loader can extract payloads embedded within the same archive, retrieve them from external infrastructure, or process payloads disguised as benign files such as PNG, HTM, LOG, XLSX, ICO, and XML. The loader uses a custom XOR-based decryption mechanism and can perform multiple decoding and decryption stages before executing the next payload. It also implements geolocation checks against multiple external services and, in certain versions, employs Phantom Persistence to maintain execution across system restarts.
Following execution, the loader deploys ValleyRAT, which provides command-and-control communication, command execution, and additional module loading. ValleyRAT subsequently loads custom modules that download and execute an embedded Python-based backdoor known as ABCDoor. ABCDoor is executed through a bundled pythonw.exe process and establishes persistence through both Registry Run keys and scheduled tasks. This enables the malware to operate with reduced visibility while maintaining access to compromised systems.
ABCDoor provides extensive surveillance and remote-control capabilities, including system information collection, screenshot and multi-monitor screen streaming, keyboard and mouse control, clipboard collection, process management, file upload/download, file operations, and malware update or removal. Its communication with command-and-control infrastructure occurs over HTTPS using Socket.IO, while legitimate utilities such as FFmpeg and Python are abused to support screen capture and execution. The malware also stores operational artifacts in Registry locations and local application directories.
The campaign demonstrates a segmented, modular attack chain combining phishing, obfuscated loaders, geofencing, persistence, legitimate-tool abuse, encrypted payload delivery, and remote surveillance capabilities. For Indian BFSI organizations, the use of tax and regulatory-themed lures is particularly relevant because employees routinely handle tax, compliance, financial and government correspondence, creating opportunities for initial compromise and subsequent access to sensitive financial, customer and corporate information.
The Silver Fox campaign poses a significant risk to the Indian BFSI sector, where tax, GST, regulatory, compliance and financial correspondence are common business processes and can be effectively abused for phishing-based initial access. The campaign’s use of India-specific tax-themed lures, geofencing for Indian systems and multi-stage payload delivery increases the likelihood of successful compromise among employees handling sensitive financial information.
Successful infection could provide attackers with persistent access, screen capture, clipboard collection, file access, process monitoring and remote keyboard/mouse control, potentially exposing customer information, financial records, credentials, internal documents and transaction-related data. The use of legitimate tools such as Python and FFmpeg, encrypted payloads, country-based execution checks and multiple persistence mechanisms can further complicate detection within BFSI environments.
While the observed campaign is not exclusively focused on BFSI organizations, its demonstrated targeting of Indian entities and reliance on tax-related social engineering make banks, insurers, fintech companies, financial-service providers and their employees and third-party service ecosystems relevant potential targets.
IOCs: The full indicator set is available in the CYFIRMA platform for deployment across your security controls. (Source: Surface Web)
Ransomware remained a relevant threat to the Indian BFSI sector during the period from Jan 2025 through August 2026, with multiple ransomware groups identified across the observed finance-sector dataset. The activity indicates that the threat was distributed across several ransomware operations rather than concentrated around a single dominant group. This reflects the continued exposure of financial organizations to ransomware operations that can combine operational disruption with data theft and extortion.

During the Jan 2025 – August 2026 reporting period, KillSec and WorldLeaks recorded the highest observed finance-sector victim counts, with 2 victims each. APT73/Bashe, Babuk2, Qilin, Medusa, Morpheus, Sinobi, Triple X, Warlock and Xploitrs each recorded 1 identified finance-sector victim during the same period. The distribution demonstrates that several ransomware operations affected the Indian financial sector.

Across India between January 2026 and August 2026, ransomware activity extended beyond the BFSI sector, with identified victims distributed across multiple industries. This industry-wide dataset covers a shorter, more recent window than the finance-sector-specific dataset above and should be read as a separate comparison rather than an update to it. Information Technology recorded the highest number of identified victims (30), followed by Manufacturing (24) and Healthcare (17). Finance recorded 6 identified victims in this January–August 2026 dataset, placing it among the affected sectors but below the three most heavily impacted industries. Professional Goods & Services recorded 15 victims; Automotive, 9; Materials, 7; Consumer Goods & Services, 6; and Education, 6.
This broader distribution is relevant to BFSI because financial institutions operate within an interconnected ecosystem of technology providers, manufacturers, professional services firms, healthcare organizations, and other third parties. A ransomware incident affecting a connected service provider can therefore create indirect operational or data-security risks for financial organizations even when the BFSI organization itself is not the direct victim.
The observed data indicates that ransomware continues to pose a multi-actor and multi-sector threat to India’s BFSI ecosystem.
The two datasets referenced in this section cover different periods and should not be read as conflicting.
The finance-sector-specific dataset (Jan 2025 – August 2026) identifies 13 finance-sector victims across 11 ransomware groups, while the shorter, industry-wide dataset (January 2026 –August 2026) records 6 Finance-sector victims within a broader cross-industry comparison.
Both confirm that ransomware activity against Indian financial institutions is distributed across multiple groups rather than concentrated in one. BFSI organizations should therefore monitor both direct ransomware activity against financial entities and ransomware incidents affecting critical third parties and technology providers that support financial operations.

Analysis of validated threat activity data collected for India’s finance sector between March and August 2026 identified 46 data-breach incidents, 37 data-leak incidents and 33 credit-card-related incidents, highlighting data compromise and financial-information exposure as the most prominent observed threat categories during the reporting period.
Hacktivism accounted for 13 incidents, while DDoS activity accounted for 6 incidents, demonstrating that disruption-oriented attacks also affected financial organizations during the period. Web exploitation accounted for 3 incidents, while 1 claimed hack was recorded. Data breaches and data leaks are counted separately because they represent different forms of exposure in the underlying dataset.
The distribution indicates that India’s Finance sector faced a broader threat landscape than ransomware alone, with data compromise, payment-card exposure and information leakage forming the dominant observed categories. These incidents can increase the risk of fraud, identity abuse, account takeover and targeted social engineering, while hacktivism and DDoS activity can additionally affect service availability and customer-facing operations.
On 24 July 2026, a significant volume of data allegedly associated with a major Indian public-sector bank was advertised on a dark-web platform. The dataset was reported to exceed 700 GB, with some reports estimating the total volume at close to 1 TB. The exposed information reportedly included customer-related records, identification documents, loan-related information, internet-banking records, corporate and NRI banking information, internal documents, audit material, and branch- and ATM-related records.
The breach was reportedly linked to the compromise of an employee email account, which provided unauthorized access to sensitive information. The exact initial method used to compromise the employee account and the full extent of the data accessed had not been publicly established at the time of reporting.
For India’s BFSI sector, this type of breach highlights the risk that attackers can gain access to highly sensitive financial and customer information by compromising individual employee accounts, even without directly breaching core banking systems. Such incidents can increase the risk of identity theft, phishing, social engineering, financial fraud, and further unauthorized access. They also underline the importance of strong identity and access management, multi-factor authentication, email security, employee-account monitoring, data-loss prevention, and tighter controls over sensitive financial information.

On 24 August 2026, a threat actor advertised on an underground forum an alleged database breach involving an Indian digital-payments and financial-services company headquartered in Bengaluru. The exposed sample reportedly contained individual names, email addresses, telephone numbers, residential addresses, and banking-related information, indicating exposure of personally identifiable and financial-service-related data. The available evidence confirms the underground disclosure date but does not independently establish when the underlying compromise occurred or confirm the authenticity of the complete dataset.
For the India BFSI sector, such exposure could increase the risk of targeted phishing, customer impersonation, social-engineering attacks and financial fraud, while demonstrating the broader risk posed by data breaches at payment and financial-service providers connected to the BFSI ecosystem.

On 6 August 2026, an underground forum post advertised a list of datasets associated with multiple countries, including India, with the India-specific listing containing an entry referencing a bank. The post did not provide sufficient evidence in the available material to independently verify the authenticity, volume, or exact contents of the advertised dataset; therefore, the specific categories of compromised information cannot be confirmed from the available evidence.
If genuine, exposure of banking-related data could increase the risk of targeted phishing, customer impersonation, social engineering, account-takeover attempts, and financial fraud against Indian BFSI customers. The listing also highlights the continued exposure of Indian financial institutions to underground data trading and alleged third-party or database leaks, warranting monitoring for subsequent publication or validation of the advertised data.

On 24 August 2026, a post shared on the “JundAlNabi Official” Telegram channel appeared to disclose payroll-related banking information associated with employees, including beneficiary names, bank account details, IFSC codes, regional and branch information, and references to updated account/IFSC details. The exposure of such information presents a significant risk to India’s BFSI ecosystem because compromised banking identifiers can be leveraged for targeted phishing, social engineering, account-related fraud, payment redirection, identity impersonation, and employee/customer profiling.
Although the exposed information alone may not provide direct access to bank accounts, its combination with other leaked or publicly available information can materially increase the effectiveness of financial fraud campaigns.
For BFSI organizations, the incident reinforces the need for stronger data-loss prevention, monitoring of sensitive financial information, employee-focused fraud awareness, rapid assessment of exposed credentials and banking identifiers, and coordination between cybersecurity, fraud, and privacy teams.

Note: The authenticity of the breaches, access sales, and hacktivist activity described above remains unverified at the time of reporting, as the claims originate solely from the threat actors.
Beyond APT activity and ransomware, the Indian BFSI sector is exposed to a broad range of financially motivated cyber threats. These include direct banking data breaches, compromise of third-party financial-service providers, payment and card-data theft, UPI-enabled fraud, banking impersonation and underground trading of financial information. These attacks can affect banks directly or exploit customers, payment infrastructure, fintechs and other interconnected entities within the BFSI ecosystem.
Banking data breaches involve unauthorized access to or exposure of information held by banks and financial institutions. Unlike ransomware attacks, the primary objective in these incidents may be the theft or disclosure of sensitive information rather than encryption of banking systems.
Exposed information can include customer PII, KYC documents, account-related information, loan records, employee information, internal documents, and other sensitive banking data. Attackers may obtain such information through compromised employee accounts, stolen credentials, vulnerable applications, exposed databases, or unauthorized access to internal systems.
For the India BFSI landscape, this category is important because leaked banking information can subsequently be used for identity theft, account takeover, targeted phishing, financial fraud, and underground data trading. The impact of a breach should be assessed based on the type of information exposed and whether unauthorized access to banking systems or customer accounts was confirmed.
Payment infrastructure is a critical component of India’s BFSI ecosystem and includes card-processing systems, payment gateways, ATM networks, PoS infrastructure and other services involved in financial transactions.
Threat actors may target these systems to obtain credit- and debit-card information or payment credentials, which can subsequently be used for fraudulent transactions or sold through underground marketplaces. A compromise involving a payment processor or other shared infrastructure can potentially affect customers associated with multiple financial institutions.
This section therefore covers payment infrastructure compromises, card-data theft, ATM and PoS attacks, payment gateway incidents and credible exposure of Indian card information.
Card dumps should be assessed carefully because the appearance of a bank’s cards in an underground dataset does not, by itself, prove that the bank was directly breached. The assessment should establish the source of the data and whether the affected financial institution or payment provider was identified as the source of the compromise.
The widespread adoption of UPI and mobile banking has created a large digital attack surface for financially motivated cybercriminals. Threat actors increasingly target bank customers, mobile devices and authentication mechanisms to conduct unauthorized transactions.
Common attack methods include malicious APKs, fake banking applications, phishing links, credential theft, OTP theft, remote-access applications, social engineering and account takeover. Once attackers obtain access to a victim’s device or banking credentials, they may use legitimate UPI or digital banking functionality to initiate fraudulent transactions.
These incidents are important to the BFSI threat landscape even when the bank’s infrastructure is not compromised. The threat may instead originate at the customer or endpoint level and subsequently result in unauthorized use of legitimate banking services.
Customer account compromise and UPI fraud should therefore be distinguished from confirmed compromise of bank infrastructure when assessing these incidents.
Banking phishing campaigns involve the use of fraudulent websites, applications, messages or communication channels to impersonate legitimate financial institutions.
Threat actors commonly impersonate banks, payment providers or bank employees to convince victims to disclose login credentials, card information, OTPs, KYC information or other sensitive financial data. Campaigns may be distributed through email, SMS, messaging applications, social-media platforms or malicious mobile applications.
Attackers may also use legitimate cloud and hosting services to host phishing pages or distribute malicious applications. The use of such infrastructure does not mean that the underlying cloud provider or the impersonated bank was compromised.
For the India BFSI landscape, this category is relevant because successful banking impersonation can result in credential theft, customer account takeover, unauthorized transactions, and financial losses, even without a direct intrusion into bank infrastructure.
Cybercriminals increasingly monetize stolen financial information through underground forums, marketplaces, and private channels. This section covers the exposure, sale, or advertisement of Indian financial information obtained through previous breaches, credential theft, malware infections, or other criminal operations.
Relevant data may include credit and debit card information, bank account details, banking credentials, UPI-related information, KYC documents, customer PII, and financial records.
Underground exposure is important because stolen information can remain exploitable long after the original compromise. Threat actors may sell the same dataset to multiple buyers, use it for fraud, or combine it with other information to conduct targeted attacks against customers and financial institutions.
However, underground advertisements should be treated according to the available evidence. A threat actor’s claim that a database belongs to an Indian bank should not be treated as a confirmed breach unless the authenticity or origin of the data can be established.
The Indian BFSI sector is entering a threat environment where traditional cyberattacks are increasingly converging with AI-enabled fraud, digital-payment abuse, identity compromise, mobile malware and third-party dependency risks. Threat activity observed during 2026 indicates that attackers are increasingly targeting customers, employees, payment workflows and supporting infrastructure rather than relying solely on direct compromise of bank infrastructure. RBI has identified AI-enabled cyberattacks as a significant near-term threat to financial institutions, while industry assessments indicate that several previously emerging BFSI threats have progressed into operational activity.
The increasing availability of generative AI is expected to enhance financially motivated attacks against Indian BFSI organizations and their customers. Threat actors can use AI to generate convincing phishing messages, impersonate employees or executives, automate social-engineering interactions, and create fraudulent identities or communications. Deepfake audio and video can further increase the credibility of impersonation-based attacks, particularly when targeting high-value transactions or individuals with authority to approve payments.
The primary risk to BFSI organizations is the increased scale and credibility of existing fraud techniques rather than the emergence of an entirely new attack method. AI-enabled impersonation can make it more difficult for employees and customers to distinguish legitimate communications from fraudulent requests, increasing the potential for credential disclosure, unauthorized payments, and account compromise.
Phishing and social-engineering campaigns are expected to become increasingly personalized through the use of AI-generated content. Threat actors can produce convincing messages that imitate the language, branding and communication style of banks, payment providers and financial institutions.
The threat extends across email phishing, SMS-based smishing, voice-based vishing and messaging-platform scams. The use of legitimate banking terminology and personalized victim information can increase the likelihood of successful credential harvesting or financial fraud. The 2026 abuse of cloud infrastructure to host fraudulent banking pages impersonating major Indian banks demonstrates the continued evolution of this attack model.
UPI and mobile banking remain significant attack surfaces because they provide direct access to financial transactions through customer-operated devices. During 2026, Indian cybercrime cases demonstrated the continued use of malicious APKs, fake KYC applications, fraudulent links, and social-engineering techniques to obtain access to banking information and conduct unauthorized transactions.
Threat actors are expected to continue combining mobile malware with credential theft, OTP interception, remote-access techniques, and social engineering. These attacks may compromise the customer’s device or account rather than the bank’s infrastructure but can nevertheless result in direct financial losses and increased fraud-management costs for BFSI organizations.
Threat actors are increasingly abusing legitimate cloud and SaaS platforms to host phishing pages, distribute malicious applications, and collect stolen information. This approach allows attackers to operate from infrastructure belonging to trusted service providers rather than relying exclusively on newly registered malicious domains or dedicated attacker infrastructure.
In August 2026, Indian authorities identified criminal abuse of Google Firebase infrastructure involving fraudulent websites and applications impersonating major Indian banks. The activity demonstrates how legitimate third-party infrastructure can be incorporated into banking fraud campaigns without requiring compromise of the impersonated bank or the cloud provider itself.
This trend may increase the difficulty of detection because blocking entire legitimate cloud platforms could disrupt legitimate business activity.
Indian BFSI organizations increasingly depend on fintech platforms, payment processors, cloud services, KYC providers, software vendors, APIs, and managed-service providers. This interconnected environment creates the possibility that a compromise affecting an external provider could indirectly expose financial data, credentials, or services used by banks and their customers.
The risk is particularly relevant where multiple financial institutions depend on a common technology provider or payment infrastructure. However, a third-party security incident should not automatically be classified as a bank breach. The actual relationship between the affected provider and BFSI organization, as well as the specific data or service affected, must be established before assigning direct impact.
The India BFSI threat landscape is expected to increasingly shift toward identity-centric, payment-centric, and AI-assisted attacks. Rather than relying exclusively on direct infrastructure compromise, financially motivated actors can exploit customers, employees, legitimate cloud infrastructure, payment workflows, and third-party dependencies to reach financial assets. Consequently, AI-enabled fraud, UPI and mobile banking abuse, identity compromise, and third-party dependencies should remain priority areas for BFSI monitoring and defensive planning through 2026 and beyond.
AI-enabled cybercrime is emerging as a significant concern for the Indian BFSI sector. In its June 2026 Financial Stability Report, the RBI identified AI-enabled cyberattacks as the most significant near-term cybersecurity threat perceived by financial institutions.
Evidence from 2026 indicates that deepfake and AI-assisted impersonation are already being incorporated into financial-fraud activity in India. In June 2026, the Indian Cyber Crime Coordination Centre (I4C) warned of rising AI and deepfake fraud targeting banks and fintech users, highlighting the potential for compromised authentication to enable fraudulent KYC completion, digital-wallet activation, opening of financial accounts and unauthorized access to existing banking or digital-service accounts. Indian banks have also issued customer guidance specifically addressing deepfake scams and AI-generated impersonation.
AI is also being used to impersonate trusted entities and individuals in digital-payment fraud. Research on India’s digital-payment environment has documented AI-driven impersonation as an emerging fraud technique, where AI-generated content can be used to make fraudulent communications appear more credible and persuade victims to transfer funds.
CYFIRMA Assessment: Based on the available 2026 evidence, AI should be assessed primarily as an enabler of existing financial-fraud techniques, particularly impersonation, social engineering, and identity fraud. The principal risk to India BFSI is that AI can increase the credibility and scalability of fraudulent interactions, potentially making customer and employee verification more difficult.
Threat actors can use generative AI to produce convincing banking emails, SMS messages, and messaging-platform communications. AI can improve language quality and allow attackers to rapidly generate customized messages for different victims.
AI-generated or cloned voices can be used to impersonate trusted individuals during telephone-based social engineering. The objective may include obtaining sensitive information, persuading victims to perform actions, or supporting fraudulent payment requests.
AI can generate or manipulate video and images to imitate executives, employees, or customers. This can potentially be used against identity-verification processes or high-value financial workflows.
AI can help attackers generate responses dynamically during fraudulent conversations, allowing scams to appear more realistic and reducing the effort required to conduct prolonged interactions with victims.
Indian BFSI organizations should maintain an integrated incident-response framework covering cybersecurity incidents, personal-data breaches and financial fraud. Following detection, organizations should identify affected systems, accounts and data; determine the potential scope and impact; preserve relevant logs and forensic evidence; initiate containment and recovery measures; and assess applicable regulatory reporting and notification obligations.
Under the CERT-In Directions issued under Section 70B of the Information Technology Act, 2000, specified cyber incidents are required to be reported to CERT-In within six hours of noticing such incidents or being brought to notice of such incidents. Organizations should therefore maintain predefined escalation procedures that enable rapid identification of reportable incidents, preservation of relevant information and timely submission of available details. Additional information can be provided as it becomes available.
Where an incident involves personal data, organizations should separately assess applicable obligations under the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, taking into account the applicable enforcement timeline and nature of the incident. The DPDP framework introduces specific requirements relating to personal-data breach response and notification, and organizations should ensure that privacy, cybersecurity and fraud-response teams coordinate their assessments.
Third-party incidents should also be assessed to determine whether they have resulted in exposure of BFSI or customer data, disruption of critical services or other material impact on the organization. Regulatory assessment should operate in parallel with technical containment, evidence preservation, customer protection and business-continuity measures.

Organizations should maintain documented ownership for each stage, predefined escalation thresholds, and tested response procedures to ensure that regulatory obligations do not delay containment or customer-protection actions.
Most Exploited Vulnerabilities in India – Last 90 Days
| Vulnerability | Vendor | Product | CVSS | Possible Threat Actor |
| CVE-2018-10562 | Dasan | Dasan GPON Home Router | 9.8 | Unknown |
| CVE-2014-8361 | Realtek | Realtek SDK | 9.8 | Unknown |
| CVE-2015-2051 | D-Link | D-Link DIR-645, DAP-1522 revB, DAP-1650 revB, DIR-880L, DIR-865L, DIR-860L revA, DIR-860L revB, DIR-815 revB, DIR-300 revB, DIR-600 revB, DIR-645, TEW-751DR, TEW-733GR | 8.8 | Unknown |
| CVE-2016-6277 | Netgear | NETGEAR R/D Series Routers | 8.8 | Unknown |
| CVE-2026-41940 | cPanel | cPanel and WHM | 9.8 | Lazarus Group |
| CVE-2023-35078 | Ivanti | Endpoint Manager Mobile (EPMM), formerly MobileIron Core | 9.8 | Unknown |
| CVE-2023-20198 | Cisco | Cisco IOS XE | 10 | Blacktech, Earth Estries, Fancy Bear, Grayfly, Mission2025 |
| CVE-2026-1603 | Ivanti | Ivanti EPM | 7.5 | Unknown |
| CVE-2025-55182 | Meta | React Server Components | 10 | Unknown |
| CVE-2023-42793 | JetBrains | TeamCity | 9.8 | Unknown |
| CVE-2023-35082 | Ivanti | Endpoint Manager Mobile (EPMM), formerly MobileIron Core | 9.8 | Unknown |
| CVE-2023-41265 | Qlik | Qlik Sense | 9.9 | Unknown |
| CVE-2021-42013 | Apache | Apache HTTP Server | 9.8 | Unknown |
| CVE-2017-9841 | PHPUnit – Sebastian Bergmann | PHPUnit | 9.8 | Unknown |
| CVE-2026-3055 | Citrix | Citrix NetScaler ADC and NetScaler Gateway | 9.3 | Unknown |
| CVE-2023-36845 | Juniper | Junos OS (J-Web) | 9.8 | Unknown |
| CVE-2023-4966 | Citrix | Citrix ADC and Citrix Gateway | 7.5 | Unknown |
| CVE-2019-1653 | Cisco | Cisco RV320/RV325 | 7.5 | Blacktech, Earth Estries, Fancy Bear, Grayfly, Mission2025 |
| CVE-2023-22518 | Atlassian | Confluence | 10 | Ghostsec, Grayfly, Mission2025 |
| CVE-2022-26138 | Atlassian | Confluence | 9.8 | Unknown |
| CVE-2024-27198 | JetBrains | TeamCity | 9.8 | Unknown |
The India BFSI cyber-threat landscape is moving beyond conventional infrastructure attacks toward a broader ecosystem of identity abuse, financial fraud, data exposure, cloud exploitation, ransomware, and third-party compromise. The strongest signal from the observed activity is that attackers can reach financial assets through employees, customers, digital-payment channels, legitimate technology platforms, and connected service providers without necessarily compromising the core banking environment first.
BFSI organizations should therefore focus on resilience across the entire financial ecosystem, combining identity security, behavioral detection, payment protection, cloud monitoring, vulnerability management, third-party assurance, threat intelligence, and rapid regulatory response. The best organizations to manage the next phase of risk will be those that treat cyber defense and fraud prevention as a single business-resilience challenge rather than separate security functions.