Many top financial firms hit by data breaches in the past year

A white padlock on a dark digital background.
(Image credit: Shutterstock.com)

More than three-quarters (78%) of financial institutions in the European Union (EU) suffered a data breach in the last 12 months, a new report from SecurityScorecard has claimed.

The information security company set out to determine the state of cybersecurity among organizations that must comply with the Digital Operational Resilience Act (DORA) by January 2025. 

To do that, it analyzed 240 of the largest financial institutions in the EU, as well as their third- and fourth-party vendor operations in Europe. This amounted to an ecosystem of 26,142 domains. It picked the 240 organizations based on current revenue, assets under management, or gross written premium. 

Fourth-party risk

The firms analyzed include private equity, asset management, retail banks, Insurance, and pension funds.

Besides the vast majority suffering a cyberattack, an even bigger percentage (84%) were exposed to a fourth-party breach. As per the researchers, there is a “vast web of unseen risks” hiding in plain sight, requiring visibility across the entire third- and fourth-party ecosystem. Despite the findings, businesses lack consensus on how to measure and track fourth-party risks, it was said.

Furthermore, just 3% of the third-party vendors that were analyzed for the report suffered a breach. There is a “massive butterfly effect” here that the threat actors are just now starting to leverage, the researchers say, adding that supply chain attacks are growing more popular among hackers.

In conclusion, almost a fifth (18%) had a poor cybersecurity rating (C or lower), which makes them four to seven times more likely to suffer a data breach, compared to those with the highest rating. To predict a data breach, businesses should pay attention to these factors, the researchers concluded: endpoint security; patching cadence; ransomware score; DNS health; IP reputation; cubit score; and network security.

“If nearly 20% of the most well-resourced financial entities in the EU have grades of C or worse, then it’s likely that the overall cyber resilience for other financial entities is actually much lower,” said Matthew McKenna, Chief Sales Officer, SecurityScorecard. 

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A digital themed isometric showing a neon padlock in the foreground, and a technological diagram of a processor logic board in the background.
Third-party data breaches have become a major security concern
Security padlock in circuit board, digital encryption concept
Rising cost of breaches forces organizations to rethink cybersecurity
security
The true cost of a security breach
Someone holding a passport with two boarding passes inside it
Top digital loan firm security slip-up puts data of 36 million users at risk
Security padlock and circuit board to protect data
Trust in digital services around the world sees a massive drop as security worries continue
EU
“Rehearse, rehearse, rehearse” - is your business doing enough on DORA compliance?
Latest in Pro
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
AI quantization
What is AI quantization?
US flags
US government IT contracts set to be centralized in new Trump order
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Google Gemini AI
Gmail is adding a new Gemini AI tool to help smarten up your work emails
Latest in News
Disney Plus logo with popcorn
You can finally tell Disney+ to stop bugging you about that terrible Marvel show you regret starting
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Hatch Restore 3 in Putty
You can finally start your day with The Office theme song, and I couldn't be more excited
Cassian Andor looking nervously over his shoulder in Andor season 2
New Andor season 2 trailer has got Star Wars fans asking the same question – and it includes an ominous call back to Rogue One's official teaser
Ncuti Gatwa as The Fifteenth Doctor in Doctor Who
Disney+ drops new trailer for Doctor Who season 2 that promises an epic adventure across time and space