FBI: Malware-enabled ATM jackpotting crimes on the rise

• More than 700 ATM jackpotting incidents occurred in the last year alone, accounting for over $20 million in losses. • The FBI issued a new alert regarding malware-enabled ATM jackpotting crimes on the rise.
Source

Press Release: FDIC-Insured Institutions Reported Return on Assets of 1.24 Percent and Net Income of $77.7 Billion in Fourth Quarter 2025

FDIC-insured institutions reported a return on assets of 1.24 percent and aggregate net income of $77.7 billion in the fourth quarter of 2025, with loan growth accelerating to 2.0 percent from the previous quarter. The Deposit Insurance Fund Reserve Ratio increased by 2 basis points to 1.42 percent.
Source

‘Starkiller’ Phishing Service Proxies Real Login Pages, MFA

• Starkiller is a new phishing-as-a-service offering that dynamically loads real login pages and relays user inputs and MFA credentials. • The service allows for real-time session monitoring, keylogging, and automated alerts, effectively bypassing traditional security measures.
Source

FinCEN launches online portal for whistleblower tips

- FinCEN has launched a new webpage for confidentially accepting whistleblower tips on fraud, money laundering, and sanctions violations. - This portal aims to enhance reporting of financial crimes.
Source

Report: Deepfake detection efforts foiling fraudsters

Fraudsters are becoming increasingly frustrated with deepfake detection systems; these systems are effectively preventing fraudulent activities. The article discusses the growing use of AI in fraud and scams, highlighting that despite advancements, fraudsters are finding it harder to bypass detection mechanisms.
Source

FDIC, OCC release stress test scenarios

The FDIC and OCC released stress test scenarios for financial institutions in coordination with the Federal Reserve. These scenarios will be used in upcoming stress tests.
Source

Kimwolf Botnet Swamps Anonymity Network I2P

- Kimwolf botnet disrupted the I2P network by overwhelming it with infected routers. - The disruption was caused by a Sybil attack, where the botnet tried to join 700,000 nodes on I2P. - I2P is a decentralized, privacy-focused communications network.
Source

Patch Tuesday, February 2026 Edition

Microsoft released critical updates for Windows operating systems and other software, addressing six zero-day vulnerabilities. These include security feature bypasses in various components like Windows Shell, MSHTML, Microsoft Word, Remote Desktop Services, DWM, and a denial-of-service vulnerability in the Windows Remote Access Connection Manager.
Source

Congress reauthorizes private-public cybersecurity framework

• Congress reauthorized a voluntary framework for private sector and government agencies to share cyberthreat information. • The reauthorization was part of a larger budget deal.
Source

Update to Notice of Financial Institutions for Which the Federal Deposit Insurance Corporation Has Been Appointed Either Receiver, Liquidator, or Manager

The Federal Deposit Insurance Corporation has appointed itself as the sole receiver for a financial institution; no specific actions required for Texas CUs at this time.
Source

Huntington hires BNY alum as next risk chief

Senthil Kumar will become Huntington’s Chief Risk Officer as it transitions to a Category III bank; involves higher liquidity requirements, capital buffers, and more frequent stress tests.
Source

Please Don’t Feed the Scattered Lapsus ShinyHunters

- Scattered Lapsus ShinyHunters (SLSH) uses a unique playbook involving harassment and threats beyond typical ransom demands. - Engaging with SLSH is discouraged as it may escalate the situation further.
Source

Florida credit union sues Fiserv, alleging lax cybersecurity

FiCare Federal Credit Union alleges Fiserv's lax cybersecurity led to a breach and unauthorized charges. The credit union claims Fiserv informed customers they would be charged for security upgrades.
Source

Press Release: First Independence Bank, Detroit, Michigan, Assumes All Deposits of Metropolitan Capital Bank & Trust, Chicago, Illinois

First Independence Bank assumes deposits of Metropolitan Capital Bank & Trust; FDIC serves as receiver. Deposits remain insured and accessible.
Source

Report: Data breaches becoming more focused

Financial services were the top target for data breaches in 2025; attackers have become more selective. The report by the Identity Theft Resource Center highlights an increasing trend of focused attacks.
Source

ABA Fraudcast: Who is calling me?

The article discusses the challenge of spoofed calls from criminals and the need to protect lawful bank communications. It highlights the importance of identifying legitimate calls amidst fraudulent ones.
Source

Survey: AI, cybersecurity top priorities to community banks in 2026

Artificial intelligence remains a top priority for community financial institutions in 2026; cybersecurity and digital assets also areas of focus. The survey was conducted by software solutions provider CSI.
Source

Who Operates the Badbox 2.0 Botnet?

- Kimwolf botmasters compromised the control panel for Badbox 2.0. - The screenshot shows seven authorized users, including one named 'ABCD' who may be Dort. - Badbox 2.0 has a history of infecting Android TV streaming boxes and engaging in advertising fraud.
Source

FDIC approves deposit insurance applications for Ford, GM industrial banks

The FDIC has approved deposit insurance applications for Ford and GM to establish industrial banks. This move could potentially impact the competitive landscape in the banking industry, particularly for auto manufacturers.
Source

Survey: AI, fraud among top cybersecurity trends for 2026

Artificial intelligence is enhancing cybersecurity efforts but also enabling fraud. Cyber-enabled fraud will affect people of various backgrounds in 2026.
Source

Payments fraud risks burgeon with AI

Artificial intelligence threats in payments are increasing; new industry trends such as agentic commerce and passkey adoption are being implemented for defense.
Source

Kimwolf Botnet Lurking in Corporate, Govt. Networks

The Kimwolf botnet has infected over 2 million devices and can scan local networks for additional targets. It primarily affects residential proxies, especially Android TV streaming boxes, but also compromises corporate and government networks. Infoblox found that nearly 25% of its customers made queries to Kimwolf-related domains.
Source