Bank Vendors Are Now Finance’s Biggest Cyber Risk, New Data Shows

Ransomware attacks on financial institutions rose 30% in 2025, climbing from 156 incidents to 202, and early 2026 numbers are already worse, according to new research from cyber risk firm Black Kite. But the more striking figure sits one layer removed from the banks themselves: among the vendors that power core financial services, the number carrying critical, actively dangerous software flaws nearly quintupled in a single year. The data points to a structural shift in how attackers are getting in. They are no longer just knocking on the bank’s front door; increasingly, they are walking in through a supplier the bank trusted.

Why This Is Trending Now

Two incidents this past year turned an abstract risk into a concrete one. A ransomware group called Qilin compromised a single managed service provider in South Korea and used that one foothold to move laterally into 32 financial institutions, stealing more than two terabytes of data without needing to breach any of them directly. Separately, a vulnerability at Texas-based fintech data vendor Marquis Software Solutions exposed up to 1.35 million customers across more than 74 U.S. financial institutions. Both cases share the same root cause: the bank’s own defenses held, but the vendor’s did not, and the bank paid the price anyway.

What Happened?

Black Kite’s 2026 Financial Services Cybersecurity Report tracked 140 vendors with significant exposure to the financial sector and found that those carrying critical-severity vulnerabilities (rated CVSS 9 or higher) grew from 15 to 73 in just twelve months, a 4.9x increase. Vendors with high-severity flaws nearly tripled. More than half of the 140 vendors, 76 of them, carry at least one vulnerability already confirmed as actively exploited in real-world attacks, according to the U.S. Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog. Confirmed breaches across that same vendor pool climbed from six to 39 in a year. Meanwhile, direct ransomware attacks on financial institutions kept climbing too, with the report noting that Q1 2026 alone saw 65 incidents, a 76% jump over the same period in 2025.

What It Means for the Industry

The report describes finance as facing a two-front attack: ransomware groups hitting institutions directly, and a vendor ecosystem growing measurably more dangerous at the same time. Notably, the targets are shifting. Banks were the most-attacked subsector in 2023 with 71 incidents, but that number fell to 36 by 2025, while investment firms nearly doubled from 44 to 84 incidents over the same period. Patch management is a particular weak spot: 109 of the 140 core vendors studied, 78%, showed at least one critical-level patch management failure. This pattern connects to a theme we covered in how fintech companies are fighting AI-powered fraud, where identity and access weaknesses, not just outright system failures, are increasingly the entry point attackers rely on.

How It Could Affect Businesses and Consumers

For financial institutions, the practical implication is that an annual vendor security review is no longer enough. Black Kite’s data shows a vendor’s risk profile can shift dramatically within months, and the Marquis Software breach illustrates the cost of missing that window: monitoring tools had flagged Marquis at elevated risk about a month before the attack, but the breach was not publicly disclosed until more than ten weeks after the initial intrusion. For consumers, a data breach originating at a vendor rarely announces itself clearly. Bank customers whose data was exposed through a third party often only learn about it through a notification letter, sometimes months later, which is why security researchers increasingly recommend the same monitoring habits described in our earlier guide on protecting your finances from AI-powered scams.

Key Benefits and Opportunities

The silver lining in the data is that risk is measurable before it turns into a breach. Continuous, automated vendor monitoring, as opposed to point-in-time annual questionnaires, can surface a weakening security posture in near real time rather than at the next scheduled review. That shift also opens an opportunity for a growing category of vendor risk management and cyber risk quantification tools that translate technical vulnerability data into financial exposure figures boards can act on. For financial institutions, treating vendor risk as an ongoing, quantifiable line item rather than a compliance checkbox is emerging as a competitive differentiator, not just a defensive one.

Risks and Challenges

The core challenge is structural: banks operate under heavy regulatory scrutiny, but many of the vendors they depend on for data analytics, cloud infrastructure, and payment processing do not face comparable oversight. Over 48,000 new software vulnerabilities were disclosed globally in 2025 alone, and AI-assisted vulnerability discovery tools are expected to push that number higher in 2026, widening the gap between how fast new risks appear and how fast vendors patch them. Ransomware groups have also proven resilient to enforcement. LockBit and ALPHV/BlackCat were dismantled by law enforcement in late 2023 and early 2024, cutting their combined finance-sector attacks from 61 to 16, but newer groups such as Qilin rebuilt that capacity within a year, and the total number of distinct groups targeting finance grew from 37 to 48.

What Experts, Companies, or Regulators Are Saying

Regulators have moved to close the oversight gap. In the European Union, the Digital Operational Resilience Act has been in force since January 2025 and shifted into active enforcement in 2026, requiring banks, insurers, and payment institutions to maintain a formal register of every ICT vendor relationship and report major incidents within tight deadlines. National authorities are now conducting live supervisory reviews rather than simply checking that policies exist on paper. In the United States, frameworks such as GLBA, FFIEC guidance, and NYDFS cybersecurity rules similarly push financial institutions to extend due diligence to their vendors, though enforcement approaches vary by regulator and state. Black Kite’s researchers frame the underlying problem as one of visibility: institutions cannot manage risk in vendors, or in the vendors those vendors depend on, that they have not mapped in the first place.

What Happens Next?

Expect financial regulators on both sides of the Atlantic to keep tightening third-party oversight requirements through 2026, and expect more institutions to shift from annual vendor questionnaires toward continuous, automated monitoring of supplier security postures. Ransomware activity is unlikely to slow on its own, given how quickly new groups have replaced dismantled ones, which means the vendors serving banks, payment processors, and investment firms will likely remain a preferred entry point for attackers looking for one weak link that opens the door to many institutions at once.

Conclusion

The 2026 data makes a simple point hard to ignore: a financial institution’s cybersecurity is only as strong as the weakest vendor it depends on. As ransomware activity climbs and critical vulnerabilities pile up across the supplier ecosystem, banks that treat vendor risk as a one-time compliance exercise are increasingly exposed to breaches they cannot see coming from inside their own walls. The institutions that fare best from here will likely be the ones that start watching their vendors as closely as they watch themselves.

Trending Stories

FindTechHome is an independent platform delivering the latest fintech news, market insights, and updates on digital finance, AI, blockchain, and emerging financial technologies.

findtechome @2026. All Rights Reserved.