Verizon recorded 1,300 breaches across finance and insurance in its 2026 Data Breach Investigations Report.
Every case involved confirmed data disclosure.
Internal data appeared in 53% of the breaches. Personal data appeared in 43%. Credentials appeared in 26%. Financial gain motivated 98%.
Those four figures describe an industry losing the material required to attack it again. Internal records explain how the institution works. Personal records identify the people inside the relationship. Credentials allow someone else to enter under a name the institution already trusts.
The common routes required no breakthrough in criminal science. Attackers exploited vulnerabilities, sent phishing messages and used compromised credentials. Familiar methods continued to work against organisations that spend heavily to make them fail.
Finance did not lack security. It still lost the data.
Successful Attacks Against Swiss Finance Increased
FINMA's record deserves attention because it measures attacks of substantial importance against supervised institutions. It does not count the daily noise that banks and financial firms block as a matter of routine.
It counts attacks that succeeded or partly succeeded.
Reports increased by 30% in 2024. FINMA said they rose significantly again during the following reporting period. Unauthorised access accounted for 37% of reported attacks. Identity fraud accounted for 14%. Third parties were involved in 47%.
The institutions operated inside one of the world's most mature financial markets. They worked under regulatory supervision, audit, reporting obligations, security programmes and years of explicit warning.
Attackers still reached them through identities, suppliers and access the institution had reason to trust.
Third-party involvement changes the boundary. A financial institution can strengthen its own network while client information, administration and critical services continue through software vendors, cloud platforms, processors and outsourced providers.
FINMA found institutions that had not completely identified, documented or monitored every outsourced function. The providers sat outside the institution. Their access and consequence did not.
The Best Result in Ransomware Was 49%
Financial services produced the strongest result in Sophos's ransomware study. No other industry was better at stopping attackers from encrypting data.
Attackers still encrypted data in 49% of financial-services attacks.
They attempted to compromise backups in 90% of cases and succeeded in 48% of those attempts. Among financial firms whose data had been encrypted, 51% paid a ransom. Recovery cost an average of $2.58 million before the ransom itself.
These numbers deserve to sit together. The best-performing industry stopped encryption slightly more often than it failed to stop it. Attackers reached the recovery systems designed for the day the primary systems could no longer be trusted. Half of the firms with encrypted data paid the people who had attacked them.
Security investment changed the odds. It did not produce immunity.
Family Offices Had the Controls
Deloitte's 2024 family-office research found strong passwords or multifactor authentication in 85% of offices. Seventy-two per cent maintained backups. Fifty-eight per cent trained their staff.
Forty-three per cent had suffered an attack during the previous 12 to 24 months. One in four had been attacked at least three times. Among offices managing more than $1 billion, 62% reported an attack.
One-third of the attacked family offices suffered damage or loss.
A second Deloitte study, published in 2026, surveyed 1,587 family-owned businesses across 35 countries. Seventy-four per cent had experienced a cyberattack during the previous two years. One-third had experienced more than one.
Among the businesses attacked, 54% reported financial damage. Fifty-one per cent reported operational damage. Fifty-one per cent reported reputational damage.
Only 4% reported no damage.
The record does not describe organisations that forgot every password, backup and policy. It describes attacks continuing through environments where those measures already existed.
Security Was the Reason Customers Chose the Bank
The American Bankers Association's *Banking Journal* reported a 2026 survey of US bank customers and executives.
Fifty-one per cent of customers said security was the primary reason they chose their bank.
Sixty-seven per cent said they would consider switching after a serious breach.
The two answers expose the same decision from opposite sides. Security helps win the relationship. A breach gives the customer a reason to reopen it.
The survey measured stated intention. Two studies of bank deposits measured behaviour.
The Money Moved
The International Monetary Fund examined malicious cyber incidents at US banks between 2014 and 2022.
Deposits at smaller banks declined after an attack. The decline did not end with the investigation, the recovery or the reporting cycle. Retail and wholesale deposits continued to fall until the cumulative reduction reached approximately 5% after six quarters.
The movement was quiet enough to avoid the language of a bank run and persistent enough to survive every immediate response to the incident.
Another study followed those deposits through local banking markets. Published in the *Journal of Money, Credit and Banking*, the research found that cyberattacks against smaller banks did not reduce the total amount held across the local market.
The deposits changed institutions.
Larger banks gained market share after a smaller bank was attacked. The gains concentrated among larger banks with high customer-reputation scores.
The researchers called it a flight to reputation.
The affected bank retained its licence, reopened its systems and continued operating.
Its competitors held the money.
