The Deposits Kept Falling for Six Quarters

Financial institutions are being breached despite mature controls. The market record shows what customers do next.

The answer

Financial institutions continue to lose internal data, personal information and credentials despite regulation, security investment, backups and established controls. Customer research and observed deposit records show the market response: after serious cyber incidents, deposits leave smaller banks and move towards larger institutions with stronger reputations.

Verizon recorded 1,300 breaches across finance and insurance in its 2026 Data Breach Investigations Report.

Every case involved confirmed data disclosure.

Internal data appeared in 53% of the breaches. Personal data appeared in 43%. Credentials appeared in 26%. Financial gain motivated 98%.

Those four figures describe an industry losing the material required to attack it again. Internal records explain how the institution works. Personal records identify the people inside the relationship. Credentials allow someone else to enter under a name the institution already trusts.

The common routes required no breakthrough in criminal science. Attackers exploited vulnerabilities, sent phishing messages and used compromised credentials. Familiar methods continued to work against organisations that spend heavily to make them fail.

Finance did not lack security. It still lost the data.

Successful Attacks Against Swiss Finance Increased

FINMA's record deserves attention because it measures attacks of substantial importance against supervised institutions. It does not count the daily noise that banks and financial firms block as a matter of routine.

It counts attacks that succeeded or partly succeeded.

Reports increased by 30% in 2024. FINMA said they rose significantly again during the following reporting period. Unauthorised access accounted for 37% of reported attacks. Identity fraud accounted for 14%. Third parties were involved in 47%.

The institutions operated inside one of the world's most mature financial markets. They worked under regulatory supervision, audit, reporting obligations, security programmes and years of explicit warning.

Attackers still reached them through identities, suppliers and access the institution had reason to trust.

Third-party involvement changes the boundary. A financial institution can strengthen its own network while client information, administration and critical services continue through software vendors, cloud platforms, processors and outsourced providers.

FINMA found institutions that had not completely identified, documented or monitored every outsourced function. The providers sat outside the institution. Their access and consequence did not.

The Best Result in Ransomware Was 49%

Financial services produced the strongest result in Sophos's ransomware study. No other industry was better at stopping attackers from encrypting data.

Attackers still encrypted data in 49% of financial-services attacks.

They attempted to compromise backups in 90% of cases and succeeded in 48% of those attempts. Among financial firms whose data had been encrypted, 51% paid a ransom. Recovery cost an average of $2.58 million before the ransom itself.

These numbers deserve to sit together. The best-performing industry stopped encryption slightly more often than it failed to stop it. Attackers reached the recovery systems designed for the day the primary systems could no longer be trusted. Half of the firms with encrypted data paid the people who had attacked them.

Security investment changed the odds. It did not produce immunity.

Family Offices Had the Controls

Deloitte's 2024 family-office research found strong passwords or multifactor authentication in 85% of offices. Seventy-two per cent maintained backups. Fifty-eight per cent trained their staff.

Forty-three per cent had suffered an attack during the previous 12 to 24 months. One in four had been attacked at least three times. Among offices managing more than $1 billion, 62% reported an attack.

One-third of the attacked family offices suffered damage or loss.

A second Deloitte study, published in 2026, surveyed 1,587 family-owned businesses across 35 countries. Seventy-four per cent had experienced a cyberattack during the previous two years. One-third had experienced more than one.

Among the businesses attacked, 54% reported financial damage. Fifty-one per cent reported operational damage. Fifty-one per cent reported reputational damage.

Only 4% reported no damage.

The record does not describe organisations that forgot every password, backup and policy. It describes attacks continuing through environments where those measures already existed.

Security Was the Reason Customers Chose the Bank

The American Bankers Association's *Banking Journal* reported a 2026 survey of US bank customers and executives.

Fifty-one per cent of customers said security was the primary reason they chose their bank.

Sixty-seven per cent said they would consider switching after a serious breach.

The two answers expose the same decision from opposite sides. Security helps win the relationship. A breach gives the customer a reason to reopen it.

The survey measured stated intention. Two studies of bank deposits measured behaviour.

The Money Moved

The International Monetary Fund examined malicious cyber incidents at US banks between 2014 and 2022.

Deposits at smaller banks declined after an attack. The decline did not end with the investigation, the recovery or the reporting cycle. Retail and wholesale deposits continued to fall until the cumulative reduction reached approximately 5% after six quarters.

The movement was quiet enough to avoid the language of a bank run and persistent enough to survive every immediate response to the incident.

Another study followed those deposits through local banking markets. Published in the *Journal of Money, Credit and Banking*, the research found that cyberattacks against smaller banks did not reduce the total amount held across the local market.

The deposits changed institutions.

Larger banks gained market share after a smaller bank was attacked. The gains concentrated among larger banks with high customer-reputation scores.

The researchers called it a flight to reputation.

The affected bank retained its licence, reopened its systems and continued operating.

Its competitors held the money.

Sources

  1. Verizon: 2026 Data Breach Investigations ReportVerizon

    Industry guidance

  2. FINMA: Risk Monitor 2025FINMA

    Primary authority

  3. FINMA: How FINMA is getting to the bottom of cyber risks in the financial sector: 24 February 2026FINMA

    Primary authority

  4. Sophos: The State of Ransomware in Financial Services 2024Sophos

    Industry guidance

  5. Deloitte: The Family Office Cybersecurity Report 2024Deloitte

    Industry guidance

  6. Deloitte Private: Family Business Cybersecurity 2026Deloitte Private

    Industry guidance

  7. American Bankers Association: Survey: Most customers would switch banks after major data breach: 2 March 2026American Bankers Association

    Industry guidance

  8. International Monetary Fund: Global Financial Stability Report: Chapter 3, April 2024International Monetary Fund

    Primary authority

  9. Gogolin, Lim and Vallascas, "Cyberattacks on Small Banks and the Impact on Local Banking Markets": Journal of Money, Credit and Banking: 2026Gogolin, Lim and Vallascas, "Cyberattacks on Small Banks and the Impact on Local Banking Markets"

    Academic research

Jonathan P. De Collibus

Jonathan co-founded Svperior in 2014 and leads its cyber practice. His work sits where adversarial pressure, technical architecture, and consequential decisions meet, with experience across clinical, financial, public-sector, and private-client systems where confidentiality, continuity, and technical correctness carry material consequences.

Cyber strategy / Adversarial assessment / Security architecture / Private systemsRead Jonathan's full biography

Need to apply this to a specific situation?

Send us the initial context. If the matter fits, we will respond directly.

Send private inquiry