Black Kite found that 76 of the 140 vendors most concentrated in financial services carry at least one vulnerability CISA has confirmed is being exploited. Ransomware against the sector rose 76% in the first quarter, and a growing share of it arrives through a supplier rather than the front door.
Key Takeaways
Financial institutions spend more on security than almost any other sector, and regulators hold them to the tightest standards for how they manage it. The weak point in that arrangement has always been that an institution can only fully control its own estate. New research from Black Kite puts a number on everything else, and the number is not reassuring: more than half of the vendors that finance depends on most are running software that attackers are already known to be exploiting.
Black Kite's 2026 Financial Services Report examined a pool of 140 vendors, defined as any supplier whose client base is at least 10% financial sector, alongside a broader sample of roughly 17,000 vendors monitored by its financial sector customers. Of the 140, 76 carry at least one vulnerability on CISA's Known Exploited Vulnerabilities catalogue, which lists flaws with confirmed attacks in the wild rather than theoretical risk. 109 of the 140, or 78%, show at least one critical-level patch management failure.
The direction of travel is worse than the snapshot. In one year the number of those vendors carrying critical CVEs rose from 15 to 73. Among the 20 vendors financial institutions rely on most, 12 now carry critical CVEs, up from 9. Confirmed breaches among the 140 climbed from 6 to 39 in twelve months, and among the top 20 from 1 to 7. Black Kite also found 42.1% of the concentrated pool had employee credentials in stealer logs and 57.9% had active phishing infrastructure associated with them.
The counterintuitive finding is that concentration makes things worse, not better. Across the broad 17,000-vendor sample, 60% earned A-band cyber ratings. Among the 140 concentrated vendors that fell to 36%, and among the top 20 it was 32%, with 11% in the C-band. The vendors with the most financial sector customers are, on this evidence, the ones in the weakest shape. Announcing the findings, Ferhat Dikbiyik, Black Kite's Chief Research and Intelligence Officer, summarised it as direct attacks climbing again while the vendor ecosystem becomes measurably more vulnerable.
The vendor numbers matter because of how the attacks now arrive. Black Kite recorded 202 finance ransomware incidents in 2025, up 30% from 156 in 2024, and 65 in the first quarter of 2026 alone, a 76% increase on the same quarter a year earlier. Its dataset counts only confirmed victims where both encryption and exfiltration were verified, so it describes a conservative lower bound rather than a ceiling.
The clearest illustration is the Qilin campaign Black Kite calls the Korean Leaks. A single managed service provider compromise cascaded into 32 South Korean financial institutions and more than 2 terabytes of stolen data. South Korea recorded 32 finance ransomware incidents in 2025 after zero in both 2023 and 2024. None of those institutions had to be individually breached; they shared a supplier. The report also cites the Marquis Software Solutions breach, which exposed up to 1.35 million customers across 74 or more U.S. financial institutions.
CrowdStrike's 2026 Financial Services Threat Landscape Report, covering April 2025 to March 2026, shows the same pattern from the attacker side. It counted 423 financial services entities named on dedicated leak sites, a 27% rise, and found the sector accounts for 12% of all the threat activity it observed. The biggest single figure is from nation-state actors: DPRK-nexus groups stole $2.02 billion in digital assets in 2025, and one of them, PRESSURE CHOLLIMA, took $1.46 billion through supply chain compromise.
The wider breach data explains why supplier software is such an effective route. Verizon's 2026 Data Breach Investigations Report found 31% of breaches now start with a software vulnerability, overtaking stolen passwords as the most common way in, and 48% of breaches involve ransomware. A vendor carrying a known exploited flaw is exactly the entry point those numbers describe.
The supervisory side is shifting too. As Ncontracts' September vendor management roundup notes, the Federal Reserve, FDIC, OCC and NCUA have proposed replacing their 2023 interagency third-party risk guidance, and Financial Stability Board chair Andrew Bailey has warned G20 finance ministers about the sector's reliance on a small number of concentrated technology providers. The same roundup records CISA adding ConnectWise ScreenConnect, GitLab and JFrog Artifactory to the KEV catalogue on September 11.
It also records the kind of case that makes any framework hard to operate. Paylogix, a third-party administrator, discovered a breach in November 2025 and did not notify its insurance-carrier clients until July 2026. An institution can only act on vendor risk it knows about, and an eight-month gap means the client's own incident clock never started. Contract terms that require prompt notification are only as good as the vendor's willingness and ability to detect and report.
The practical conclusion is that annual questionnaires cannot keep pace with the data. A vendor that passed review last year may be one of the 73 now carrying critical CVEs, and a KEV addition like the September 11 batch can turn a routine tool into an active exposure overnight.
Financial institutions have spent a decade hardening their own estates, and the attackers have responded by going around them. The next improvement in the sector's security will be measured less by what banks do inside their walls than by what they know about the suppliers who hold the keys.
Report
The full adversary picture behind the 423 leak-site victims and the $1.46 billion supply chain theft cited here, group by group.
Download
Guide
A structured approach to cyber risk for banks, asset managers and insurers, for teams whose most exposed systems now sit with a supplier.
Download
Guide
When a shared provider is hit, as 32 Korean institutions learned at once, the first hour of isolation and notification decides how far it spreads.
Download
High-risk AI obligations for hiring and workforce management moved to December 2027, and the classification problem did not move.
NIST expects quantum-vulnerable algorithms gone by 2035, and the obstacle is producing an inventory of the old ones.
The NIS2 Directive requirements are now in force, and a frank assessment of where most organisations stand.