Compliance & Risk

54% of the Vendors Finance Depends On Carry a Known Exploited Flaw, and Sector Ransomware Is Up 76%

Black Kite found that 76 of the 140 vendors most concentrated in financial services carry at least one vulnerability CISA has confirmed is being exploited. Ransomware against the sector rose 76% in the first quarter, and a growing share of it arrives through a supplier rather than the front door.

September 24, 2026 · Compliance & Risk
A trading desk in a bright, empty office with four monitors and a laptop showing market charts and price tables

Key Takeaways

  • Black Kite found 76 of the 140 vendors most concentrated in financial services (54%) carry at least one CISA Known Exploited Vulnerability, and 109 of them (78%) show a critical-level patch management failure.
  • Confirmed breaches among those 140 vendors climbed from 6 to 39 in twelve months, and among the 20 most relied-upon vendors from 1 to 7.
  • Black Kite counted 65 finance ransomware incidents in Q1 2026, up 76% on Q1 2025, after a 30% rise across 2025 to 202 incidents.
  • CrowdStrike counted 423 financial services entities named on leak sites, up 27%, and found the sector accounts for 12% of all threat activity it observed.

Financial institutions spend more on security than almost any other sector, and regulators hold them to the tightest standards for how they manage it. The weak point in that arrangement has always been that an institution can only fully control its own estate. New research from Black Kite puts a number on everything else, and the number is not reassuring: more than half of the vendors that finance depends on most are running software that attackers are already known to be exploiting.

The Vendor Estate Is Measurably Getting Worse

Black Kite's 2026 Financial Services Report examined a pool of 140 vendors, defined as any supplier whose client base is at least 10% financial sector, alongside a broader sample of roughly 17,000 vendors monitored by its financial sector customers. Of the 140, 76 carry at least one vulnerability on CISA's Known Exploited Vulnerabilities catalogue, which lists flaws with confirmed attacks in the wild rather than theoretical risk. 109 of the 140, or 78%, show at least one critical-level patch management failure.

The direction of travel is worse than the snapshot. In one year the number of those vendors carrying critical CVEs rose from 15 to 73. Among the 20 vendors financial institutions rely on most, 12 now carry critical CVEs, up from 9. Confirmed breaches among the 140 climbed from 6 to 39 in twelve months, and among the top 20 from 1 to 7. Black Kite also found 42.1% of the concentrated pool had employee credentials in stealer logs and 57.9% had active phishing infrastructure associated with them.

The counterintuitive finding is that concentration makes things worse, not better. Across the broad 17,000-vendor sample, 60% earned A-band cyber ratings. Among the 140 concentrated vendors that fell to 36%, and among the top 20 it was 32%, with 11% in the C-band. The vendors with the most financial sector customers are, on this evidence, the ones in the weakest shape. Announcing the findings, Ferhat Dikbiyik, Black Kite's Chief Research and Intelligence Officer, summarised it as direct attacks climbing again while the vendor ecosystem becomes measurably more vulnerable.

One Supplier, 32 Institutions

The vendor numbers matter because of how the attacks now arrive. Black Kite recorded 202 finance ransomware incidents in 2025, up 30% from 156 in 2024, and 65 in the first quarter of 2026 alone, a 76% increase on the same quarter a year earlier. Its dataset counts only confirmed victims where both encryption and exfiltration were verified, so it describes a conservative lower bound rather than a ceiling.

The clearest illustration is the Qilin campaign Black Kite calls the Korean Leaks. A single managed service provider compromise cascaded into 32 South Korean financial institutions and more than 2 terabytes of stolen data. South Korea recorded 32 finance ransomware incidents in 2025 after zero in both 2023 and 2024. None of those institutions had to be individually breached; they shared a supplier. The report also cites the Marquis Software Solutions breach, which exposed up to 1.35 million customers across 74 or more U.S. financial institutions.

CrowdStrike's 2026 Financial Services Threat Landscape Report, covering April 2025 to March 2026, shows the same pattern from the attacker side. It counted 423 financial services entities named on dedicated leak sites, a 27% rise, and found the sector accounts for 12% of all the threat activity it observed. The biggest single figure is from nation-state actors: DPRK-nexus groups stole $2.02 billion in digital assets in 2025, and one of them, PRESSURE CHOLLIMA, took $1.46 billion through supply chain compromise.

The wider breach data explains why supplier software is such an effective route. Verizon's 2026 Data Breach Investigations Report found 31% of breaches now start with a software vulnerability, overtaking stolen passwords as the most common way in, and 48% of breaches involve ransomware. A vendor carrying a known exploited flaw is exactly the entry point those numbers describe.

Regulators Are Moving, but Notification Still Lags

The supervisory side is shifting too. As Ncontracts' September vendor management roundup notes, the Federal Reserve, FDIC, OCC and NCUA have proposed replacing their 2023 interagency third-party risk guidance, and Financial Stability Board chair Andrew Bailey has warned G20 finance ministers about the sector's reliance on a small number of concentrated technology providers. The same roundup records CISA adding ConnectWise ScreenConnect, GitLab and JFrog Artifactory to the KEV catalogue on September 11.

It also records the kind of case that makes any framework hard to operate. Paylogix, a third-party administrator, discovered a breach in November 2025 and did not notify its insurance-carrier clients until July 2026. An institution can only act on vendor risk it knows about, and an eight-month gap means the client's own incident clock never started. Contract terms that require prompt notification are only as good as the vendor's willingness and ability to detect and report.

The practical conclusion is that annual questionnaires cannot keep pace with the data. A vendor that passed review last year may be one of the 73 now carrying critical CVEs, and a KEV addition like the September 11 batch can turn a routine tool into an active exposure overnight.

Financial institutions have spent a decade hardening their own estates, and the attackers have responded by going around them. The next improvement in the sector's security will be measured less by what banks do inside their walls than by what they know about the suppliers who hold the keys.

Share

More in Compliance & Risk

All Resources →