Finance
Overview
The economy is currently booming and so is cybercrime against financial institutions. Hackers often have one motive, to steal money; and the finance sector has an abundance of it. It is but natural for this industry to attract the attention of such attackers.
According to a survey, the average number of cyber attacks per banking institution increased to 520 in the first half of 2018, up by 207 attacks the previous year. Recent activity on the dark web indicates an increase in attacks against financial services (and businesses) and their customers. Advanced email attacks via business email compromise (BEC) remain cybercriminals’ most favored method of entry.
The increasing incidence of cyberattacks on financial firms reflects how much this industry relies on technology to solve its business-related challenges. Many financial institutions rely on big data to grow their market share. Moreover, to better understand their consumers and to attract new ones, finance firms tap into social media networks, consumer databases, and news feeds to collect data.
Firms of this industry focus on defending corporate systems while disregarding their Achilles’ heel—their staff and customers. Advanced email attacks targeting finance staff and customers have seen a 150% spike in recent months. According to a recent survey, cyber attacks against financial organizations increased by 238% between February and April 2020.
While these attacks can take a variety of forms, they nearly always begin with a BEC, phishing attack, or other advanced email threats. 80% of financial institutions lack the technologies needed to detect and prevent increasingly sophisticated BEC assaults aimed at their employees. This has had a negative impact on banks’ bottom lines. According to the FBI, BEC assaults caused $12.5 billion in losses worldwide between October 2013 and May 2018. $2.9 billion was believed to have been stolen from US banks alone during that time period.

Finance Data Breaches Stats
- In 2018, Under Armour’s MyFitnessPal app was hacked, exposing personal information of 150 million users.
- According to Verizon’s 2020 DBIR report, internal actors were involved in 30% of data breaches in 2020.
- According to Verizon’s 2020 DBIR report, phishing was involved in 80% of the breaches in the finance industry.
- According to Verizon’s 2020 DBIR report, Email was used as a method of conducting the breach in more than 90% of the attacks.
- Payment-card-related investigations account for 80% of all data breaches. (SecurityMetrics)
- 71% of all data breaches are financially motivated.
- As per Accenture, the banking industry has the largest cost of cyberattacks at $18.3 million per organization each year.
- In 2017, 65% of banks in the US failed the Online Security Test by OTA.
- 67% of financial institutions reported an increase in cyberattacks in 2018 (VMWare).
- According to a recent survey, financial institutions are 300 times more likely to be targeted by cyberattacks than organizations in other industries (Forbes).

Finance Industry DMARC Adoption
Of the top 100 global banks:
- 38% had no DMARC record
- 24% had a DMARC record at a p=none policy
- 2% had a DMARC record with a p=quarantine policy
- 36% had a DMARC record with a p=reject policy
DMARC adoption – Currently, 38% of the top 100 global banks have no DMARC record configured. We may conclude that over 62% of the top 100 global banks are exposed to domain abuse, leaving their customers and email receivers vulnerable to phishing attacks and email fraud.
None Policy – The None (Monitor) policy is used by 24% of the top 100 global banks.This policy detects but does not prevent authentication abuse.
Quarantine Policy – The Quarantine policy, which forwards emails that fail authentication to the defined spam folder, is applied by about 2% of the top 100 global banks.
Reject Policy – Reject policy is the ideal configuration because it prevents attackers from impersonating a brand by rejecting messages that fail authentication. However, this policy has been implemented by only 3% (16 enterprises) of the top global banks.

How can DMARC help?
EmailAuth, through DMARC’s implementation, gives companies and organizations guaranteed security and complete control of their email domains. However, it has other advantages too, and you can read more about them in detail here.
EmailAuth provides a free DMARC Record Checker to display your record, test it, and verify that it is valid. All you need to perform a DMARC check is to provide your domain name. The tool will then analyze and display your DMARC record along with other information on your domain’s activities. Similarly, you can also verify your DKIM and SPF records using EmailAuth’s free and automated tools: DKIM record checker and SPF record checker.
If you do not have a DMARC record published for your domain and wish to publish one, you can use EmailAuth’s DMARC Record Generator to generate a record instantly. It completely automates the setup process for DMARC, making it easier to choose who is allowed to send emails on your domain’s behalf and keep track of your domain’s enforcement policies.
