CrowdStrike published a detailed threat intelligence report exposing a sophisticated state-sponsored hacking campaign codenamed "PHANTOM LEDGER" that targeted 47 major financial institutions across 18 countries, successfully exfiltrating an estimated $1.7 billion and compromising data belonging to over 23 million individuals.

Attack Methodology

Attackers first compromised a niche financial messaging software vendor used by all 47 targeted banks, inserting malicious code into a routine software update. AI-generated spear-phishing emails achieved a 34% click-through rate — roughly four times the industry average.

Response

Affected banks have been notified and the FBI, Interpol and Europol have launched a coordinated investigation.