🧔♂️ A friendly human may check it before it goes live. More news here
US financial sector on alert over potential cyberattacks
US financial services firms are on heightened cyber alert after Reuters reported that Iran’s Supreme Leader Ali Khamenei was killed in an air strike; the report remains unconfirmed.
The US financial sector operates critical infrastructure such as payments, clearing, trading platforms, and Treasury markets, making it a top target for hostile cyber activity, industry groups say.
A US intelligence assessment, Reuters reported, said Iran-aligned hacktivists could conduct low-level attacks, like distributed denial-of-service (DDoS) strikes.
Todd Klessman, SIFMA’s managing director for financial services cyber and technology, said the industry was monitoring the situation and noted SIFMA ran annual exercises to test operational resilience.
Credit rating agency Morningstar DBRS warned cyber risks could rise, but said the biggest threats to global banks and asset managers may be indirect, including sustained higher oil prices and borrower shocks.
A 2025 FS-ISAC report found the financial sector was the top target of DDoS attacks in 2024, with hacktivism surging amid the Hamas-Israel and Russia-Ukraine wars.
Smaller-scale DDoS and ransomware incidents have disrupted parts of the market, including a 2023 ransomware attack that disrupted settlement of some US Treasury trades at a US broker-dealer unit of Industrial and Commercial Bank of China.
🔗 Source: Reuters
🧠 Food for thought
Implications, context, and why it matters.
Iran’s playbook and the financial sector’s organized defense
- The alert covers generic “hacktivists” plus Iran-aligned groups that a U.S. intelligence assessment says could carry out low-level cyberattacks, including distributed denial-of-service (DDoS) strikes 1.
- DDoS pressure has a track record. A 2025 FS-ISAC report says the financial sector took the most DDoS hits in 2024, with hacktivism rising during the Hamas-Israel and Russia-Ukraine wars 2.
- Coordination runs through FS-ISAC, a member-driven, not-for-profit organization that shares threat intelligence across the financial sector. It also runs through annual SIFMA (the Securities Industry and Financial Markets Association) exercises that test operational resilience 3.
Denial-of-service is only part of the worry
- DDoS attacks can knock services offline, yet banks, broker-dealers, and asset managers worry more about market disruption. That includes settlement interruptions like a 2023 ransomware attack that disrupted settlement of some U.S. Treasury trades at a U.S. broker-dealer unit of Industrial and Commercial Bank of China 2.
- Industry groups keep pushing “operational resilience.” The term means firms work to keep payments, clearing, and trading running during an attack, since the sector is treated as critical infrastructure 4.
- Morningstar DBRS said cyber risks could rise. It also said bigger risks to global banks and asset managers may arrive indirectly, including sustained higher oil prices and borrower shocks 5.
- Smaller DDoS and ransomware cases have already disrupted parts of the market. Firms remain on heightened alert amid an unconfirmed report that Iran’s Supreme Leader Ali Khamenei was killed in an air strike 4.
Stay updated on the go with our mobile app.
Get latest insights with smoother, more personalized experience through TIA mobile app.




