A recent survey conducted by Moody's involving 102 insurers and asset managers worldwide revealed a significant increase in cybersecurity spending within the financial sector. The survey found that approximately half of the respondents now allocate between 6% and 10% of their IT budgets specifically to cybersecurity initiatives. This marks a notable rise compared to previous years, with the trend being especially prominent among life and health insurers as well as very large companies. The survey also highlighted that nearly all insurers and asset managers now treat cybersecurity as a distinct line item in their budgetary planning, reflecting the growing recognition of cyber risk as a critical business concern. Despite the increased investment, the sector continues to face challenges, as demonstrated by a series of recent high-profile breaches, including a July 2025 incident at Allianz Life Insurance of North America that resulted in a significant data compromise. The report underscores that higher spending does not automatically translate to improved security outcomes, particularly in the face of persistent threats from third-party breaches. The weekly roundup also referenced other notable incidents, such as a third-party breach affecting Renault in the United Kingdom, a WhatsApp malware campaign in Brazil, and skepticism in Germany regarding the Chat Control initiative. Additionally, two British teenagers were arrested in connection with a ransomware attack on a preschool, and the Qilin ransomware group claimed responsibility for disrupting Asahi beer production. The roundup further mentioned that China-linked hackers have weaponized the Nezha tool, and a breach at Invoicely exposed 180,000 personal records. The Moody's survey findings suggest that while insurers and asset managers are responding to the evolving threat landscape with increased budgets, the complexity and frequency of cyber incidents continue to test the effectiveness of these investments. The sector's focus on cybersecurity is driven by both regulatory pressures and the operational risks posed by cyberattacks. The report also notes that the upward trend in spending is likely to continue as organizations seek to bolster their defenses against increasingly sophisticated adversaries. The inclusion of cybersecurity as a separate budget item indicates a maturing approach to risk management within the industry. However, the ongoing occurrence of breaches, particularly those involving third-party vendors, highlights the need for comprehensive risk assessment and supply chain security measures. The survey's results provide valuable insight into the priorities and challenges facing insurers and asset managers as they navigate the complex cybersecurity landscape. The findings also serve as a reminder that investment in cybersecurity must be accompanied by effective governance, incident response planning, and continuous improvement to address emerging threats. Overall, the financial sector's commitment to cybersecurity spending reflects a broader recognition of the importance of protecting sensitive data and maintaining trust in an increasingly digital environment.

See the actors and campaigns active against you right now.
8 events from the most recent confirmed update back to the earliest known activity.
A Moody's survey found that insurers and asset managers were allocating more budget to cybersecurity. The finding was presented alongside the late-September and early-October 2025 cyber incidents summarized in the roundup.
The roundup notes Germany's apparent opposition to the EU proposal that would require platforms to scan private messages for abuse material. End-to-end encrypted services such as Signal and WhatsApp have also opposed the measure.
Researcher Jeremiah Fowler discovered an unencrypted database tied to Invoicely containing about 180,000 sensitive financial and personal records. The database was secured after notification.
Huntress reported that suspected China-linked actors weaponized the open-source Nezha tool and used phpMyAdmin log poisoning and web shells to deploy Gh0st RAT. The activity reportedly affected more than 100 systems, mainly in East Asia.
Police in the UK arrested two teenagers in connection with the ransomware and extortion attack on the Kido preschool chain. The case involved theft of children's data through the Famly childcare management app.
Trend Micro reported on a Windows malware campaign dubbed 'Sorvepotel' that spread via WhatsApp and heavily affected Brazilian government and public-sector entities. The campaign delivered banking-stealing payloads to victims.
Renault informed UK customers that a third-party incident exposed personal data, including customer and vehicle-related information. The roundup describes the breach as part of broader third-party compromise risks affecting organizations.
The Qilin ransomware group claimed a late-September 2025 attack on Asahi Group Holdings in Japan. The incident reportedly disrupted beer production and other operations, and the group alleged it stole data.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.