Dikla Sheffer, the firm's Vice President of Business Development, told Finance Magnates on Wednesday that the company identified the virus a few weeks ago.
"This is an organized attack on brokerages, affiliate networks, PSPs, VOIPs, and other companies operating within the retail trading industry,” said Sheffer. “Once we identified the virus, we saw fit to publish a warning and share our findings, in the hope that industry colleagues will become more aware of cybersecurity dangers and take the necessary steps to protect themselves.”
Regular test, irregular virus
PandaTS spotted the piece of malware during a routine check up on computers at several of its clients’ call centers. After a thorough investigation, the company's cybersecurity division identified the malware, the hackers behind it and the infected networks.
Due to an ongoing investigation and the involvement of legal authorities, the trading systems provider said that it could not publicize the identity of the hackers at this time.
Finance Magnates reached out to a number of retail brokers to see how widely the malware has spread. Though some were unaffected, several brokers did confirm that hackers had attempted, with varying degrees of success, to steal data from them.
Diagram illustrating how the Emotet virus works (source: US Department of Homeland Security)
“I can confirm that our systems were affected by a virus,” said the CEO of one FCA-regulated broker. “But we don’t believe that the hackers were able to steal any data from us.”
After downloading one of those files, which were usually spreadsheets or Word documents, users were then told they had to ‘decrypt’ information or ‘enable content.’ Clicking on those buttons downloaded a PowerShell to users’ computers which, in turn, downloaded pieces of malware from a remote server.
Silent but deadly
Thus far, the PandaTS cybersecurity team has found a number of different kinds of malware. Most notable amongst them was
Dikla Sheffer, Vice President of Business Development at Panda Trading Systems
the Emotet virus, which allows hackers to steal passwords, emails, and bank details.
More damaging is a piece of malware that allows the hackers to remotely access a user’s computer and then operate it in ‘silent mode.’ That means a user, looking at their screen, would have no idea that someone else was accessing it.
“This looks a lot like the virus that was used to attack Ukraine in 2017,” a cybersecurity expert at a consultancy firm told Finance Magnates. “Similar malware has been used to attack banks in the past couple of years. If I was a broker, I would be taking particular care to ensure it can’t spread between computers within my network.”
Client data for sale
PandaTS told Finance Magnates that the hackers have managed to infect hundreds of computers belonging to brokers and affiliate marketers.
The technology provider said that, though the hackers appear to be targeting companies operating in the retail trading industry, several major firms, in a number of different fields of business, have also been affected by the attack.
Further research by the firm's cybersecurity team indicates that the hackers are selling client information on the dark web.
“Data theft is not an incident, it’s an industry,” Boaz Gam, the CEO of data protection solution provider LPS told Finance Magnates. “Companies must take steps to protect their leads or they are sure to be hit. That means losing business, damage to reputation and the potential for regulatory fines.”
Malware: the computer's common cold
Stopping the malware is difficult as it doesn’t make any noticeable changes to one’s computer and cannot be identified by common anti-virus applications.
Boaz Gam, CEO of LPS
As noted, hackers can gain remote access to a user’s PC, but they do so in ‘silent mode,’ meaning the user cannot see what they are doing.
Moreover, the malware is akin to the common cold. The means by which it infects you are the same, as are the symptoms, but the actual components of the virus are constantly changing.
Having worked on a solution for its clients’, PandaTS has now developed technology that can identify whether or not a computer is infected by the malware.
Nonetheless, the best means of defense is not to get infected by the virus in the first place. And unlike the common cold, which is spread by the often unavoidable, artillery-like sneezing of other people on the bus in the morning, all you have to do to ensure you don’t get infected by malware is not download random files from people you don’t know.
Dikla Sheffer, the firm's Vice President of Business Development, told Finance Magnates on Wednesday that the company identified the virus a few weeks ago.
"This is an organized attack on brokerages, affiliate networks, PSPs, VOIPs, and other companies operating within the retail trading industry,” said Sheffer. “Once we identified the virus, we saw fit to publish a warning and share our findings, in the hope that industry colleagues will become more aware of cybersecurity dangers and take the necessary steps to protect themselves.”
Regular test, irregular virus
PandaTS spotted the piece of malware during a routine check up on computers at several of its clients’ call centers. After a thorough investigation, the company's cybersecurity division identified the malware, the hackers behind it and the infected networks.
Due to an ongoing investigation and the involvement of legal authorities, the trading systems provider said that it could not publicize the identity of the hackers at this time.
Finance Magnates reached out to a number of retail brokers to see how widely the malware has spread. Though some were unaffected, several brokers did confirm that hackers had attempted, with varying degrees of success, to steal data from them.
Diagram illustrating how the Emotet virus works (source: US Department of Homeland Security)
“I can confirm that our systems were affected by a virus,” said the CEO of one FCA-regulated broker. “But we don’t believe that the hackers were able to steal any data from us.”
After downloading one of those files, which were usually spreadsheets or Word documents, users were then told they had to ‘decrypt’ information or ‘enable content.’ Clicking on those buttons downloaded a PowerShell to users’ computers which, in turn, downloaded pieces of malware from a remote server.
Silent but deadly
Thus far, the PandaTS cybersecurity team has found a number of different kinds of malware. Most notable amongst them was
Dikla Sheffer, Vice President of Business Development at Panda Trading Systems
the Emotet virus, which allows hackers to steal passwords, emails, and bank details.
More damaging is a piece of malware that allows the hackers to remotely access a user’s computer and then operate it in ‘silent mode.’ That means a user, looking at their screen, would have no idea that someone else was accessing it.
“This looks a lot like the virus that was used to attack Ukraine in 2017,” a cybersecurity expert at a consultancy firm told Finance Magnates. “Similar malware has been used to attack banks in the past couple of years. If I was a broker, I would be taking particular care to ensure it can’t spread between computers within my network.”
Client data for sale
PandaTS told Finance Magnates that the hackers have managed to infect hundreds of computers belonging to brokers and affiliate marketers.
The technology provider said that, though the hackers appear to be targeting companies operating in the retail trading industry, several major firms, in a number of different fields of business, have also been affected by the attack.
Further research by the firm's cybersecurity team indicates that the hackers are selling client information on the dark web.
“Data theft is not an incident, it’s an industry,” Boaz Gam, the CEO of data protection solution provider LPS told Finance Magnates. “Companies must take steps to protect their leads or they are sure to be hit. That means losing business, damage to reputation and the potential for regulatory fines.”
Malware: the computer's common cold
Stopping the malware is difficult as it doesn’t make any noticeable changes to one’s computer and cannot be identified by common anti-virus applications.
Boaz Gam, CEO of LPS
As noted, hackers can gain remote access to a user’s PC, but they do so in ‘silent mode,’ meaning the user cannot see what they are doing.
Moreover, the malware is akin to the common cold. The means by which it infects you are the same, as are the symptoms, but the actual components of the virus are constantly changing.
Having worked on a solution for its clients’, PandaTS has now developed technology that can identify whether or not a computer is infected by the malware.
Nonetheless, the best means of defense is not to get infected by the virus in the first place. And unlike the common cold, which is spread by the often unavoidable, artillery-like sneezing of other people on the bus in the morning, all you have to do to ensure you don’t get infected by malware is not download random files from people you don’t know.
Dukascopy Operating Income Jumps 12% as FX Trading Gains Offset Commission Drop
Featured Videos
FM Daily Brief - 1 May 2026
FM Daily Brief - 1 May 2026
FM Daily Brief - 1 May 2026
FM Daily Brief - 1 May 2026
iForex's CEO tells Finance Magnates the cost of their IPO delay. Also ahead: the US prediction markets legal battle splits in two, and the FCA greenlights onchain funds. It's Friday, the first of May 2026. You're listening to the Finance Magnates Daily Brief.
iForex's CEO tells Finance Magnates the cost of their IPO delay. Also ahead: the US prediction markets legal battle splits in two, and the FCA greenlights onchain funds. It's Friday, the first of May 2026. You're listening to the Finance Magnates Daily Brief.
iForex's CEO tells Finance Magnates the cost of their IPO delay. Also ahead: the US prediction markets legal battle splits in two, and the FCA greenlights onchain funds. It's Friday, the first of May 2026. You're listening to the Finance Magnates Daily Brief.
iForex's CEO tells Finance Magnates the cost of their IPO delay. Also ahead: the US prediction markets legal battle splits in two, and the FCA greenlights onchain funds. It's Friday, the first of May 2026. You're listening to the Finance Magnates Daily Brief.
Not All Video Reviews Are Created Equal | Finance Magnates
Not All Video Reviews Are Created Equal | Finance Magnates
Not All Video Reviews Are Created Equal | Finance Magnates
Not All Video Reviews Are Created Equal | Finance Magnates
Not All Video Reviews Are Created Equal | Finance Magnates
Not All Video Reviews Are Created Equal | Finance Magnates
We deliver fast, structured, neutral reviews covering regulation, platforms, leverage, payouts, and risk across brokers, prop firms, and fintech platforms.
Book your Finance Magnates video review: https://lnkd.in/dDubZJ2S
#FinanceMagnates #BrokerReview #PropTrading #Fintech #Forex #Crypto #CFD #TradingPlatforms #DigitalAssets
We deliver fast, structured, neutral reviews covering regulation, platforms, leverage, payouts, and risk across brokers, prop firms, and fintech platforms.
Book your Finance Magnates video review: https://lnkd.in/dDubZJ2S
#FinanceMagnates #BrokerReview #PropTrading #Fintech #Forex #Crypto #CFD #TradingPlatforms #DigitalAssets
We deliver fast, structured, neutral reviews covering regulation, platforms, leverage, payouts, and risk across brokers, prop firms, and fintech platforms.
Book your Finance Magnates video review: https://lnkd.in/dDubZJ2S
#FinanceMagnates #BrokerReview #PropTrading #Fintech #Forex #Crypto #CFD #TradingPlatforms #DigitalAssets
We deliver fast, structured, neutral reviews covering regulation, platforms, leverage, payouts, and risk across brokers, prop firms, and fintech platforms.
Book your Finance Magnates video review: https://lnkd.in/dDubZJ2S
#FinanceMagnates #BrokerReview #PropTrading #Fintech #Forex #Crypto #CFD #TradingPlatforms #DigitalAssets
We deliver fast, structured, neutral reviews covering regulation, platforms, leverage, payouts, and risk across brokers, prop firms, and fintech platforms.
Book your Finance Magnates video review: https://lnkd.in/dDubZJ2S
#FinanceMagnates #BrokerReview #PropTrading #Fintech #Forex #Crypto #CFD #TradingPlatforms #DigitalAssets
We deliver fast, structured, neutral reviews covering regulation, platforms, leverage, payouts, and risk across brokers, prop firms, and fintech platforms.
Book your Finance Magnates video review: https://lnkd.in/dDubZJ2S
#FinanceMagnates #BrokerReview #PropTrading #Fintech #Forex #Crypto #CFD #TradingPlatforms #DigitalAssets
FM Daily Brief - 30 April 2026
FM Daily Brief - 30 April 2026
FM Daily Brief - 30 April 2026
FM Daily Brief - 30 April 2026
FM Daily Brief - 30 April 2026
FM Daily Brief - 30 April 2026
iForex posts its first annual results as a listed broker. Also ahead: CFI Financial secures a Brazil license, and prediction markets have a big week, with new ETF launches and fresh Polymarket loss data. It's Thursday, the thirtieth of April 2026. You're listening to the Finance Magnates Daily Brief.
iForex posts its first annual results as a listed broker. Also ahead: CFI Financial secures a Brazil license, and prediction markets have a big week, with new ETF launches and fresh Polymarket loss data. It's Thursday, the thirtieth of April 2026. You're listening to the Finance Magnates Daily Brief.
iForex posts its first annual results as a listed broker. Also ahead: CFI Financial secures a Brazil license, and prediction markets have a big week, with new ETF launches and fresh Polymarket loss data. It's Thursday, the thirtieth of April 2026. You're listening to the Finance Magnates Daily Brief.
iForex posts its first annual results as a listed broker. Also ahead: CFI Financial secures a Brazil license, and prediction markets have a big week, with new ETF launches and fresh Polymarket loss data. It's Thursday, the thirtieth of April 2026. You're listening to the Finance Magnates Daily Brief.
iForex posts its first annual results as a listed broker. Also ahead: CFI Financial secures a Brazil license, and prediction markets have a big week, with new ETF launches and fresh Polymarket loss data. It's Thursday, the thirtieth of April 2026. You're listening to the Finance Magnates Daily Brief.
iForex posts its first annual results as a listed broker. Also ahead: CFI Financial secures a Brazil license, and prediction markets have a big week, with new ETF launches and fresh Polymarket loss data. It's Thursday, the thirtieth of April 2026. You're listening to the Finance Magnates Daily Brief.
FM Daily Brief - 29 April 2026
FM Daily Brief - 29 April 2026
FM Daily Brief - 29 April 2026
FM Daily Brief - 29 April 2026
FM Daily Brief - 29 April 2026
FM Daily Brief - 29 April 2026
XTB and Robinhood both post first-quarter earnings. But the numbers point in very different directions. Also ahead: Capital.com pushes into three new markets and signals a move into payments.
It's Wednesday, the 29th of April 2026. You're listening to the Finance Magnates Daily Brief.
XTB and Robinhood both post first-quarter earnings. But the numbers point in very different directions. Also ahead: Capital.com pushes into three new markets and signals a move into payments.
It's Wednesday, the 29th of April 2026. You're listening to the Finance Magnates Daily Brief.
XTB and Robinhood both post first-quarter earnings. But the numbers point in very different directions. Also ahead: Capital.com pushes into three new markets and signals a move into payments.
It's Wednesday, the 29th of April 2026. You're listening to the Finance Magnates Daily Brief.
XTB and Robinhood both post first-quarter earnings. But the numbers point in very different directions. Also ahead: Capital.com pushes into three new markets and signals a move into payments.
It's Wednesday, the 29th of April 2026. You're listening to the Finance Magnates Daily Brief.
XTB and Robinhood both post first-quarter earnings. But the numbers point in very different directions. Also ahead: Capital.com pushes into three new markets and signals a move into payments.
It's Wednesday, the 29th of April 2026. You're listening to the Finance Magnates Daily Brief.
XTB and Robinhood both post first-quarter earnings. But the numbers point in very different directions. Also ahead: Capital.com pushes into three new markets and signals a move into payments.
It's Wednesday, the 29th of April 2026. You're listening to the Finance Magnates Daily Brief.
FM Daily Brief - 28 April 2026
FM Daily Brief - 28 April 2026
FM Daily Brief - 28 April 2026
FM Daily Brief - 28 April 2026
FM Daily Brief - 28 April 2026
FM Daily Brief - 28 April 2026
Startrader posts three-point-one trillion dollars in first-quarter volume — up three hundred and forty percent from a year ago. Also ahead: Fintokei claims sub-second trader payouts, and eToro opens its premium subscription tier to all investors.
Startrader posts three-point-one trillion dollars in first-quarter volume — up three hundred and forty percent from a year ago. Also ahead: Fintokei claims sub-second trader payouts, and eToro opens its premium subscription tier to all investors.
Startrader posts three-point-one trillion dollars in first-quarter volume — up three hundred and forty percent from a year ago. Also ahead: Fintokei claims sub-second trader payouts, and eToro opens its premium subscription tier to all investors.
Startrader posts three-point-one trillion dollars in first-quarter volume — up three hundred and forty percent from a year ago. Also ahead: Fintokei claims sub-second trader payouts, and eToro opens its premium subscription tier to all investors.
Startrader posts three-point-one trillion dollars in first-quarter volume — up three hundred and forty percent from a year ago. Also ahead: Fintokei claims sub-second trader payouts, and eToro opens its premium subscription tier to all investors.
Startrader posts three-point-one trillion dollars in first-quarter volume — up three hundred and forty percent from a year ago. Also ahead: Fintokei claims sub-second trader payouts, and eToro opens its premium subscription tier to all investors.