The modern bank heist is already under way


The image of the bank robber is hopelessly outdated. Today’s heist does not begin with a getaway car outside a branch. It begins quietly, with an adversary establishing persistence inside a financial institution’s network and studying how the organisation responds, says Tom Kellermann, VP of AI Security and Threat Research at Trend AI.

The objective is no longer simply to steal money. Attackers want access to the financial system itself: payment infrastructure, confidential market intelligence, investment strategies, customer identities and the mechanisms used to defend them. TrendAI’s Modern Bank Heists in 2026 research, based on a survey of 48 financial-sector CISOs, reveals the scale of this shift. Eighty-nine per cent reported an increase in AI-enabled attacks, while 55 per cent had experienced a rise in attacks against APIs. Almost half, 46pc, had encountered attempts to steal non-public market information or investment strategies.

Read more…
Source:  Trend Micro News


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Georgia: Columbus hit by data breach, officials say not considered ransomware incident

    July 29, 2024

    Columbus experienced a data breach last Wednesday, the same day as an internet outage, city officials say. The only information believed to have been accessed are employees’ names, work emails and passwords, according to Mike Richardson, the city’s director of security and risk. He said no employee’s personal financial information was compromised. All employee passwords were ...

  • Northern Ireland: Man arrested in connection with PSNI data breach

    July 29, 2024

    Detectives investigating criminality linked to the PSNI data breach have arrested a 54-year-old man. Data relating to all 9,483 PSNI officers and staff was mistakenly included in a spreadsheet published online last August in response to a freedom of information request. The list included the surname and first initial of every employee, their rank or grade, ...

  • Investigators probe suspected sabotage of French fiber optic network

    July 28, 2024

    The disruptions occurred early Wednesday, hitting several — but not all — internet operators. Authorities suggested the damage to the cables was intentional. The prosecutor’s office opened a preliminary investigation on charges of “damaging goods of a nature of harming the fundamental interests of the nation,” as well as “obstruction of an automatic data processing system” ...

  • CVE-2024-6922: Automation Anywhere Automation 360 Server-Side Request Forgery

    July 26, 2024

    Automation 360 Robotic Process Automation suite v21-v32 is vulnerable to unauthenticated Server-Side Request Forgery (SSRF). SSRF occurs when the server can be induced to perform arbitrary requests on behalf of an attacker. An attacker with unauthenticated access to the Automation 360 Control Room HTTPS service (port 443) or HTTP service (port 80) can trigger arbitrary web ...

  • Guernsey: Warning after spike in cyber-attacks

    July 25, 2024

    Authorities have warned organisations to take extra measures to protect their IT systems after a spike in cyber-attacks in Guernsey. The Office of the Data Protection Authority (ODPA) said some Microsoft 365 systems had been compromised by phishing attacks, where someone is tricked into giving out information over email. It warned criminals were becoming increasingly adept ...

  • Onyx Sleet uses array of malware to gather intelligence for North Korea

    July 25, 2024

    On July 25, 2024, the United States Department of Justice (DOJ) indicted an individual linked to the North Korean threat actor that Microsoft tracks as Onyx Sleet. Microsoft Threat Intelligence collaborated with the Federal Bureau of Investigation (FBI) in tracking activity associated with Onyx Sleet. Microsoft will continue to closely monitor Onyx Sleet’s activity to assess ...