3 Sources
[1]
TrendAI Report Warns of Rising AI-Driven Cyber Threats to Financial Sector
Instead, they are actively disrupting defenders during live incidents, using artificial intelligence to increase the speed, scale and sophistication of attacks. Financial institutions are facing an unprecedented wave of AI-powered cyberattacks as cybercrime groups increasingly automate fraud, ransomware and intrusion campaigns, according to new research from TrendAI. The Modern Bank Heists in 2026 report, based on a survey of 46 Chief Information Security Officers (CISOs) from financial institutions worldwide, reveals that attackers are no longer simply stealing data. Instead, they are actively disrupting defenders during live incidents, using artificial intelligence to increase the speed, scale and sophistication of attacks. Among the report's key findings: The report also highlights how cybercrime groups are rapidly adopting agentic AI to automate phishing, fraud and exploitation at machine speed. Rather than relying on individual operators, attackers are increasingly orchestrating specialised AI agents capable of running multiple stages of an attack simultaneously. Sharda Tickoo, Country Manager, India & SAARC, TrendAI: "The most concerning finding isn't simply the rise in AI-enabled attacks. It's that attackers are actively disrupting defenders while incidents are unfolding. When adversaries can interfere with your response as well as execute the attack itself, the traditional rules of cyber defence no longer apply. Organisations need autonomous security capabilities that can fight back just as quickly." TrendAI researchers also identified growing use of advanced techniques including steganography, where malicious commands are hidden inside seemingly harmless images, allowing malware to evade traditional security controls. At the same time, commercially available Remote Access Trojans (RATs) continue to evolve, offering cybercriminals sophisticated capabilities once reserved for nation-state actors. The report concludes that financial institutions must shift from reactive cybersecurity to proactive intrusion suppression by combining AI-powered detection, threat intelligence, virtual patching, managed detection and response, and executive-level security leadership. Sharda added, "Trust has always been the foundation of banking. Today that trust is under sustained attack from cybercrime cartels using AI to scale operations faster than many organisations can defend themselves. Security leaders must be empowered to act independently, because defending financial institutions now requires continuous, intelligence-led operations rather than periodic response." Additional recommendations from TrendAI To counter increasingly autonomous attacks, TrendAI recommends financial institutions:
[2]
Cybercriminals Are Using AI to Outrun Financial Institutions, TrendAI Finds
Nearly nine in ten organisations report a surge in AI-enabled attacks as cybercrime cartels industrialise operations Financial institutions are facing an unprecedented wave of AI-powered cyberattacks as cybercrime groups increasingly automate fraud, ransomware and intrusion campaigns, according to new research from TrendAI. The Modern Bank Heists in 2026 report, based on a survey of 46 Chief Information Security Officers (CISOs) from financial institutions worldwide, reveals that attackers are no longer simply stealing data. Instead, they are actively disrupting defenders during live incidents, using artificial intelligence to increase the speed, scale and sophistication of attacks. Among the report's key findings: * 89%of organisations reported a year-on-year increase in AI-enabled attacks. * 67%experienced "counter incident response", where attackers actively interfered with security teams during live investigations. * 41%suffered destructive cyberattacks over the past year. * 55%reported an increase in API-based attacks. * 46%experienced attempts to steal non-public market intelligence or investment strategies. * More than half(54%)saw no increase in cybersecurity budgets despite the worsening threat landscape. The report also highlights how cybercrime groups are rapidly adopting agentic AI to automate phishing, fraud and exploitation at machine speed. Rather than relying on individual operators, attackers are increasingly orchestrating specialised AI agents capable of running multiple stages of an attack simultaneously. Sharda Tickoo, Country Manager, India & SAARC, TrendAI: "The most concerning finding isn't simply the rise in AI-enabled attacks. It's that attackers are actively disrupting defenders while incidents are unfolding. When adversaries can interfere with your response as well as execute the attack itself, the traditional rules of cyber defence no longer apply. Organisations need autonomous security capabilities that can fight back just as quickly." TrendAI researchers also identified growing use of advanced techniques including steganography, where malicious commands are hidden inside seemingly harmless images, allowing malware to evade traditional security controls. At the same time, commercially available Remote Access Trojans (RATs) continue to evolve, offering cybercriminals sophisticated capabilities once reserved for nation-state actors. The report concludes that financial institutions must shift from reactive cybersecurity to proactive intrusion suppression by combining AI-powered detection, threat intelligence, virtual patching, managed detection and response, and executive-level security leadership. Sharda added, "Trust has always been the foundation of banking. Today that trust is under sustained attack from cybercrime cartels using AI to scale operations faster than many organisations can defend themselves. Security leaders must be empowered to act independently, because defending financial institutions now requires continuous, intelligence-led operations rather than periodic response." Additional recommendations from TrendAI To counter increasingly autonomous attacks, TrendAI recommends financial institutions: * Adopt an intrusion suppression strategy that combines virtual patching, proactive threat hunting and managed detection and response. * Build AI-enabled security operations capable of responding at machine speed. * Strengthen protection against prompt injection, deepfake-enabled fraud and business email compromise.
[3]
TrendAI Report: Nation-State Actors Embed AI Across H1 2026 Attack Chains
Generative AI is now sharpening nation-state exploits and powering autonomous reconnaissance, mid-year findings show TrendAI today released its H1 2026 APT Activity Roundup. The mid-year findings on the H1 2026 threat landscape showed that AI has moved beyond isolated experiments. Nation states used AI in more stages of the intrusion lifecycle than any other prior half TrendAI has tracked. Between January and June 2026, TrendAI detected the following APT (advanced persistent threat) nation-state activity: * China-aligned threat actors used generative AI to sharpen exploits and iteratively build malware through vibe coding. One AI agent independently ran its own reconnaissance and lateral movement inside a target network. * Russia-aligned Pawn Storm opened the year with an Office zero-day vulnerability and kept pressing Ukraine and its partners across government, defense, and wartime-aid organizations. * DPRK-aligned actors folded commercial AI into their operations and poisoned a widely used software package to reach downstream developers. * Iran-aligned Earth Vetala scanned for a newly disclosed Ivanti vulnerability within days of its release, and other Iran-aligned actors carried out hands-on attacks against internet-exposed operational technology, tampering with fuel-tank gauges at sites in the United States. Sharda Tickoo, Country Manager for India and SAARC at TrendAI: "Artificial intelligence has stopped being a side tool for attackers and has become a teammate embedded in the operation itself. We are watching nation-state actors hand reconnaissance and lateral movement to an AI agent, and use generative models to iterate on malware the way a developer ships code. Defenders now have to assume the adversary on the other end of an intrusion may not be a person typing commands, but a system executing a plan." Key findings include: * AI now touches more stages of the intrusion lifecycle, from exploit development to autonomous reconnaissance and lateral movement * Known and zero-day vulnerabilities are weaponized within days of disclosure, and the software supply chain remains a favored entry point * Operational technology and physical-world targets -- including fuel-tank monitoring systems -- are back in attackers' crosshairs * A newer tracking method, ADINT, harvests location and device data from online ad auctions without deploying any malware * Threat actors increasingly hide command-and-control on trusted cloud platforms, developer tunnels, blockchains, and paste sites
Share
Copy Link
TrendAI's Modern Bank Heists in 2026 report surveyed 46 CISOs from financial institutions worldwide and found 89% experienced a rise in AI-enabled cyberattacks. Cybercriminals now use agentic AI to automate fraud and ransomware while actively disrupting defenders during live incidents. 67% of organizations faced counter incident response tactics.
Financial institutions are under siege from AI-powered cyberattacks as cybercriminals industrialize their operations using artificial intelligence to execute fraud, ransomware, and intrusion campaigns at unprecedented speed and scale. TrendAI's Modern Bank Heists in 2026 report, based on a survey of 46 CISOs from financial institutions worldwide, reveals a disturbing shift in attacker behavior: adversaries are no longer content with simply stealing data
1
2
. They now actively disrupt security teams during live investigations, fundamentally changing the rules of cyber defense.
Source: CXOToday
The findings paint a stark picture: 89% of organizations reported a year-on-year increase in AI-enabled cyberattacks, while 67% experienced counter incident response where attackers interfered with security teams during active investigations
2
. This means adversaries can both execute attacks and sabotage the defense response simultaneously, creating a dual threat that traditional security measures struggle to counter.Cybercrime groups are rapidly adopting agentic AI to orchestrate sophisticated attacks at machine speed. Rather than relying on individual operators typing commands, attackers now deploy specialized AI agents capable of running multiple stages of an attack simultaneously
1
. These autonomous systems can execute phishing campaigns, fraud schemes, and exploitation techniques without human intervention, dramatically increasing both the velocity and volume of threats.Sharda Tickoo, Country Manager for India and SAARC at TrendAI, emphasized the gravity of the situation: "The most concerning finding isn't simply the rise in AI-enabled attacks. It's that attackers are actively disrupting defenders while incidents are unfolding. When adversaries can interfere with your response as well as execute the attack itself, the traditional rules of cyber defence no longer apply"
1
.The TrendAI report documents widespread destructive attacks and targeted theft campaigns. 41% of financial institutions suffered destructive cyberattacks over the past year, while 55% reported an increase in API-based attacks
2
. Perhaps most concerning, 46% experienced attempts to steal non-public market intelligence or investment strategies, indicating that attackers are targeting the intellectual property that gives institutions their competitive edge.TrendAI researchers identified growing use of advanced techniques including steganography, where malicious commands are hidden inside seemingly harmless images, allowing malware to evade traditional security controls
1
. Commercially available Remote Access Trojans continue to evolve, offering cybercriminals sophisticated capabilities once reserved for nation-state actors.TrendAI's H1 2026 APT Activity Roundup reveals that nation-state actors have moved AI beyond isolated experiments and now use it across more stages of the intrusion lifecycle than ever before
3
. China-aligned threat actors used generative AI to sharpen exploits and iteratively build malware through vibe coding, with one AI agent independently running its own reconnaissance and lateral movement inside a target network. Russia-aligned Pawn Storm exploited an Office zero-day vulnerability targeting Ukraine and its partners across government and defense organizations.
Source: CXOToday
DPRK-aligned actors folded commercial AI into their operations and poisoned a widely used software package to reach downstream developers in supply chain attacks. Iran-aligned Earth Vetala scanned for a newly disclosed Ivanti vulnerability within days of its release, while other Iran-aligned actors carried out hands-on attacks against operational technology, tampering with fuel-tank gauges at sites in the United States
3
.Related Stories
Despite the escalating threat landscape, more than half of organizations (54%) saw no increase in cybersecurity budgets
2
. This funding gap creates a dangerous asymmetry where attackers leverage AI-driven autonomous reconnaissance and automated attack capabilities while defenders operate with static resources.Tickoo noted that "Trust has always been the foundation of banking. Today that trust is under sustained attack from cybercrime cartels using AI to scale operations faster than many organisations can defend themselves"
1
. She stressed that security leaders must be empowered to act independently, as defending financial institutions now requires continuous, intelligence-led operations rather than periodic response.TrendAI concludes that financial institutions must shift from reactive cybersecurity to proactive intrusion suppression. The report recommends adopting an intrusion suppression strategy that combines virtual patching, proactive threat hunting, and managed detection and response
2
. Organizations need to build AI-enabled security operations capable of responding at machine speed and strengthen protection against prompt injection, deepfake-enabled fraud, and business email compromise.The research also highlights emerging tracking methods like ADINT, which harvests location and device data from online ad auctions without deploying any malware
3
. Threat actors increasingly hide command-and-control infrastructure on trusted cloud platforms, developer tunnels, blockchains, and paste sites, making detection more challenging. Known and zero-day vulnerabilities are weaponized within days of disclosure, compressing the window for defensive action. As AI continues to evolve on both sides of the cybersecurity equation, financial institutions face mounting pressure to deploy autonomous security capabilities that can match the speed and sophistication of AI-powered threats.Summarized by
Navi
03 Jan 2025•Technology

23 Jul 2026•Technology

02 Jan 2026•Technology

1
Technology

2
Technology

3
Technology
