Russia’s invasion of Ukraine puts U.S. financial institutions at elevated risks of cyberattacks, and experts believe proactive steps should be taken to lessen threats.

Russian cybercriminals have taken aim at U.S. interests before, and the attacks predicted to arrive in the wake of heightened U.S. sanctions are nothing new, Tari Schreider, strategic cybersecurity advisor with Aite-Novarica, told Bank Automation News.
“What’s happening now with Russia’s cybersecurity attacks comes right from their cyberwarfare playbook,” Schreider said. “They perfected it back in August of 2008, when they went after Georgia and started attacking their critical infrastructure.”
Areas of risk
Ransomware remains a chief risk for U.S. banks, with Schreider noting that 60% of ransomware attacks originate from Russia and the overall risk of ransomware attacks will nearly double in the coming months.
Distributed denial of service (DDoS) attacks, which overload and incapacitate digital targets with fraudulent traffic, are also set to arise, Tony Cole, chief technology officer of cybersecurity firm Attivo Networks, told BAN. “It is very likely that Russian cybercriminal groups will pick up the pace of their attacks to inflict damage through ransomware and other means,” Cole said. “DDoS attacks are certainly possible against banks and critical infrastructure providers as well.”
Banks may then see assets and information stolen, chains of communication disrupted, and internal processes infiltrated in what Mick Douglas, principal instructor of cybersecurity research and education firm SANS Institute, called a living-off-the-land (LOtL) attack, where cybercriminals gain access to an internal bank network and create sneak attacks.
“They are using core parts of the OS against you. None of your tools will stop these. You likely already have exclusions for the ports and protocols these tools use,” Douglas said in a Wednesday tweet.
Cybercriminals may also target the pandemic-induced influx of remote employees at financial institutions, Schreider said.
“Something that financial institutions with a large contingent of remote workers must be concerned with, is somebody coming in and compromising one of their remote workers and then backhauling it into their network,” he told BAN.
How smaller banks can mitigate the impact of cyberattacks
Large financial institutions have the technology and financial capabilities to withstand most cyberattacks, Cole told BAN.
“Most large financial institutions have been preparing for nation-state and organized crime-focused cyberattacks for several years,” Cole said. “Russia as a nation has significant sophisticated capabilities though, so if they wish to attack U.S. institutions, and they will, it will have an impact and some organizations will be breached.”
The major concern is for community banks and their service providers, with Schreider cautioning: “Large banks have done a great job of being resilient to these attacks. But you have 5,000 community banks, and the most vulnerable institutions are going to be those service providers that serve multiple banks.”
Banks, according to cybersecurity experts, should take a multipronged approach to mitigate the impact of cyberattacks by:
- Regularly testing offline backups and ensuring backups are precise and available for use;
- Rehearsing incident response plans in case of a breach;
- Meeting with cloud providers to discuss steps in case of a DDoS attack; and
- Engaging with the Financial Services-Information Sharing Analysis Center (FS-ISAC) to share tactics, techniques and procedures, as well as indicators of compromise.
Bank Automation Summit, taking place March 1-2 in Charlotte, N.C., is the first and only event to focus solely on automation in banking. The event will feature the brightest minds from across financial services on intelligent automation strategies and deployment. Learn more and register here for Bank Automation Summit 2022.






