FinAi News

No products in the cart.

Subscribe
  • News
  • AI News Tool
  • Data
  • Transactions
  • Events
    • FinAi Banking Summit
    • FinAi Lending Summit
  • Podcast
  • WEBINARS
    • Webinar Library
Log In
No Result
View All Result
  • Banking
  • Lending
  • Payments
  • Risk & Security
  • Strategy
FinAi News
  • News
  • AI News Tool
  • Data
  • Transactions
  • Events
    • FinAi Banking Summit
    • FinAi Lending Summit
  • Podcast
  • WEBINARS
    • Webinar Library
BAN PLUS
Log In
No Result
View All Result
FinAi News
No Result
View All Result

Zero-trust framework is mandatory in era of gen AI

57% of CISOs consider phishing attacks the biggest AI threat in 2026

Vaidik TrivedibyVaidik Trivedi
April 21, 2026
in Risk & Security
Reading Time: 9 mins read
0
Share on Facebook

AI is becoming a double-edged sword in the fight against cybercriminals, acting as a threat and a defense. 

AI is anticipated to be the most significant driver of change in cybersecurity in 2026, with 87% of cyber executives and public workers predicting that AI will increase system vulnerability and boost cyberattacks, according to Global Cybersecurity Outlook 2026 report by the World Economic Forum published in March. 

On average, a successful cyberattack costs a business $250,000, the report stated, adding that the energy, financial services, health and telecom sectors are the most targeted.

(AI-generated)

That threat troubles financial institution leaders. 

“Cybersecurity keeps me up at night more than the concern for rising delinquencies,” Linda Armyn, chief executive of $14 billion FourLeaf Credit Union, told FinAi News. “Although difficult, delinquencies can be managed, but the impairment that comes along with a successful cyberattack can be impossible to recover from.” 

Lower barrier to entry 

Fraudsters are using AI to enhance traditional cyberattack methods such as phishing, malware and social engineering because these approaches continue to deliver strong results, a January Moody’s Ratings report stated.  

With gen AI, fraudsters can launch mass attacks on FIs at low cost, Steve Ross, head of business development for the Americas at S-RM, a global corporate intelligence and cybersecurity consultancy, told FinAi News. 

This technology simplifies the job for would-be criminals, opening the door to additional threat actors, Ross added. 

“Rather than inventing entirely new schemes, criminals use AI to automate and personalize attacks at scale, making them more convincing and much harder for organizations and individuals to detect,” Leroy Terrelonge, vice president and senior credit officer in the Moody’s Ratings Cyber Credit Risk Group, told FinAi News. 

Nearly 57% of chief information security officers consider phishing attacks the biggest threat from gen AI in 2026, according to cybersecurity company Splunk‘s January CISO Report. 

It’s not just the quantity and quality of attacks that are growing. New age AI-driven attacks like gen AI-driven deepfake videos are also on the rise, although frequency is low as of now, Terrelonge said.  

Better attacks, zero trust  

Deepfake audio and video, which were considered fringe technologies a few years ago, are being used in real-world scams, prompting warnings from governments and tech companies, Terrelonge said. 

To fight scams, financial institutions have embedded machine learning into cyber frameworks for years, but as cyberattacks evolve, so must defense mechanisms, Terrelonge said, adding that companies now are adopting zero-trust models. 

(AI-generated)

A zero-trust cybersecurity model assumes that no user, device or system should be trusted by default, even if they are inside the network, according to IBM. Every access request must be verified using identity, context and behavior before being granted. 

This allows companies to constantly monitor whether a device has been compromised or if a bad actor has taken it over and is trying to access the mainframe, John Lunn, chief executive of payments provider Gr4vy, told FinAi News. 

With the rise of agents, FIs need to remain vigilant about who is granted access to data, Lunn said, adding that banks and payments rails are built on the theory that bots are bad, and then the theory changes to “some bots are good.” 

Similarly, zero-trust assumes that everyone is a bad actor, he said. 

“With zero-trust, no matter the bot or user, they have to verify at the gate to access the castle. Data and system access should only be given to a device or user once they prove that they are good actors.” — John Lunn, chief executive of payments provider Gr4vy

The agentic AI market is expected to grow from $1.6 billion in 2026 to $5.71 billion in 2034, with a CAGR of 14%, according to data analysis company Fortune Business Insights’ April 6 report.  

Explainability, guardrails 

As AI turbocharges cyberattacks, financial institutions are using the tech to defend against them, FourLeaf’s Armyn said.  

“One of the biggest hurdles of AI deployment within a bank’s walls is the explainability aspect of it, not the accuracy,” she said. “The accuracy of AI can be improved, but if the models can’t explain decisions, we are in deep waters.” 

One solution for the explainability issue is deploying multiple agentic AI models for different functions, Eren Ramdhani, chief product officer at fraud detection and cybersecurity company INETCO, told FinAi News, adding that agents tasked with just one function are more explainable and accountable than an agent that does it all.

“Agentic AI models have less parameters than general LLMs, which can help in training them for specific tasks along with reducing hallucinations and false positives,” he said. 

Better training, vendors 

Deploying better tech is only half the battle, Terrelonge said. 

“While we are seeing adoption of machine learning and AI capabilities in security tooling, humans still tend to be the weakest link in the security chain.” — Eren Ramdhani, chief product officer at fraud detection and cybersecurity company INETCO

Financial institutions account for more than 50% of all phishing attacks globally, making them the most targeted sector, according to an August 2025 report from cybersecurity company Red Shift. 

FIs are educating their employees constantly about password hygiene and spotting phishing attempts, he said. Many FIs are deploying AI agents to flag incoming phishing attempts as the first defense. 

Educating employees is just as essential as picking a good vendor for cybersecurity needs, Daragh Morrissey, global AI lead for financial services at Microsoft, told FinAi News. 

FIs cannot just take AI models out of the box and deploy them internally, Morrissey said, adding that recent events have taught the industry that many of these models can be “jail broken” or manipulated to do tasks that they are not designed to do. 

Adding closed gen AI models can pose a risk to a financial institution’s data, Morrissey said, adding that either FIs need to lean into open-source models for workflows or deploy AI models that have strict guardrails. 

Goliath at risk 

Despite their substantial investments in cybersecurity, large organizations remain attractive targets for cybercriminals, Yoni Katz, lead cyber credit risk associate at Moody’s Ratings, told FinAi News. Some large organizations still rely on legacy stacks, a weakness that cybercriminals can exploit with new age tech like AI. 

“Larger entities are disproportionately affected by cybersecurity incidents and recurrent attacks,” Katz said, adding that cybercriminals focus on high-value targets where the potential payouts are greatest. 

FIs that suffered data breaches this year include: 

  • Lloyds Banking Group suffered a breach in March in which data for nearly 447,000 customers was leaked; 
  • Banner Capital Bank suffered unauthorized access to customer financial data via compromised employee email in March; and 
  • Online lender Figure Lending suffered customer data exposure in January. 

A favorite target for fraudsters would be an FI that is modernizing and its critical systems, like its core, are not securely connected with other modern systems via APIs, Katz explained. Fraudsters will exploit that by deploying repeated Distributed Denial-of-Service attacks to either take down the system or steal information in ransomware. 

Many FIs like JPMorgan are taking a layered cybersecurity approach along with a zero-trust framework to fend off cyberattacks, Greg Hodges, head of trust and safety at J.P. Morgan Payments, told FinAi News. 

“J.P. Morgan Payments has implemented multilayered authentication methods and tools like device fingerprinting,” Hodges said. “These systems are trained to recognize typical customer behavior, so any deviation can trigger immediate scrutiny.” 

Layered approach 

The winner of the between FIs and cyberattackers will be the side that has more compute, Steve Shillingford, CEO at agentic AI service provider DeepSee, told FinAi News. 

“Fraudsters are trying to find the cheapest and quickest way to hurt you,” Shillingford said, adding that FIs are already equipped to deal with such attacks. 

“The story changes when it’s a nation-state actor trying to hurt you, because they can and are willing to spend $100,000 a minute to hurt you,” he said. 

In the coming years, AI’s strength will be measured by “who can acquire more compute,” as that is the benchmark for brute strength, Shillingford said.  

Compute can be gained with individual defense layers, he said.  

“Consider it like a cake where each layer of defense needs to be broken down to get to the next one,” Shillingford said. 

This approach discourages small fraudsters from trying to breach security systems and provides a good cushion for organizations to deal with bigger attackers, he added. 

“Large FIs need to deploy a zero-trust and layered defense system or risk ransomware and security breaches,” he said. 

Register here for the FinAi Lending Summit, set for Oct. 7-8 in Las Vegas. 

Tags: artificial intelligence (AI)cybersecurityFeaturesJPMorgan ChaseMicrosoftMoody'sNewsPremium
Previous Post

Transactions: Credit unions select Upstart for AI-driven personal lending

Next Post

Capital One’s efficiency ratio reflects continued tech, AI transformation

Related Posts

Moonshot’s Kimi K3 on browser
Risk & Security

Kimi AI escapes sandbox in third-party test, researchers say

August 7, 2026
Risk & Security

AI voice authentication ‘a cat-and-mouse game’, experts warn

August 6, 2026
Multiple blue cubes showing the silhouettes of people, with one red cube showing a silhouette wearing a mask and with an alert symbol
Risk & Security

Synthetic identities both friend and foe in anti-fraud processes

August 5, 2026
Next Post
capital one

Capital One’s efficiency ratio reflects continued tech, AI transformation

EMERGING FINTECH DIRECTORY

Emerging Fintech Directory

FinAi Podcast

SPONSORED

Build an Antifragile Strategy to Outperform the Market

July 14, 2026

How AI and Product Experts Turn Fuzzy Requirements Into Focused Dev-ready Roadmaps

April 19, 2026

Is Your Technology Supplier There for You?

April 1, 2026

  • About Us
  • Help Center
  • Contact Us
  • Privacy Terms
  • ADA Compliance
  • Advertise

 [wt_cli_manage_consent]

Connect

twitter linkedin podcast podcast podcast
© 2026 Royal Media
No Result
View All Result
  • NEWS
    • All News
    • Banking
    • Lending
    • Payments
    • Risk & Security
    • Strategy
  • AI News Tool [Beta]
  • DATA
  • TRANSACTIONS
  • EVENTS
    • FinAi Banking Summit
    • FinAi Lending Summit
  • PODCAST
  • WEBINARS
    • Webinar Library
  • SUBSCRIBE
  • Log In / Account

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Unlock This Article

Create your free FinAi News account to access this article and stay informed on how AI is transforming financial services including banking, lending, payments, and risk.

Yes, I'd like to receive FinAi News updates, breaking news, and exclusive AI insights for financial services leaders.

Continue Reading with FinAi News Premium - Less than $2/Day

Upgrade to FinAi News Premium for unlimited access to news, insights, trends, and intelligence on how AI is transforming financial services including banking, lending, payments, and risk.
Upgrade to FinAi News Premium Subscription
No Result
View All Result
  • NEWS
    • All News
    • Banking
    • Lending
    • Payments
    • Risk & Security
    • Strategy
  • AI News Tool [Beta]
  • DATA
  • TRANSACTIONS
  • EVENTS
    • FinAi Banking Summit
    • FinAi Lending Summit
  • PODCAST
  • WEBINARS
    • Webinar Library
  • SUBSCRIBE
  • Log In / Account