Generative AI has lowered the barrier to entry for cybercriminals, arming even unskilled attackers with tools to launch sophisticated, targeted and highly believable campaigns against banks and financial institutions. As phishing, supply chain breaches, client-side exploits and cloud missteps accelerate, Simon Wijckmans, CEO of c/side discusses how defenders must evolve beyond outdated safeguards or risk being left behind.

Hackers no longer need to be particularly clever, nor patient, to target high-value financial services organisations. They just need access to a few tools (many of which are freely available) that continue to get better everyday thanks to Generative AI.
Banks and financial institutions have, of course, always been magnets for cybercrime. That hasn’t changed, but what has is just how fast attackers can move and how well they can mimic real people. AI makes it cheap and easy to launch attacks that are targeted, believable and costly. Most security teams are still playing catch-up and stuck applying yesterday’s safeguards to today’s attack patterns and hoping for the best. But hope, as we should all know by now, is not a cyberstrategy built to last.
Here’s what to understand about the biggest AI-fuelled cybersecurity challenges for banks and financial services right now.
Phishing is no longer sloppy
Everyone knows what a phishing email looks like. Or at least they used to. Generative AI has completely rewritten that playbook, and attackers can now generate messages that sound like actual colleagues, customers or executives. They can adapt tone, insert references and follow up in ways that feel authentic, even to employees that have undergone training to watch out for them.
In many cases, attackers don’t even need to write the emails themselves. They can feed in a basic prompt and let the language model do the rest. Throw in a deepfake voice on a follow-up call and it gets even harder to spot the trap. That’s how attackers convince bank employees to hand over credentials, authorise payments or expose sensitive data. It’s not with brute force, but with believable stories and timing that feels right (and it works).
Supply chain attacks are easier now too
Why go straight at the bank when you can take a shortcut through a vendor? Attackers are shifting toward third-party software and services that plug into financial systems. These providers often lack strong security controls and serve as a backdoor into otherwise well-defended environments.
The industry response so far has been basic due diligence and long audit checklists. That is not nearly enough. Financial institutions need continuous, real-time visibility into their software supply chain risk. Static questionnaires cannot keep up with adversaries who automate discovery and exploit faster than vendors can respond.
Client-side is the new weak point
Most banks have spent years hardening their backends. They run hardened servers, encrypt everything and segment networks. But the frontend remains relatively wide open.
Client-side attacks target the browser, not the server. Attackers compromise third-party scripts and inject malicious code directly into the web experience. That code never touches the bank’s infrastructure; it runs in the user’s browser and siphons off sensitive data silently. Too many banks ignore this surface entirely by assuming that if their servers are secure, their users are safe. That assumption is now outdated.
Cloud missteps are still biting teams
Cloud adoption has delivered flexibility, but it has also created a minefield. One overlooked setting can expose critical systems, and one unused port can become an entry point. AI tools help attackers scan for misconfigurations across thousands of targets in minutes. They don’t need to be experts, they just need to know where to point the script. Financial services’ cloud security teams cannot afford to rely on manual reviews and reactive audits. They need automation that is at least as fast and scalable as the threats.
Attackers don’t need to build their own tools anymore
Ransomware-as-a-Service is real. A less skilled attacker can now rent everything they need to pull off enterprise-level attacks. Tooling, infrastructure, payment collection and more, all packaged and readily available. Security teams are no longer up against a few highly skilled operators. They are up against an ecosystem that’s growing, fast.
Security teams need to evolve or get left behind
Defenders are not powerless, and AI works both ways. Security teams can use it to detect anomalies faster, isolate threats automatically and reduce time to containment. Client-side monitoring can help flag and block malicious scripts before they run. Zero-trust architecture can eliminate the soft spots that attackers count on. Stronger behavioral monitoring can stop social engineering attempts in real-time.
Basic blocking and tackling still matters, too. Timely patching, live testing of incident response plans and focused employee training go a long way, especially when phishing emails are now indistinguishable from internal memos.
But security teams in the financial sector need to move faster than most are right now. That means deploying tools that reduce complexity instead of adding to it, it means identifying the attack surfaces that have been overlooked, and it means admitting that what worked five years ago no longer applies. Attackers have evolved, and defenders need to do the same.

