The rapid development of digital banking services and financial technologies is resulting in an unprecedented cybersecurity paradigm, which the current security posture is not equipped to handle,” says the report titled ‘Digital Threat Report 2025-26’, complied by the Ministry of Electronics and Information Technology (MeitY), CERT-In, CSIRT-Fin, and cybersecurity firm SISA.
“The cyber security landscape for banking is shifting due to an increasing reliance on connected financial systems, embedded finance, artificial intelligence (AI), real-time payments, APIs, and third-party services,” says the report.
“Unlike isolated legacy banking systems, where the attack surface was limited to the core banking application, contemporary interconnected systems allow attackers to target relationships rather than the bank itself”.
It further says that modern cyber threats are now exploiting the trust surface between systems rather than infiltrating individual institutions and organizations. “Modern cyber threats are targeting the biometric onboarding, partner applications, AI-driven payments, processing and settlement flows, APIs, programmable finance, and connected payment ecosystems.
It further says that modern cyber threats are now exploiting the trust surface between systems rather than infiltrating individual institutions and organizations. “Modern cyber threats are targeting the biometric onboarding, partner applications, AI-driven payments, processing and settlement flows, APIs, programmable finance, and connected payment ecosystems.
The attack surface has broadened with the interconnectedness of finance and the involvement of numerous entities in delivering financial services,” the report says.
According to the report, the cyber security challenges for the banking sector and the financial ecosystem at large are also exacerbated by a lack of harmonization in regulatory oversight; hence, a regulatory lag is allowing threat actors to expand their reach.
According to the report, the cyber security challenges for the banking sector and the financial ecosystem at large are also exacerbated by a lack of harmonization in regulatory oversight; hence, a regulatory lag is allowing threat actors to expand their reach.
“Banking identities in digital payment systems are the cornerstone of contemporary finance,” the report states. “An attacker compromising an individual’s digital identity would be able to threaten, disrupt, and impact multiple financial accounts, applications, and platforms rather than individual banking applications as traditionally known.
Attackers could also compromise the integrity of compliance monitoring systems, masking their actions or suppressing critical security alerts by modifying logs or monitoring tools.”
“The traditional network perimeter is no longer the exclusive domain of a bank or financial institution,” the report adds.
“The traditional network perimeter is no longer the exclusive domain of a bank or financial institution,” the report adds.
“Banks should transition from a mindset of protecting the network to securing the extended, distributed ecosystem comprising interconnected platforms, partnerships, APIs, cloud infrastructures, AI, and identity management.” The report says that as digital finance grows more sophisticated, organizations need to rethink their security approaches and strategies to account for the dynamic and distributed nature of such a platform.
This article has been indexed from CySecurity News – Latest Information Security and Hacking Incidents
Read the original article:
