Skip to content
New technology is increasing the speed and depth of cyber attacks

New technology is increasing the speed and depth of cyber attacks

Ft April 20, 2026

Roula Khalaf, Editor of the FT, selects her favourite stories in this weekly .

Financial services companies are stepping up efforts to strengthen their defences against the growing threat of cyber crime, in an attempt to safeguard their clients, customers and themselves from costly hacks and reputational damage.

Banks such as JPMorgan Chase, Lloyds Banking Group and Santander are taking measures to keep their systems safe amid an increasing number of cyber attacks, as threat actors use new technology to increase the speed and breadth of their attacks.

“More is changing now and faster than we have seen in a long time, the time to find and exploit vulnerabilities is drastically decreasing,” says Patrick Opet, chief information security officer at JPMorgan.

According to IBM’s X-Force 2025 Threat Intelligence Index, the finance and insurance sectors accounted for 27 per cent of all incidents in 2025, the second highest of all industries.

The status of financial institutions as the backbone of modern economies has made them an obvious target for attackers. In particular, their large financial reserves and wealth of customer data make them an attractive option for those seeking to commit cyber crime.

“It is the ability to get paid in a ransomware scenario [which motivates hackers],” says Katherine Kearns, head of proactive cyber services at cyber security consultancy S-RM, adding that this has made financial services companies inviting targets.

For this reason, banks have often been at the forefront of cyber security, being early adopters to technology such as multi-factor authentication and increased supply chain protections.

However, experts have now warned that the rapid adoption of AI has given cyber criminals a new avenue to commit attacks. According to research commissioned by financial and risk advisory company Kroll, 76 per cent of organisations have experienced a security incident involving AI applications or models in the past two years.

Further, the use of AI has made it easier for threat actors to commit attacks and improved efforts to socially engineer victims such as through fake phone calls or “deepfake” videos.

“I received an email pretending to be from a big US bank and it looked absolutely perfect, it was well written, it had a profile and the only thing that got me suspicious was the email address,” says Nick Calver, vice-president for the financial services industry at cyber security company Palo Alto Networks and former cyber executive at Lloyds Bank and HSBC.

“It’s making threats more real and it’s only going to get more threatening,” he adds.

It is the ability to get paid in a ransomware scenario [which motivates hackers]

AI has also enabled hackers to better pick their points of entry, which has often led cyber criminals to look to supply chains as the “soft underbelly” of their real target.

The rapidly changing landscape has forced financial institutions and their cyber advisers into improving their defences in order to combat the changing threat landscape.

Thomas Harvey, chief information security officer at Santander UK, told the FT’s Cyber Resilience Summit in December that to mitigate that risk the company regularly audited its partners.

“We have a lot of cyber security clauses which we stipulate within, we go through various different cyber security assessments in terms of onboarding and we have monitoring tools which are monitoring the external posture of our supply chain in case there are changes,” he said.

“We said to suppliers that if you don’t change your approach, we will stop buying,” JPMorgan’s Opet says, highlighting a 2025 letter sent to suppliers.

“We started probing suppliers on how they defend themselves . . . And so essentially we collect information on all of our suppliers, to identify weaknesses in their infrastructure or signs of pre-compromise,” he adds.

Meanwhile, Lloyds has developed its Global Correlation Engine, an AI tool which helps identify threats and reduce false positives — activity that is misidentified as being malicious.

“Most financial institutions are re-evaluating what ‘good’ looks like,” says Brent Tomlinson, president of risk advisory at Kroll. “[Most cyber incidents are] predominantly an identity issue; social engineering, phishing, etc, so more robust compliance training and programmes, more internal guardrails [are being implemented],” he adds.

The escalating situation has also prompted warnings from cyber experts that companies should train their employees to be aware of such threats.

“If someone rings you up for a password reset, don’t just take this at face value, make them come into the office,” says Toby Lewis, head of threat analysis at Darktrace, a cyber security group.

Regulators such as the Bank of England and the Financial Conduct Authority are advising those in the sector to focus on resilience so that systems can be restored quickly in the event of an attack, according to a person familiar with their thinking.

The changes have also seen some turn to former hackers in order to get inside the heads of those attacking them from the people who know them best.

One of the organisations helping to link the two is The Hacking Games, a group formed in 2023 to help neurodivergent and unconventional cyber talent fall into the hands of the “good guys” rather than criminal gangs.

“The good guys are not very good at recruiting and we wanted to change that,” says Oliver Roskill, co-founder of the group.

The Hacking Games now has partnerships with organisations including the Co-op, the UK retail group which was hit by a damaging cyber attack last year. The collaboration sees groups go into schools to give career talks and assess interested students to see if they could have a calling in cyber security.

“Traditional hiring looks at intelligence, we look at personality and cognitive ability,” Roskill adds. “We do careers talks, and when we get to 16, we will . . . test their aptitudes for a career in cyber.”

One of those working with The Hacking Games is Conor Freeman, a former hacker who served more than two years in prison after being charged with his crimes.

Upon his release, Freeman enrolled in a master’s degree in cyber security at University College Dublin, but struggled to find work because of the stigma associated with his criminal record.

“In the last three years of my life, I had many interviews but as soon as my background came up, I was rejected . . . as soon as they raised it with shareholders, they said not a chance.”

Then he was introduced to The Hacking Games by a mutual acquaintance, and now works on the other half of The Hacking Games’ business model: “offensive security services.”

“We’ve had a lot of people looking for that unconventional point . . . people want a hacker to hack their company like a real hacker would do,” Freeman says.

“I thought the only thing I’m good at was hacking, but had I been exposed to other routes at a younger age I may have gone in a different direction,” he adds.

Extracted Entities

Attack Types (2)

Companies (1)

Industries (1)

MITRE ATT&CK (1)