Sunday, June 21, 2026

Security Boulevard Logo

Security Boulevard

The Home of the Security Bloggers Network

Community Chats Webinars Library
  • Home
    • Cybersecurity News
    • Features
    • Industry Spotlight
    • News Releases
  • Security Creators Network
    • Latest Posts
    • Syndicate Your Blog
    • Write for Security Boulevard
  • Webinars
    • Upcoming Webinars
    • Calendar View
    • On-Demand Webinars
  • Events
    • Upcoming Events
    • On-Demand Events
  • Sponsored Content
  • Chat
    • Security Boulevard Chat
    • Marketing InSecurity Podcast
    • Techstrong.tv Podcast
    • TechstrongTV - Twitch
  • Library
  • Related Sites
    • Techstrong Group
    • Cloud Native Now
    • DevOps.com
    • Security Boulevard
    • Techstrong Research
    • Techstrong TV
    • Techstrong.tv Podcast
    • Techstrong.tv - Twitch
    • Devops Chat
    • DevOps Dozen
    • DevOps TV
  • Media Kit
  • About
    • Sponsor

  • Analytics
  • AppSec
  • CISO
  • Cloud
  • DevOps
  • GRC
  • Identity
  • Incident Response
  • IoT / ICS
  • Threats / Breaches
  • More
    • Blockchain / Digital Currencies
    • Careers
    • Cyberlaw
    • Mobile
    • Social Engineering
  • Humor
Security Bloggers Network 

Home » Editorial Calendar » API Security » Defending the Enterprise: New Insights from Banking Industry Experts on Fraud and Cyber Threats

SBN

Defending the Enterprise: New Insights from Banking Industry Experts on Fraud and Cyber Threats

by Jordan Gottlieb on September 17, 2024

As cybercriminals continue to raise the bar in terms of the sophistication of their attacks, as well as forging an easier path to conduct these attacks, the key to weathering this growing storm of cyber threats lies in the detection further up the cyber kill chain. The sooner the detection, the higher the chances your bank has of stopping these attacks before they cause damage to your customers and systems. However, the longer these vulnerabilities remain exposed, the greater the risk – turning what could be a minor assault into a full-scale invasion. 

This urgent need for proactive action was underscored in a recent webinar featuring industry experts Chief Insights Officer Julie Conroy from Datos Insights and Arkose Labs Head of Product Vikas Shetty. We had the honor of diving deep into this and other pressing issues, and their wealth of experience and sharp insights are incredibly valuable as we navigate the complexities of modern cybersecurity in banking. Here are the key takeaways.

From Lone Wolves to Organized Cybercrime

The session kicked off with a stark look at the shifting threat landscape. Vikas explained how cybercrime has evolved from isolated hackers to coordinated crime syndicates using advanced technologies. Banks and other financial institutions now face a significantly expanded threat surface, as attackers deploy sophisticated tools across various endpoints such as APIs. This shift has made traditional security measures less effective, requiring constant vigilance and adaptability.

A New Era of Threats 

One of the most eye-opening trends is the rise of cybercrime-as-a-service (CaaS), a fully outsourced entity that generates revenue from bad actors who purchase a subscription for use of the service. Similar to a peer-to-peer (P2P) model, CaaS is an attacker-to-attacker (A2A) model where the CaaS entity provides a hosted software platform that can be used to actively engage in criminal attacks on their subscribers’ behalf, or provides an enabling service assisting subscribers with their own attacks. 

Julie and Vikas illustrated how this model has significantly lowered the entry barriers for cybercriminals. Phishing kits are often purchased for just a few hundred dollars a month, and require little to no technical experience. This has resulted in a troubling increase in account takeover (ATO) attacks and a rise in sophisticated schemes like man-in-the-middle reverse proxy phishing, where phishing emails direct customers to reverse proxy servers that capture real credentials and MFA codes. Similarly, ATO attacks now involve advanced automation and AI, making them more effective and harder to detect. Julie shared data showing that ATO continues to be a major concern globally, with attackers increasingly using AI to enhance phishing schemes and scale attacks.webinar Arkose Labs screengrab

The Growing Concern of API Security 

With the rise of open APIs driven by PSD2 in Europe and similar regulations in North America, API security has rapidly become a top concern for financial institutions. Securing APIs is akin to locking all the doors in a sprawling mansion, yet some doors remain hidden behind walls or beneath staircases. Without a full inventory, financial institutions can’t know which doors are secure and which ones are wide open, leaving room for intruders to slip through unnoticed. 

Julie pointed out that securing these APIs is a complex challenge due to their diverse nature – whether mission-to-mission, process-to-process or those powering websites and mobile apps. Vikas emphasized that no single solution can effectively safeguard all types of APIs, which makes comprehensive protection a daunting task. Many institutions struggle with inventory management and discoverability of their APIs, often leaving potential vulnerabilities unchecked.

This lack of confidence, with 59% of financial institutions still in the dark about their API exposure, highlights a critical vulnerability. As attackers become more sophisticated, even a single overlooked endpoint can lead to catastrophic attacks. Julie reinforced the urgency of addressing this issue, as APIs have quickly become a prime target for cybercriminals. Without a comprehensive, focused approach to API security, financial institutions are leaving themselves open to exploitation.

Fraud in the Era of Real-Time Payments (RTP)

Julie also highlighted a significant trend: fraud attacks that are growing alongside the adoption of real-time payments (RTP) systems. Fraudsters are exploiting faster payment rails to quickly move stolen money through extensive networks of mule accounts, making it increasingly difficult to trace and recover funds. Julie emphasized that these criminals are capitalizing on the vulnerabilities of the end customer, and the speed of transactions exacerbates the challenge of tracing and reversing fraudulent activity.

AI: A Double-Edged Sword

The discussion then turned to the role of AI, and Julie noted that while adversaries are early adopters of AI, using it to develop and scale attacks with greater efficiency, banks are still lagging behind. This is due to the lengthy process large financial institutions face in adopting new technologies, driven by a need for transparency and traceability. For instance, the process of adopting AI in banking involves navigating business cases, legal reviews, IT queues and model risk governance, which slows down the integration of AI compared to its rapid adoption by attackers. On the defensive side, banks are deploying AI in back-office use cases, such as automating claim disputes and triage, but face challenges in applying AI to frontline fraud detection. 

Meanwhile, malicious actors are using AI to create highly convincing phishing schemes and to scale their operations more effectively. The introduction of generative AI into the ecosystem has further amplified these threats, with attackers leveraging advanced AI tools to craft realistic emails and execute more sophisticated fraud tactics. 

Vikas elaborated on the impact of AI, distinguishing between classical machine learning methods and generative AI. While classical AI methods are being used to tackle traditional ATO and fraud issues, generative AI introduces new challenges like impersonation attacks and deep fake frauds. Vikas noted that generative AI’s probabilistic nature makes it less suited for detection scenarios but emphasized that it presents significant concerns due to its potential for creating realistic fake personas and deep fakes.

Navigating the Regulatory Maze 

We also explored the complex regulatory landscape, which plays a crucial role in shaping how financial institutions approach cybersecurity. Julie outlined several key regulations, including FFIEC 2021 update, Dodd-Frank 1033, PCI DSS 4.0, DORA (Digital Operational Resilience Act), NIS II and PSD3, emphasizing that while these regulations provide a baseline for compliance, they should be viewed as minimum standards. Financial institutions should aim to exceed these standards to address the rapidly evolving threat environment effectively. Regulations can help justify investments and propel business cases, but they are not a substitute for a proactive and robust security posture.

Proactive Defense Strategies for Banks 

As we explored solutions, Julie discussed the importance of a nimble control framework. Traditional fraud detection often resembles putting a bucket under a leaky roof after the rain has already started. Proactive defense strategies, on the other hand, are about fixing the roof before the storm hits, ensuring the damage is mitigated before it can even occur. The challenge lies in overcoming operational hurdles and leveraging AI effectively, as the attackers do. Julie stressed that banks adopting AI-driven solutions and faster response mechanisms can significantly improve defenses.

Vikas echoed this sentiment, stressing the need for proactive detection and mitigation strategies. He explained that traditional methods of waiting until after a transaction to analyze and respond are too slow. Modern approaches involve multi-layered security and progressive proofing, where evaluations occur at various points during a transaction, starting at the login or registration stage. This allows for earlier detection of potential threats and minimizes downstream impact.

Join Us for More Insights

The insights shared during our webinar are just the beginning of what’s needed to tackle today’s cybersecurity challenges in banking. To see the actual research Julie shared and to dive deeper into these crucial topics, I encourage you to download the on-demand webinar. 

Sign up for our upcoming webinar Defending the Enterprise – Fusion Realities: Collaboration in the Age of AI on September 26!

 

*** This is a Security Bloggers Network syndicated blog from Arkose Labs authored by Jordan Gottlieb. Read the original post at: https://www.arkoselabs.com/blog/new-banking-insights-fraud-cyber-threats

September 17, 2024September 17, 2024 Jordan Gottlieb account takeover, API security, fraud prevention
  • ← Beyond the Hype (Cycle): Why CDR’s Current Phase Spells Success
  • Get Caught Up With ggshield: New Ways To Install, Custom Remediation Messages, SERIF, And More… →

Techstrong TV

Click full-screen to enable volume control
Watch latest episodes and shows

Tech Field Day Events

Upcoming Webinars

True Agentic SecOps at Lakehouse Scale
Agentic Software Delivery in 2026: How To Bridge The Gap Between AI Ambition and Delivery Confidence
Untangling the EU Cyber Resilience Act
The Software Supply Chain Just Got Harder to See
Building a Resilient Security Culture in the AI Era with AWS & Datadog

Podcast

Listen to all of our podcasts

Secure by Design

3 weeks ago | Jack Poller

Senator Sanders Wants to Own AI Companies — and Hand America’s Adversaries the Keys

4 weeks ago | Jack Poller

NIST’s Nine: The PQC Signature Race Moves to Round Three

4 weeks ago | Jack Poller

The Quantum Arms Race: Why Washington Just Wrote a $2 Billion Check to Nine Companies

1 month ago | Jack Poller

Beyond Moore’s Law: The Hyper-Acceleration of Autonomous AI Cyber Capabilities

1 month ago | Jack Poller

The Exception Economy: When Security Teams Stop Protecting and Start Negotiating

Press Releases

GoPlus's Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

GoPlus’s Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

C2A Security’s EVSec Risk Management and Automation Platform Gains Traction in Automotive Industry as Companies Seek to Efficiently Meet Regulatory Requirements

C2A Security’s EVSec Risk Management and Automation Platform Gains Traction in Automotive Industry as Companies Seek to Efficiently Meet Regulatory Requirements

Zama Raises $73M in Series A Lead by Multicoin Capital and Protocol Labs to Commercialize Fully Homomorphic Encryption

Zama Raises $73M in Series A Lead by Multicoin Capital and Protocol Labs to Commercialize Fully Homomorphic Encryption

RSM US Deploys Stellar Cyber Open XDR Platform to Secure Clients

RSM US Deploys Stellar Cyber Open XDR Platform to Secure Clients

ThreatHunter.ai Halts Hundreds of Attacks in the past 48 hours: Combating Ransomware and Nation-State Cyber Threats Head-On

ThreatHunter.ai Halts Hundreds of Attacks in the past 48 hours: Combating Ransomware and Nation-State Cyber Threats Head-On

Subscribe to our Newsletters

Most Read on the Boulevard

Databricks Acquires Cybersecurity Startup Panther Labs to Fortify AI Defense
SailPoint Acquires Entro to Continuously Detect and Monitor Non-Human Identities
MSG Breach: Knicks Take the NBA Championship, ShinyHunters Takes the Data 
Malwarebytes Finds Ad Scams Hidden in 40+ World Cup Streaming Sites
F5 Embeds Neural Network in WAF Platform to Continuously Assess Risks
FortiBleed Leak Exposes VPN Credentials for Nearly 74,000 Fortinet Devices
Kodak Confirms Data Breach Claimed by ShinyHunters Extortion Gang
Microsoft Defender Zero-Day Privilege Escalation Vulnerability (RoguePlanet)
GitHub Locks Down npm: What the New Install Defaults Mean for Your Supply Chain
973 MCP Packages, 71% Single-Maintainer: A Practitioner’s Guide to AI Developer Security

Industry Spotlight

NYC Sewers Crawling With Rats and Potential Bad Actors 
Cybersecurity Featured Industry Spotlight Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threats & Breaches 

NYC Sewers Crawling With Rats and Potential Bad Actors 

June 18, 2026 Teri Robinson | 3 days ago 0
Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks
Cloud Security Cybersecurity Data Privacy Data Security Featured Incident Response Industry Spotlight Malware Mobile Security Network Security News Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threats & Breaches Vulnerabilities 

Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks

April 12, 2026 Jeffrey Burt | Apr 12 Comments Off on Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks
The Day the Security Music Died
AI and Machine Learning in Security Cybersecurity Featured Industry Spotlight Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

The Day the Security Music Died

April 8, 2026 Alan Shimel | Apr 08 Comments Off on The Day the Security Music Died

Top Stories

Job Seekers Make for Vulnerable Targets
Cybersecurity Data Privacy Data Security Featured News Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

Job Seekers Make for Vulnerable Targets

June 19, 2026 Teri Robinson | 2 days ago 0
MSG Breach: Knicks Take the NBA Championship, ShinyHunters Takes the Data 
Cybersecurity Data Security Featured News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

MSG Breach: Knicks Take the NBA Championship, ShinyHunters Takes the Data 

June 18, 2026 Teri Robinson | 3 days ago 0
Trying to Control AI is Like Holding Sand
AI and Machine Learning in Security Cybersecurity Featured News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

Trying to Control AI is Like Holding Sand

June 17, 2026 Alan Shimel | 3 days ago 0

Security Humor

Fortinet® Follies

Fortinet® Follies

Download Free eBook

[su_panel border="0px solid #ddd" radius="0" text_align="center" padding-top="0px" padding-bottom="0px"]
Managing the AppSec Toolstack
[/su_panel]

Security Boulevard Logo White

DMCA

Join the Community

  • Add your blog to Security Creators Network
  • Write for Security Boulevard
  • Bloggers Meetup and Awards
  • Ask a Question
  • Email: [email protected]

Useful Links

  • About
  • Media Kit
  • Sponsor Info
  • Copyright
  • TOS
  • DMCA Compliance Statement
  • Privacy Policy

Related Sites

  • Techstrong Group
  • Cloud Native Now
  • DevOps.com
  • Digital CxO
  • Techstrong Research
  • Techstrong TV
  • Techstrong.tv Podcast
  • DevOps Chat
  • DevOps Dozen
  • DevOps TV
Powered by Techstrong Group
Copyright © 2026 Techstrong Group Inc. All rights reserved.
×

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.