You will not receive a warning when an AI system begins mapping your bank's internal network. There will be no unusual login alert, no flagged transaction, no security notification. The first sign may be a payment that has already cleared.
SECTION 1. THE SPEED PROBLEM
Financial crime has always been an arms race. Fraud techniques evolve, banks adapt, fraudsters adapt again. What has changed is the pace of that cycle. For most of the past decade, a sophisticated cyber intrusion into a financial institution, the kind that compromises payment systems or extracts sensitive customer data, required a team of skilled operators working over days or weeks. The institution had time. Not much time, but time to detect, contain, and respond.
AI has compressed that window. The same type of attack that previously took a team eleven days to execute can now be completed in under eight hours by a single operator using commercially available AI tools. Not experimental research-grade tools. Tools that can be purchased or downloaded today. The defenders did not slow down. The attackers got faster.
SECTION 2. WHAT THIS LOOKS LIKE IN PRACTICE
It starts with an email. Not the obvious phishing email with a misspelled domain and a sense of manufactured urgency. An email that knows your name, references your recent work, and is written in the register of someone who understands your institution. Generative AI, trained on publicly available information about you and your organisation, produced it in seconds.
You click. The session is captured. And before your bank's security team has finished their morning briefing, an automated system has begun quietly mapping every server, account, and system your credentials can reach. There is no flashing red light. There is no dramatic alarm. There is only a faint pattern of internal network activity that, in isolation, looks ordinary.
The transfers that follow are not dramatic. They are designed not to be. A series of transactions, each within normal parameters, across several accounts over several days. By the time the pattern is visible, the money has moved. The access pathway is closed. The investigation begins where the attack ended.
SECTION 3. WHY BANKS STRUGGLE TO KEEP UP
This is not a story about negligent banks or inadequate security teams. The institutions that financial regulators assess as operationally resilient, the ones that pass their annual tests and satisfy their compliance obligations, are exposed to exactly this type of attack.
The reason is structural. The frameworks banks use to assess and manage resilience were designed for a different threat environment. They set thresholds for what counts as a significant disruption. They test against scenarios that reflect historical attack patterns. They assess risk on an annual or semi-annual cycle.
An AI-driven attack is specifically designed to operate below those thresholds, to exploit the gaps between assessment cycles, and to move faster than incident response protocols were written to handle. It is not that the rules are being broken. It is that the rules describe a slower, simpler world.
SECTION 4. WHAT NEEDS TO CHANGE
The institutions that will navigate this shift successfully are building something different. Continuous intelligence, rather than periodic assessment. The ability to detect that something unusual is happening inside their systems before it becomes a loss event, not after.
This is a solvable problem. It requires treating AI-driven threats as a category that demands a different operational response, not a variant of the threats that existing frameworks already address. For customers, the practical implication is simpler. Verify before you trust. Even a familiar voice. Even a familiar email. Even a familiar website. The signals that used to mark something as genuine no longer carry the same weight.
SECTION 5. THE VIDEO CONFERENCE THAT WAS NOT REAL
The most instructive single case from the last two years did not happen at a bank. It happened at the finance function of a multinational engineering firm in Hong Kong. A junior finance employee was asked, by what appeared to be a routine email from the group's Chief Financial Officer, to join a video call to discuss a confidential transaction. The call took place. The Chief Financial Officer was on the call. So were several other senior colleagues that the employee recognised. The transaction was discussed. Authorisation was given. The employee processed transfers totalling approximately 25 million United States dollars over the following days, in line with what had been agreed on the call.
None of the people on the call were real. Every face, every voice, every gesture was generated by an AI system that had been trained on publicly available video and audio of the actual executives. The employee had not been negligent. The employee had followed the verification protocol that the firm had specifically designed to defeat email-only and voice-only impersonation. The protocol said, if in doubt, get them on a video call. The attacker had read the protocol and built around it.
The case matters because it illustrates the central uncomfortable truth about this generation of fraud. The defence that worked yesterday is the playbook the attacker uses today. There is no pattern recognition shortcut, no awkward phrasing to spot, no obvious tell. The verification protocols that institutions and customers have been trained on for two decades are being satisfied by the attack itself.
SECTION 6. WHAT YOU CAN ACTUALLY DO
The question every reasonable person asks at this point is the same. If institutions are struggling, what can a normal customer realistically do? The honest answer is that no individual practice will eliminate the risk. The structural solution is at the institutional and regulatory level. But there are three practices that meaningfully reduce personal exposure, and they cost nothing.
The first is the second-channel rule. If you receive a request to move money, confirm a payment, or change account details, never confirm it through the same channel the request arrived on. If the email asks you to call, do not call the number in the email. Call the number you already have stored. If the voice on the phone says it is your bank, hang up and call the bank back on the number on the back of your card. The cost of the extra call is zero. The protection it provides against AI-generated impersonation is meaningful.
The second is to slow the clock. Almost every successful AI-generated fraud relies on urgency. The message is time-sensitive. The transfer must happen today. The opportunity will be lost. Real institutions almost never operate on this timeline for routine transactions. If a request is urgent, that is itself a signal to verify, not a reason to skip verification.
The third is to assume that what looks normal can be fabricated. The familiar email signature, the recognisable voice, the website that looks identical to the one you have used for years, the colleague's face on a video call, none of these carry the weight they used to. They are not evidence of authenticity. They are evidence that the attacker has done their homework. Treat the absence of obvious warning signs as a neutral fact, not as reassurance.
SECTION 7. WHAT BANKS OWE THEIR CUSTOMERS
The conversation about AI-driven fraud often skips a step. It moves quickly from describing the problem to advising customers on how to protect themselves. That framing puts the burden in the wrong place. The institutions that hold customers' money, process their payments, and operate the systems that fraudsters attack have an obligation to make their environment defensible by ordinary people using ordinary judgement. That obligation has not gone away because the threat environment has changed. If anything, it has intensified.
What customers should reasonably expect, and increasingly will expect, is that their bank treats AI-enabled threats as a category that requires a different operational response, not as a footnote to the existing fraud programme. They should expect verification protocols that have been re-tested against deepfake scenarios, not protocols that were last reviewed before deepfakes existed at consumer cost. They should expect that, when fraud occurs through an attack vector the institution should reasonably have anticipated, the institution does not place the loss on the customer. And they should expect that the regulatory regime, in time, codifies these expectations as standards rather than leaving them as aspirations.
The United Kingdom's Authorised Push Payment reimbursement regime, introduced by the Payment Systems Regulator in 2024, is one example of how this expectation is being translated into rule. The regime obliges banks to reimburse customers in most cases of authorised push payment fraud, on the principle that the institution is better placed than the customer to detect and prevent the underlying compromise. Other jurisdictions are watching. The direction of travel is toward institutional responsibility, not customer blame.
SECTION 8. WHY THIS MOMENT MATTERS
Every generation of financial technology has produced its own generation of fraud. The introduction of cheques produced cheque fraud. Credit cards produced card fraud. Online banking produced phishing. Mobile banking produced SIM swap attacks. In each case, the institutions adapted, the rules adapted, and the equilibrium settled at a new point that society could live with. The AI threat environment is not different in kind from those earlier transitions. It is different in pace.
The earlier transitions unfolded over years. Banks had time to test, regulators had time to write, and customers had time to learn. The AI transition is unfolding over months. The institutions that will come through it well are the ones treating it as an architectural shift now, not as a problem to be addressed when the next regulatory cycle requires it. The customers who will come through it well are the ones who have internalised the second-channel rule before they need to use it.
The conversation will continue, here and across the wider Cabier Insights ecosystem. The institutional analysis is published in detail on Cabier Consulting. The regulatory and impact-tolerance framework is in the companion piece on CALCULATORiQ. The series will continue to track the supervisory response, the loss data, and the architectural shift toward continuous intelligence as it happens.
SECTION 9. TORCHLIGHT INSIGHT
- Insight 1. The compression of cyber intrusion timelines from weeks to hours is the single most important shift in financial crime since online banking arrived.
- Insight 2. AI-generated phishing has eliminated the detection edge that bad spelling and awkward grammar used to provide.
- Insight 3. The frameworks that determine whether a bank is operationally resilient were designed for a slower threat environment, and are being outpaced.
- Insight 4. The fix is not blame, it is architecture. Continuous intelligence replacing periodic assessment is the direction of travel.
- Insight 5. For customers, the practical defence is simpler than ever. Verify through a second channel before you trust, even when everything looks familiar.
For risk and resilience teams
The full institutional analysis, including regulatory mapping under DORA, PRA SS1/21, and NYDFS Part 500 and a complete attack scenario walkthrough, is published on Cabier Insights and CALCULATORiQ.
This article was researched and written by human editors with analytical assistance from AI tools. All conclusions, interpretations, and editorial decisions are independently reviewed by the CALCULATORiQ Editorial Team before publication.
For questions about our editorial process, see our Editorial Standards page.
Share this brief
Related Articles

Promise and Peril: Digital Assets, the Unbanked, and the Predatory Inclusion Problem

The Digital Dollar Doctrine: Why Private Stablecoins May Defend Dollar Primacy Better Than a Fed CBDC
