The more AI banks deploy, the bigger the cyber battlefield gets

Indian banks and fintech firms face growing AI-powered cyber threats. Attackers use AI to find vulnerabilities faster than before. Financial institutions are deploying AI to detect and respond to these evolving threats. This creates a new cybersec...

ANI

AI vs AI: India’s banks face a new cybersecurity arms race

India’s banks and fintech companies are facing a new cybersecurity challenge as artificial intelligence makes it easier and faster for attackers to find vulnerabilities, automate attacks and exploit compromised credentials.

This comes as the financial sector itself races to deploy AI across lending, payments, fraud detection and customer service, creating an emerging cybersecurity arms race: as attackers use AI to probe systems faster, financial institutions are turning to AI to detect, predict and respond to threats at a similar speed.

“If the threat actor is a model, your defence actor cannot be a human anymore. Your defence actor has to be a model,” Razorpay CEO and cofounder Harshil Mathur said at the Global Fintech Fest 2026.


Mathur said Razorpay’s security team is already using proprietary and open-source AI models to continuously identify vulnerabilities across its code and infrastructure.

Also Read: If attackers are using AI, companies will have to use AI to defend themselves: Razorpay CEO

“Attackers are consistently using models now to run in a loop and find weaknesses in a system across the board,” he said.
ADVERTISEMENT

Cybersecurity has traditionally relied heavily on human penetration testers and security researchers. AI can now automate parts of that process and continuously look for weaknesses before they are exploited.

“What we see today is the transitionary nature of it, where some companies haven't invested that much in cybersecurity, but the attackers have that model available,” Mathur said. “I think that's a recipe for disaster right now.”

India’s financial sector faces higher cyber risk

The urgency is particularly high for Indian financial institutions. BCG’s latest fintech report, released on Friday at GFF 2026, estimates that Indian banks face 1.6 times the cyberattack intensity of their global counterparts.
ADVERTISEMENT

While 76% of leaders surveyed by BCG rank AI-related attacks as a top concern, only 38% said more than 10% of their IT spending goes towards cybersecurity.

“The question is, are we actually, while we understand this is an issue, spending enough to be able to address it?” said Neetu Chitkara, APAC head for fintech and managing director and partner at BCG.
ADVERTISEMENT

The risk is also moving beyond conventional attacks on employees, customers and applications.

AI is becoming both weapon and attack surface

Cybersecurity firm CloudSEK's cofounder and CEO Rahul Sasi said attackers are increasingly targeting the infrastructure that runs AI itself.

“AI is creating a completely new attack surface for banks. Attackers are no longer just using AI to write better phishing emails or create deepfakes — they are now attacking the infrastructure that runs AI,” Sasi said.

The risk becomes even more significant as banks move towards agentic AI, where systems can access data and applications and take actions on behalf of users.

“The biggest risk is what an AI agent is allowed to do,” Sasi said.

Also Read: RBI flags speed, concentration, opacity as key risks as AI use grows in finance

If a bank gives an AI agent access to customer data, emails and internal systems, compromising that agent or stealing its credentials could potentially give an attacker the same access.

“So the danger isn’t just someone tricking the AI. The bigger danger is someone controlling an AI that already has powerful access inside the bank,” Sasi said.

The concern is not entirely theoretical. Earlier this year, Anthropic’s Mythos model became a flashpoint in the debate around AI and cybersecurity after demonstrating increasingly capable autonomous cyber skills. Anthropic subsequently positioned Mythos 5 as a specialised model for cybersecurity defenders while restricting its strongest capabilities from general users.

The company has also disclosed instances during security evaluations in which Mythos 5 gained access to the live internet and took unauthorised actions, including uploading a malicious software package. Anthropic said these incidents occurred in deliberately configured evaluation environments, but it still goes to show that AI systems themselves can become an attack surface.

AI agents create a new identity problem

As banks move from simple chatbots and copilots towards autonomous or agentic AI systems, another challenge is emerging: understanding what those systems are allowed to access and do.

Identity security company Saviynt’s India and SAARC head Nitin Varma said the traditional question of “who logged in” is no longer enough.

“For a bank, the critical question today is not simply saying who logged in. It is which identity, human or machine or AI, is taking this action, on whose authority, with what access to what data, and within what limits,” Varma said.

The identity landscape is expanding from employees to contractors, vendors, service accounts, APIs, bots, machine identities and AI agents.

Varma identified excessive employee access, third-party identities, privileged access, non-human identities and fragmented identity systems as key vulnerabilities for enterprises, including banks.

Also Read: ‘99% accuracy is not enough’: SBI chairman lays out three rules for trusted AI

Non-human identities can be particularly difficult to manage because service accounts, APIs, certificates, secrets and bots often have permissions that are not reviewed or revoked with the same rigour as employee accounts.

Banks adopting AI agents need visibility into what agents exist in their environment, which applications they can access and what authority they have to act, Varma said.

“The biggest shift that I see today with AI proliferating is that identity security is moving from just managing users to governing every entity that can access data or take action,” he added.

This is particularly difficult for banks running a mix of legacy core banking systems, cloud environments, SaaS applications and newer digital platforms. Rather than immediately replacing legacy systems, banks need a common governance layer that can provide visibility and enforce policies across these disparate environments, Varma said.

Attackers have speed. Defenders need it too

The biggest change brought by AI may not be the nature of cyberattacks, but their speed and scale.

Sasi said banks have always faced an uneven equation: attackers need to find just one vulnerability, while defenders have to protect potentially thousands of entry points.

“From an attacker's perspective they just have to find that one security issue that would give them access, while from a defender's perspective they have to avoid as much of things as possible,” he said. AI has simply made the attacker’s job faster.

“It’s not like the old world was safe. The current, it’s almost the same unsafe world. It’s just that it became easier for attackers to launch those,” Sasi said.

That means financial institutions increasingly need faster mechanisms to identify and remediate threats.

Chitkara said this is where “AI for AI” becomes important — using AI itself as a defence mechanism against AI-enabled attacks.

Public sector banks are also moving

The cybersecurity push is not limited to private banks and fintechs.

Bank of Baroda CEO Debadatta Chand said the financial system needs to invest more in tackling cyber fraud, with vulnerabilities emerging both at the bank level and at the customer level.

Also Read: Banks need to invest more in digital, financial literacy to tackle cyber fraud: Bank of Baroda MD

While banks need to strengthen cybersecurity infrastructure, customer-side fraud, including digital arrest scams and other social-engineering attacks, requires greater investment in financial and digital literacy, Chand said.

Punjab & Sind Bank MD and CEO Swarup Kumar Saha said the lender has strengthened cybersecurity and data-protection measures and appointed a data protection officer.

The bank is also using AI across customer acquisition, employee training, collections and fraud-risk management, while it has created an AI innovation hub and formulated an AI policy.

AI adoption brings its own risks

The concern is that financial institutions may be moving faster in deploying AI than they are in understanding its security implications.

Chitkara said India’s relatively high AI adoption also brings the risk of “shadow AI”, where employees use consumer AI tools or personal accounts to upload company information because the organisation has not provided sanctioned alternatives.

The risk goes beyond data leakage. As AI agents gain access to enterprise applications, a compromised or manipulated agent could potentially become a route into systems that were previously protected from conventional attacks.

Also Read: India’s banks could turn legacy tech into an AI advantage: BCG

Sasi expects the attack surface to expand further as AI models become cheaper, more accessible and increasingly specialised. He said smaller “distilled” models could eventually be built specifically for cyberattacks and operate without the guardrails found in some mainstream AI models.

“We're just in the early inflection point,” Sasi said.
Download
The Economic Times Business News App
for the Latest News in Business, Sensex, Stock Market Updates & More.
READ MORE
ADVERTISEMENT

READ MORE:

LOGIN & CLAIM

50 TIMESPOINTS

More from our Partners

Loading next story
Business News › AI › AI Insights › The more AI banks deploy, the bigger the cyber battlefield gets
Text Size:AAA
Success
This article has been saved

*

+