Six of the seven emerging cyber threats identified for banks and financial institutions in last year’s Digital Threat Report have now become operational realities, with artificial intelligence, stolen digital identities and manipulated payment workflows enabling attacks that increasingly mimic legitimate activity, according to India’s Digital Threat Report 2025-26 for the banking, financial services and insurance (BFSI) sector.
The report, released on Monday by electronics and IT secretary S Krishnan, says the traditional lifecycle of cyber threats—from research and experimentation to widespread exploitation—has dramatically shortened. Threats that once took years to mature are now being weaponised within months or even weeks, allowing attackers to innovate, scale and monetise faster than many financial institutions can respond.
Prepared jointly by CERT-In, CSIRT-Fin and cybersecurity firm SISA, the report says social engineering, credential theft, supply-chain compromise and cloud exploitation have evolved from emerging risks into mainstream attack methods. Of the seven threats highlighted in the previous edition, only quantum computing-related risks have yet to fully materialise, although “harvest now, decrypt later” strategies are already being deployed.
Attacks increasingly resemble normal business activity
A key finding of the report is that the most damaging cyberattacks may no longer resemble conventional security breaches.
Instead, malicious activity can appear as authenticated user sessions, authorised payments, routine account transactions, compromised vendor actions or otherwise legitimate business workflows, making attacks difficult to detect until significant damage has already occurred.
The report groups the evolving threat landscape into three broad categories: AI and human deception, software and systems, and infrastructure and economy.
Under the first category, it identifies industrial-scale deepfakes, synthetic identities, AI-generated phishing, business email compromise, credential theft and session hijacking as major risks. It warns that attackers are increasingly using artificial intelligence to generate, test and deploy scams at machine speed, weakening traditional identity verification methods based on what users see or hear.
The report also highlights what it describes as “AI asymmetry”, noting that capabilities such as vulnerability discovery, exploit generation and attack orchestration—which previously required specialist teams and weeks of effort—are becoming accessible to low-resource threat actors.
At the same time, AI models used for credit assessment, fraud detection, Know Your Customer (KYC) verification and customer onboarding are themselves emerging as attack surfaces through prompt injection, model probing and adversarial manipulation.
Cybersecurity must be treated as systemic risk
Releasing the report, Krishnan said cybersecurity is central to preserving the benefits of India’s rapid digital transformation.
“Cybersecurity is one of the most important concerns that we have to address if we have to preserve all the benefits that we have derived from digitisation,” he said.
He warned that cyberattacks could harm individuals through financial fraud, cripple organisations through ransomware and, in the worst cases, cause disruption at a national scale.
“We have to treat cybersecurity as an enterprise-wide systemic risk against which institutions need to constantly guard,” Krishnan said, adding that digital governance—including AI governance—must prioritise cybersecurity and operational resilience.
He also stressed the need to strengthen India’s technological capabilities, improve identity and account access systems, and leverage AI more effectively to help defenders detect and respond to attacks faster.
Supply-chain, cloud and payment systems under growing threat
The report warns that attacks targeting software and systems are becoming increasingly sophisticated, with growing risks from supply-chain compromise, poisoned software dependencies, cloud misconfigurations, insecure development pipelines and manipulation of payment and API business logic.
Attackers, it says, can exploit vulnerabilities such as OTP race conditions, parallel transaction triggering, object-level authorisation failures and exception pathways without deploying malware or breaching traditional network perimeters.
The third category focuses on systemic threats to financial infrastructure, including ransomware, cryptocurrency-enabled monetisation, firmware and Internet of Things (IoT) compromise, and the long-term impact of quantum computing on encrypted data.
Compliance alone no longer enough
One of the report’s major findings is what it calls the “compliance-security translation gap”—the disconnect between passing regulatory assessments and maintaining effective cyber resilience.
According to the report, institutions may meet compliance requirements while remaining vulnerable because security controls drift from their original purpose, fail to cover the full attack surface or do not keep pace with evolving technologies such as cloud computing, AI, containers and machine identities.
To explain how security incidents unfold, the report introduces a four-layer “Anatomy of Cyber Failure” framework, identifying gaps in system design, policy enforcement, threat detection and incident response. It also outlines four common attack patterns: trusted-entry breaches, privilege escalation, business logic abuse and attacks that evade organisational monitoring.
Roadmap for the next 18 months
The report recommends an 18-month roadmap for strengthening cyber resilience across the BFSI sector.
During the first six months, institutions should deploy phishing-resistant authentication for high-risk accounts, identify service and machine identities, test payment workflows against adversarial manipulation, strengthen encryption key and secrets management, and automate incident containment.
Between six and 12 months, it recommends continuous session assurance, behavioural transaction monitoring, stronger cloud identity controls, runtime software validation and quarterly attack simulations.
In the final phase, institutions should implement passwordless privileged access, strengthen security across AI model and training-data supply chains, improve oversight of third-party vendors and their suppliers, introduce runtime integrity attestation, and begin planning migration to post-quantum cryptography.
The report concludes that financial institutions must shift from periodically demonstrating the existence of security controls to continuously proving that those controls remain effective under real-world attack conditions.




