AI Accelerates Cyberattacks, Outpacing Financial Defenses

Anthropic CEO Dario Amodei called on AI companies to slow the development of their most powerful models and said the company would give independent evaluators greater access to its safety work. OpenAI CEO Sam Altman backed the proposal and said pacing AI development had become a primary topic of discussion at OpenAI.
The FCA said AI-generated vulnerability reports may appear technically plausible but prove difficult to reproduce or exploit in real banking environments. It also urged firms to retain evidence that vulnerabilities had been closed while keeping essential financial services operating during accelerated remediation.
Bailey’s remarks also supported the expertise of the City of London Police as the force faces possible merger with the Metropolitan Police under a Home Office-commissioned review examining larger regional police structures.
Anthropic described a Russian-speaking group whose AI-supported espionage operation automatically detected when malware was flagged, rewrote the malware and redeployed it to evade detection; Microsoft separately linked part of the campaign, dubbed “CaptiveCrunch,” to attacks routed through hacked hotel Wi-Fi networks.
Anthropic said the sophistication of an attack is becoming a less reliable indicator of the attacker’s resources: “A single person with a stolen AI account can now sustain the kind of campaign that used to require a well-resourced team.”
AI is helping criminals launch cyberattacks faster than banks can defend against them. Bank of England Governor Andrew Bailey warned that frontier AI could create serious new financial-crime threats, while the FCA said AI finds software vulnerabilities quicker than financial institutions can fix them. Anthropic reported that criminal groups have already used AI to automate major attack parts, including rewriting malware to dodge detection and scanning roughly two million code repositories for exposed passwords.
AI is making it easier for criminals to launch sophisticated attacks with fewer resources. Anthropic found that a single person with a stolen AI account can now run the kind of campaign that previously required a full team. The company documented a Russian-speaking group using AI to automatically detect when malware was flagged, then rewrite and redeploy it to evade detection. Microsoft linked part of this campaign, called "CaptiveCrunch," to attacks routed through hacked hotel Wi-Fi networks.
Financial institutions cannot keep pace with AI-discovered vulnerabilities. The FCA warned that AI generates vulnerability reports faster than banks can test, validate, and deploy fixes. AI-generated reports often look correct but prove impossible to reproduce or exploit in real banking systems, slowing down the remediation process. Banks must balance urgent security fixes with keeping essential financial services running, creating a dangerous backlog of unpatched vulnerabilities.
Top AI executives are pushing for the industry to pause and be more cautious. Anthropic CEO Dario Amodei called on AI companies to slow development of their most powerful models and promised to give independent evaluators greater access to safety work. OpenAI CEO Sam Altman backed the proposal, saying pacing AI development has become a main discussion topic at his company. Both leaders acknowledge that speed in AI advancement is outstripping security safeguards.
AI changes what we can tell from how complex an attack looks. In the past, only well-resourced criminal groups could mount sophisticated cyberattacks. Now, AI automates the hardest parts—from writing code to adapting malware—so attackers with minimal resources can launch advanced campaigns. This shift means financial institutions cannot assume that a complex attack comes from a large, organized group. It could come from anyone with access to an AI tool.
Publishers
20
Articles
14
Reach
34