Since the early 2010s, the banking industry has been embracing digital technologies to enhance customer services and improve efficiency across back-end operations. However, the rapid adoption of emerging technologies also exposes banks and financial institutions to fresh vulnerabilities across the digital landscape, most notably cyber threats.
Today, almost every account holder can access around-the-clock digital banking applications. Consumers now expect banks and financial institutions to deliver instant services and a seamless omnichannel experience across mobile, web, and physical touchpoints.
According to a study by Cornerstone Advisors, "by the end of 2022, just 11% of US banks and 4% of credit unions will not have launched a digital transformation strategy" [1a]. In particular, the COVID-19 pandemic has accelerated the adoption of digital banking, pushing more consumers to rely on remote channels for their day-to-day financial activities.
For example, Wells Fargo – the fourth-largest bank in the US – recorded a 35% increase in remote check deposits and a 50% growth in online wire transfers in 2021 compared with the previous year [2]. These figures demonstrate that implementing a robust digital strategy allows banks to move closer to their customers and tap into new revenue streams and business models that can deliver long-lasting benefits.
Common cyber-attacks targeting digital banking and financial institutions
While digital transformation brings significant benefits to banks, it also amplifies cyber security risks. Compared with traditional banking, online banking is more vulnerable to cyber-attacks because customer data is exposed online across multiple channels and platforms. Cornerstone reports that 33% of attempted breaches against financial services and insurance companies in the US are successful. In 2021, for example, a data breach at the online stock trading platform Robinhood exposed the personal information of 7 million consumers [1b].
A successful cyber-attack can threaten virtually all of a bank's stakeholders, including customers, investors, auditors, IT teams, and even front-line clerks. The most common types of cyber-attacks against financial institutions include, but are not limited to, the following:
Phishing
Phishing emails, in which an email posing as legitimate communication is sent to victims, are among the most common attack vectors for cybercrime because they are increasingly difficult to detect. It is estimated that phishing attacks are the origin of over 90% of all successful cyberattacks. Among the 15 billion spam and phishing emails sent every day, nearly half are directed at or impersonate financial organizations.
A notable example is the Belgian bank Crelan, where a hacker pretended to be the CEO and persuaded someone in the finance department to transfer money overseas, causing the bank to lose €70 million (US$75.8 million) [3].
Ransomware
Ransomware is a type of attack in which the attacker encrypts or otherwise compromises the victim's data and then demands a ransom, threatening to publish or sell the victim's private information if payment is not made. In May 2021, for instance, the Darkside cybercriminal gang targeted UK-based insurance company One Call with ransomware, demanded £15 million, and threatened to leak the company's data, including client information such as passwords and bank details [4].
A recent study found that ransomware assaults against the financial sector rose by 1,318% in 2021 [5]. According to Trellix, 22% of all ransomware assaults in Q3 2021 targeted the banking and financial sector [6], indicating that the sector has become a major focus for ransomware attacks.
Distributed Denial of Service (DDoS) attacks
In a Distributed Denial of Service (DDoS) attack, attackers flood a target website with traffic in order to overwhelm its capacity and cause it to crash. Such attacks disrupt corporate operations, can lead to significant financial losses, and pose a serious risk to financial institutions. Akamai reports that the total number of DDoS assaults in the financial services industry surged by 110% in 2020 compared with the previous year [7].
Recent incidents underscore the scale of the threat. In September 2021, a DDoS attack forced the closure of the websites of major New Zealand financial organizations, including Kiwibank and the national postal service [8]. In June 2021, Fiducia & GAD IT, a German company that manages technology for the country's cooperative banks, also suffered a DDoS attack that affected more than 800 financial institutions nationwide [9].
Enabling multifactor authentication (MFA)
Multifactor authentication (MFA) makes it significantly harder for fraudsters to take over accounts because it requires more than one piece of information to confirm a user's identity.
Under an MFA setup, users are prompted to verify their identity a second time, for example by entering a PIN, answering a security question, or using biometric authentication. By offering a range of authentication options, banks can better match customers' changing preferences and reduce reliance on weak or reused passwords.
According to Microsoft, MFA can prevent more than 99% of account attacks, making it one of the most effective ways to strengthen cybersecurity defenses [11].
Cloud migration and security
There is a common misconception that moving to the cloud exposes data to unrestricted access, while storing information in a locked, on-premise data center is automatically more secure. However, several factors show that cloud environments often provide stronger protection:
- Restricted access to facilities: Cloud service providers (CSPs) enforce strict physical access controls to their data centers. For example, Google implements six layers of identification to recognize authorized staff, using biometric authentication and comprehensive camera coverage [12].
- Resilient disaster recovery: CSPs such as Google store clients' data across multiple devices and in numerous locations. Data is chunked, replicated, randomly named, and made unreadable by humans. These measures improve resilience and support recovery if data is lost in one location.
- Deep security expertise: CSPs typically maintain large, experienced security teams. For instance, Microsoft Azure employs more than 3,500 security experts—a workforce size that can rival an entire organization [13].
- Heavy investment in security: CSPs have the resources to continuously strengthen their security posture. Microsoft, for example, has spent US$1 billion to secure its Azure cloud platform, enabling it to protect against a reported seven trillion potential cybersecurity events every day [14].
As a result of these capabilities, the cloud has become a trusted option for data storage. Government institutions are planning significant investments in cloud technologies. The Pentagon, for example, intends to allocate around US$10 billion to developing cloud services, and the US Department of Defense aims to move its entire infrastructure to the cloud within the next ten years [15]. The banking and financial sector is also showing growing interest: a survey by Accenture found that 20% of international banks have already committed investment funds to developing cloud banking [16].
Digital banking success and the imperative of cybersecurity
Banks and financial institutions are, so far, largely satisfied with the impact of digital banking. A Gartner survey reports that 87% of corporate directors recognize the transformational role of digital initiatives in addressing strategic business priorities, and 67% are willing to increase their budget for technology investment [17].
Against this backdrop, it is high time for banks to adopt robust cybersecurity best practices to stay protected against cyberattacks. As their dependence on digital channels deepens, the resilience of their security posture will increasingly determine the sustainability of their digital transformation.
Because digital banking relies on highly sensitive data to execute financial transactions, banks must be fully aware of the specific risks associated with operating online. They need to design and implement strong cybersecurity strategies to safeguard their data and prevent severe financial losses and long-term reputational damage.
09:36:41 query returned open=false 09:36:58 dblclick "87% of corporate directors" sidepanelOpen=false autoUpdate=true isAdv=false 09:37:02 dblclick "67% are willing to increase their budget for technology investment" sidepanelOpen=false autoUpdate=true isAdv=true