
What do AI-driven ‘bank heist’ attacks mean for defenders?
Tom Kellermann: So understanding how they're maintaining persistence through AI, understanding when AI tools are hijacked and/or broken and are now turned into malicious agents is an imperative. Achieving that is the complicated part. But I do think that one of the Achilles' heels of artificial intelligence is the fact that we really haven't solved for API attacks. And one easy way to jailbreak is through API attacks. So that's one of the singular challenges of defending those guardrails.
Johnny Hand: Welcome to AI Security Brief, where we're unpacking emerging AI threats, vulnerability research, and the strategic decisions that security leaders are making right now. I'm Johnny Hand.
Dustin Childs: And I'm Dustin Childs. Today's guest is Tom Kellermann, who leads AI security and threat research at TrendAI and just authored the new Modern Bank Heist 2026 report. Now, each year, this report takes the pulse of financial sector CISOs, and this year's edition is a turning point.
Johnny Hand: Yeah, exactly. And TrendAI actually surveyed 46 financial sector CISOs, and the headline is now a shift from stealing data to actually disrupting the defenders themselves. Over 60% of these CISOs experienced what we would call counter-incident response. That means attackers are actively fighting back during a live investigation. And all of that's happening at machine speed, which is interesting because over 89% or almost 90% reported more AI-enabled attacks year over year. And then Tom's core argument is that cybercrime has also gone agentic. So specialized AI agents orchestrating phishing, fraud, and exploitation in parallel during these incidents.
Dustin Childs: Yeah, I think this is really a short conversation for everyone, even if you're not in the financial sector, because what hits the banks first tends to hit everything else next. And like Willie Sutton said, it hits the banks first because bank robbers do that because that's where all the money is. So it is interesting to see what the banks are seeing. And there's a way through this, too, though. Tom lays out how defenders can respond in kind at machine speed and why a CISO's independent voice has never mattered more. So let's dive into the conversation.
Johnny Hand: I know the financial sector has always been, you know, a prime target for attackers, even though I think most consumers think that the financial sector's pretty secure. From your report, how is AI moving both the sophistication and the scale of attacks?
Tom Kellermann: Yeah, so this is the eighth time I've written this report. I've written it for a myriad of different organizations, but this one I'm very proud of, here obviously at TrendAI. You know, 67% of the respondents noted that they suffered from counter-incident response, again to that point that we were raising there. And then when that counter-incident response escalates, really escalates, where the burglar per se, the home invasion is now to a point where they want to commit arson, they noted that 41% suffered destructive attacks. That's a big deal. Fifty-five percent said that they didn't know how to solve for API-based attacks and that API attacks were surging. And I think most interesting here is, as we all talk about prediction markets, 46% saw that the adversary was attempting to steal non-public market information or investment strategies of the institution to conduct, you know, digital front-running or insider trading. So you're dealing with adversaries now that recognize it's not just about the money. You know, money's one thing. Moving wire transfers, getting access to accounts, you know, that's lucrative. Sure. But the most valuable information that an institution has is really their non-public market information and their market strategies.
Johnny Hand: And you said that these attacks are being orchestrated using multiple AI agents. What does an agentic attack look like end to end? I mean, where does it break from a traditional playbook? Or is it the same, just more automated with AI?
Tom Kellermann: So two things. I think we should all recognize and appreciate that ungoverned AI should be seen as a C2. I mean, if it's ungoverned and it's operating in an organization, it's basically going to be a gateway drug to any adversary to move laterally, to live off the land in your environment. And you got AI tools that can basically be hijacked. The Russians specialize in jailbreaking a myriad of LLMs out there and AI capabilities, and they turn those very functionalities against you because of the fact that the model has free access to services and tools once deployed in the environment. So for defenders out there, you got to see ungoverned AI as C2. Period. Once you govern it, you need to really be able to understand, is it jailbroken? When will it be jailbroken? Apply rules like least privilege. I mean, John, you've got lots of thoughts on this. I mean, you're protecting our organization as we speak, so I'd love to hear your thoughts on that.
Johnny Hand: Yeah. No, I think we see AI as a new attack surface as well. As much as the innovation that's happening, that's kind of the nice challenge of it. The intent behind AI is important, and businesses are transforming, but it's also an attack surface for a lot of threat actors. So, do you see that with AI, the intent of the attacker has actually shifted, and if you do, what is it that CISOs and security leaders should do differently because of that?
Tom Kellermann: Yeah, I mean, look, not all -- not all models are the same. Some models pay much closer attention to the security and the security of their guardrails. But that being said is, you know, you really need to implement principles like least privilege, eliminate shadow AI. But respect the fact that, you know, again, ungoverned AI is going to be a natural C2 and a natural living-off-the-land capability or platform for adversaries once they're in your environment. It improves their capacity to conduct reconnaissance, delivery, lateral movement, but more importantly, persistence. So I think understanding how AI enables persistence, I mean, TrendAI just put out a great report on bandcampro, a Russian actor that basically jailbroke Gemini and then dynamically created C2s within six minutes and move -- dynamically move and shift his C2 throughout an infrastructure. So understanding how they're maintaining persistence through AI, understanding when AI tools are hijacked and/or broken and are now turned into malicious agents is an imperative. Achieving that is the complicated part, but I do think that one of the Achilles' heels of artificial intelligence is the fact that we really haven't solved for API attacks. And one easy way to jailbreak is through API attacks. So if you guys have any suggestions on best practices for API security, I'd love to hear them. But otherwise, you know, that's one of the singular challenges of defending those guardrails.
Johnny Hand: No, I don't actually have that. And if I did, I would patent it and go sell it to everyone, because we're all looking for that. But I do want to take a look at how these attacks are actually taking place, because I think you mentioned before we really started recording that business email compromise is still, like, one of the biggest ways that these attackers are getting in. How is AI aiding? Is that still true in the world of agentic AI, and how is agentic AI affecting that first compromise?
Tom Kellermann: So, from a fraud perspective, to your point, business email compromise was one of the biggest concerns of the institutions. But they're also very concerned with what's called reverse business email compromise. So when you think of business email compromise for the movement of funds, right, it's an outside-in approach. But if you can hijack the accounts of, let's say, Johnny, or you, Dustin, and then have money wired or have an order for money to be wired, and then bypass authorization through AI by creating a deepfake video and/or deepfake messaging that aligns with everything, but it's coming from your true account, right? Like your employee digital twin, essentially, that is highly problematic. And so they're very concerned about the evolution of RBEC, reverse business email compromise, and account takeovers from a fraud perspective. And then the other part is they're very concerned with the fact that their market strategies and non-public market information is being stolen to conduct digital front-running and insider trading, because that's their most valuable asset.
Johnny Hand: At Pwn2Own Berlin, we did have multiple AI categories. And to me, I think the one that was most interesting was actually an exploit of Exchange, Microsoft Exchange. And the researcher who goes by the name Orange, he said that he told the AI what to do, and then the AI wrote the exploit. But it was his knowledge of Exchange -- he's a very gifted researcher and has exploited Exchange on multiple occasions. So that really showed that AI can really do this and really can create these viable exploits, but it takes a trained researcher in order to guide it and get it through. One of the things that we have in the ZDI that we're running against now is we're trying to analyze these reports. We're using AI to do it. And the AI is coming up and saying, "No, that sounds like you're going to do something bad, and I'm not going to let you do that anymore." So we have a challenge of training the AI to, like, "No, we're the good guys, and we need to do this." But yeah, to me, that was the most impressive thing, because it was a very, very complicated exploit, which as of this date, Microsoft still hasn't patched. So, it's very interesting to see.
Tom Kellermann: Wow. So one of the things that was notable in the report that ties back into the conversation about AI and AI-enabled attacks is this resurgence of RATs. Remote Access Trojans and rootkits are really flourishing, and financial institutions are really grappling with those because it allows for persistence for obvious reasons. But one of the notable parts of that is that RATs are deploying steganography to maintain persistence. Steganography is easily created now because of AI. And steganography used to be a, you know, an art form that would take time and a lot of resources to create the perfect stego. So I'm fascinated by some of these RATs like XWorm, modular capability. It's a RAT that actually performs a myriad of different attack functions. It completely automates the kill chain, and it uses stego to maintain persistence. So just one example from the report.
Johnny Hand: Do you feel like -- I was thinking about the steganography vantage point and, you know, even like -- I don't know. I remember 15, 20 years ago, you know, hiding stereo messages inside the images, like, goofing around as kind of a low-level crypto type capability. But now with AI, it's so fast. I'm thinking from a CISO hat, right? Like, how do I gain visibility, you know, understanding that my folks are uploading images and, you know, screen captures all day long into their different models for processing, right? And the fact that the native guardrails really aren't designed for that level, we have some capabilities inside our AI Guard that does cover these types of things, but it's a big challenge. Do you see that as a growing attack surface for AI? Are you seeing it more and more? Is there signal there that we should really start looking at solution-oriented offerings?
Tom Kellermann: I do. I do. And I think the first company to bring that solution to market will actually make it rain. And in the same vein with API security, those are two huge gaps, and given the environment we live in and the culture that we live in, both of those must be solved for. But I think it goes back to the original point of, you know, we really -- we've been focusing so much on AI-enabled weaponization, AI reconnaissance. We really need to start focusing on that whole persistence. How they're maintaining persistence through AI, how AI can act as command and control, or how AI can precipitate or manifest these, you know, C2s that are dynamic and/or stego that is persistent. That is really what defenders should be focusing on, particularly if you're a Fortune 1000, or you're doing business with a Fortune 1000, and they want to hijack your environment to target that entity.
Johnny Hand: Yeah. Yeah. That makes a lot of sense. If we can go back to the topic of resource constraints, I know that about half of security leaders saw no budget increase for their security teams, and they still report to the CIO. What needs to change structurally for institutions to set them up in terms of the fight so that they can be successful in defending against both the initial as well as the persistent attacks?
Tom Kellermann: And this is infuriating to me. Absolutely infuriating to me, you know. If you're a financial institution, your CISO should be reporting to your CEO, just like Johnny does here. It's just the way it should be. You should have direct access. You shouldn't be fighting for resources with your CIO. But also, I think as -- I'm going to keynote at the FFIEC's Regulatory Summit in DC coming up soon. There needs to be reporting requirements for whether or not your infrastructure's being used to island hop. What I mean by that is whether or not your infrastructure's been hijacked to be used to attack other parties. And there should be reporting requirements around destructive attacks. "Have you suffered a destructive attack?" not "Have you paid for ransomware or suffered a ransomware attack?" I think there's gaps in the reporting, and there needs to be shifts and higher levels of mandates to solve for some of the problems that we deal with today. Like, you know, you got a lot of zero days out there. Virtual patching, vulnerability shielding should be a mandate, etc., etc., etc.
Johnny Hand: Yeah, that was kind of where I was going next, was because the financial institutions are heavily regulated, are we going to start seeing some more regulations come out that are focused on AI, or at least response to agentic AI exploits?
Tom Kellermann: We will. The US will probably drag their feet because of the K Street lobby, and the dilution of proactive regulation when it comes to cybersecurity in the financial sector. I think the Monetary Authority of Singapore will be a first mover because they've always been much more, as I say, draconian and/or risk-averse. And I think the Europeans will follow suit, and then the FFIEC will hopefully follow in lockstep. But at a minimum, I think there needs to be greater -- less plausible deniability and much more transparency into the duality of utility of AI and/or the attacks today.
Johnny Hand: That's interesting. I will say, going back on your your statement about aligning the security organization up through the CEO, there's probably a lot of security leaders that are listening in on this podcast and cheering, mainly because I think that they want to bring that louder voice into the boardrooms, and a lot of CISOs are reporting to the board, but they're not a member of the board. They're not having that CEO-level. And I've always -- I've always viewed the CIO relationship as very complementary and always, you know, a good alignment for the most part, but as we move into the era of AI, it does create a lot of challenges because you're tasked with securing something that is, you know, being driven by the business, and if you are competing with resources, alignment, and those kind of things, I can definitely see that being a big challenge. So you'll probably have both cheers and a little bit of, you know, hopefully not too much challenge from our CIO community as well.
Tom Kellermann: Well, what about -- what about veto power? At a minimum, a CISO should be able to veto any project initiated by the CIO or CTO that creates systemic risk throughout the organization. Or slow something down because the red team exercises that your teams have conducted, Johnny, prove that there was, you know, an incredible attack surface there.
Johnny Hand: Yeah, I agree. I think there's a level of maturity in an organization that needs to happen, centering the security as a really close business partner in all of this. I think the alignment of it is interesting. I certainly think that there's -- you know, and we saw this for years, right? We saw it with the CIO, the growth of the CIO movement and CTO movement kind of inside organizations for the last decade, where they kind of went from, you know, secondary C-suite positions into a more primary and then, you know, reporting directly to the CEO. So I think it's the natural progression. AI's accelerating that because there's a need for transparency and visibility across the organization, and it's not a bolt-on capability. So definitely in agreement on a lot of what you're saying.
Dustin Childs: Well, real quickly, I mean, the one thing that I kind of was interested in is we're talking about offensive use of agentic AI. Are financial institutions at all in your surveys and your conversations with them using agentic AI for defensive solutions? And if so, what happens when you run out of tokens in the middle of an incident response?
Tom Kellermann: Yes, financial institutions are using it for defensive measures, primarily for threat hunting, attack path mapping, incident response, you know, automation. I think they're challenged in and of themselves with the amount of information and volume of data that's coming at them and the persistence of the adversary within systems. I think one of the challenges -- back to the points about adversaries leveraging counter incident response and becoming more punitive against the defenders is we really need to change the way we defend. For example, like, in today's world, you don't necessarily want to terminate the command and control that you found because it might trigger a succession of events or a cascading impact of, like, dynamic C2s dropping wipers in your system or an adversary essentially going nuclear. So I think it's important to note that -- I do think that they're facing bigger challenges in the sense that they understand that their market strategies are really their holy grail, and that if their adversary is now working for a foreign sanctioned bank who can take market positions ahead of their institution, they're taking a huge hit to the nature of their transactions as they work in the markets, especially the commodity markets.
Johnny Hand: So, Tom, in the interest of time and as we kind of wrap up the interview here, I wanted to make sure that we didn't miss an opportunity to get your viewpoint on today's topic. So, is there a piece of hard-won wisdom about AI security that you'd want security leaders to know about, or maybe one to two key takeaways from today's conversation that security leader could walk away and say, "I need to look into that"?
Tom Kellermann: So, from an AI security perspective, treat AI, ungoverned AI, as a C2 channel. When you begin to govern it, I think, like you said earlier, visibility, observability, and least privilege are quintessentially important, as initial steps to protecting it. I do think if you standardize on one model versus another, maybe using deception technology to understand when guardrails are being tampered with could be very beneficial to you, given that, you know, protecting the guardrails themselves is still an art form. To me, at least. And then last but not least, don't underestimate the adversary. You've got cybercrime cartels that are being protected by four rogue nation-states that are actively pursuing you. And we've seen evidence of collaboration now, real collaboration between those four rogue nation-states, or I call them the Axis of Cyber, and they're purposely targeting financial institutions out there right now to offset economic sanctions.
Johnny Hand: So, Tom, thanks for the great conversation today. I don't know if we're going to excite people or terrify them with this, but we really appreciate you sharing your insights on machine speed, the threats that's facing financial institutions, and we can't wait to have you back on the show in the future.
Tom Kellermann: Thank you very much.
Johnny Hand: Wow. Dustin, that was an amazing episode, and I felt like we could have talked to Tom forever, especially as we started unpacking how the financial industry is impacted, how agentic AI in the attack path is coming about, and then also how we're seeing those parallels where we're shifting from just stealing data into actually disrupting those operations where the attackers are fighting you live while you're trying to do your investigation.
Dustin Childs: Yeah, and because cybercrime is now industrialized and agentic, human-paced defense just can't keep up. And Tom's answer is AI-driven detection and response, which frees your analysts to do the higher-value work rather than replacing them.
Johnny Hand: Yeah, that's a good point, and I'll be honest, as a CISO, I liked another piece that he talked about, which was very structural. You have to elevate the CISO and rebalance spend towards people and managed detection, not just the tooling. So that structure really is a good strategy.
Dustin Childs: You know, this episode reminded me of our very first episode with Robert McArdle, too, where he talked about vibe crime and how agentic AI is being used for criminals-as-a-service. And that might be something you want to listen to as well if you have the time after this episode is done. We want to thank Tom Kellermann for joining us and sharing his research with us. Check out the show notes for his report, Modern Bank Heist 2026, and how to connect with Tom.
Johnny Hand: And that does it for another episode of the AI Security Brief. We want to thank you for joining us, and our goal is always to host conversations that get you thinking differently about security. And if it does, please subscribe so you don't miss what's next.
Dustin Childs: AI Security Brief is mixed and produced by Elliott Peltzman, with original music by Amneajynx. Executive producer is Jennifer Eiben, with content strategy by Ma'ayan Plaut and Melany Gallant. Additional production help from Liz Stokes. Video editing by Sarelle Joppy and Brigitte Criqui-Wild.
Johnny Hand: Thanks so much for listening, and we'll see you next time on the AI Security Brief. [ Music ]


