A New Era of Digital Threats
For years, the advice for spotting cyber threats was simple: look for bad grammar in phishing emails or suspicious links. That advice is now dangerously outdated. Today, generative AI allows malicious actors to craft perfectly worded, context-aware emails,
create convincing deepfake videos and clone the voices of executives to authorise fraudulent transactions. This new class of cyberattack is faster, more sophisticated, and harder to detect than ever before. A June 2026 Financial Stability Report from the Reserve Bank of India (RBI) confirmed this shift, identifying AI-enabled cyber threats as the single most significant risk perceived by India's leading banks and NBFCs over the next year. This is not about a single new type of malware, but a fundamental change in how attacks are conceived and executed at a massive scale.
Why India's Financial Sector is a Prime Target
India's rapid digital transformation has made its banking and financial services sector a lucrative target. With 79% of customer transactions now conducted digitally, the attack surface has expanded dramatically. Cybercriminals are drawn to the vast amounts of sensitive financial data and the potential for significant disruption. Legacy IT systems, common in many older banks, present critical vulnerabilities that advanced AI models can exploit. Furthermore, the sector's heavy reliance on third-party vendors and interconnected systems means a single breach in the supply chain can have cascading effects, turning an isolated incident into a systemic risk. Reports show that phishing remains a dominant threat, accounting for 22% of incidents, and is now frequently enhanced with deepfake technology and voice cloning.
The Evolving AI-Powered Attack Vectors
The threats posed by AI are not theoretical; they are manifesting in specific, damaging ways. Attackers are using AI for highly effective social engineering, creating hyper-realistic phishing and business email compromise (BEC) campaigns that are difficult for even trained employees to spot. Another major threat is self-adapting malware. New frameworks, such as the one nicknamed "Slopoly," use AI to change their own code to evade detection by traditional antivirus software. Attackers also use AI for automated reconnaissance, scanning networks for vulnerabilities at a speed no human team could match. This includes new forms of phishing using QR codes, known as "quishing," which can bypass traditional email security filters and are particularly effective on mobile devices.
Building a Proactive Defence Strategy
The only way to counter AI-driven attacks is to use AI in defence. The RBI has urged banks to move beyond reactive measures and build proactive, multi-layered security frameworks. This starts with a board-approved AI governance policy, as mandated by the regulator, to manage the risks associated with both internal and third-party AI models. Financial institutions are now investing heavily in AI-based threat detection systems, behavioural analytics, and automated incident response tools to shorten reaction times. Many are also collaborating to identify and secure vulnerabilities across widely used software and applications from original equipment manufacturers (OEMs). The RBI has also stressed the need for safeguards in customer-facing AI, such as disclosing when a user is interacting with an AI and providing an option for human assistance.
The Crucial Human Element in an AI World
Technology alone is not a silver bullet. The RBI report and cybersecurity experts agree that the human element remains a critical component of any defence strategy. Employee awareness and training require a significant overhaul. Instead of just looking for spelling errors, staff must be trained to navigate sophisticated social engineering, verify unusual requests through separate channels, and understand the new threat landscape. Banks like HDFC and Axis are implementing continuous training programs, including simulations of AI-driven attacks and adversarial 'red-teaming' exercises, to keep their teams prepared. Creating a culture of security, where every employee feels responsible for protecting the institution, is just as important as deploying the latest defensive technology.













