Article | August 11, 2026

The next banking crisis could start with a cyberattack

By Phillip Cranfield, Wealth Management Lead, DXC Technology

Banking crises are traditionally triggered by credit losses, market panic or a sudden loss of confidence. 

However, the next one could begin with something less visible: an AI-assisted attack that compromises a common supplier, payment process or core operational dependency before institutions can respond.

For financial services leaders, that changes the cyber conversation. Instead of “Can the organization stop every attack?” the question now is, “Can the business keep critical services running when attacks move faster, spread wider and damage confidence?”

Cyber risk has moved onto the stability agenda

The International Monetary Fund (IMF) warned that cyber incidents can create funding strains, raise solvency concerns and disrupt markets when they hit critical financial functions. Its latest analysis argues that advanced AI can reduce the time and cost required to find and exploit vulnerabilities, increasing the likelihood that attackers identify weaknesses in widely used systems at the same time.

In a sector built on shared software, cloud services, networks and payment infrastructure, that creates the conditions for correlated failure rather than isolated disruption. And that’s critical.

If customers can’t access accounts, payments don’t settle or a major provider’s outage affects multiple institutions, the technical incident quickly becomes a business event, shaping customer behavior, liquidity assumptions and regulatory scrutiny.

This isn’t just theoretical musing. The IMF also noted that cyberattacks have more than doubled since the pandemic and that the risk of extreme cyber losses has increased, with financial firms being uniquely exposed because they hold sensitive data and process high-value transactions. 

AI changes the speed and scale of the threat

AI doesn’t need to invent a new form of cybercrime to change the risk equation. It can make existing methods faster, cheaper and more persuasive.

Attackers can use GenAI to create more convincing phishing messages, automate reconnaissance, scale fraud attempts and accelerate the search for exploitable weaknesses. FS-ISAC’s 2025 outlook highlighted GenAI-enabled fraud and scams, supplier attacks, geopolitical exploitation, DDoS and ransomware as key threats testing the operational resilience of the financial services sector. 

The financial impact might come from a whole host of institutions simultaneously discovering that they rely on the same compromised tool, identity process, software component or outsourced workflow.

That’s the executive issue: concentration risk is now a cyber risk.

Regulation is following the resilience argument

Regulators are moving in the same direction.

The EU’s Digital Operational Resilience Act (DORA), which went live in January 2025, requires banks, insurers, investment firms and other financial entities to withstand, respond to and recover from ICT disruptions, including cyberattacks and system failures. 

The European Central Bank’s 2024 cyber resilience stress test of 109 banks sent the same signal. The exercise focused on how banks would respond to and recover from a severe but plausible cyber incident, rather than on whether they could prevent it. 

Prevention still matters, but it no longer serves as an organizing principle. Financial institutions need a tested model for degradation, isolation, recovery and customer communication. In a crisis, strength will be measured by how quickly leaders can protect the services that matter most and prove recovery is safe.

The executive agenda needs to change

For the C-suite, the practical work starts by mapping cyber exposure to business services. Which customer, market, payment, credit, claims or trading services must continue under stress? Which suppliers, cloud environments, data feeds, legacy platforms and identity processes do they depend on? Where could one failure affect several business lines at once?

Leaders must demand evidence, not reassurance.

  • Have the recovery plans been tested against plausible scenarios?

  • Can the organization function if a major supplier is unavailable?

  • Can critical data be trusted after an intrusion?

  • Are customer communications ready before rumor creates its own narrative?

AI should also be part of the defense. The IMF’s point is balanced: AI raises the attacker’s capabilities, but it can also help defenders detect threats, prevent fraud, identify vulnerabilities and respond faster when properly governed. 

What resilience looks like in practice

Several financial services transformations show what better resilience can mean in operational terms. Here’s a quick taste:


NatWest Group’s digitized check-clearing model increased speed and accuracy, enabled machine-learning-based fraud detection and improved the customer experience. The program reduced check-clearing costs by 50%, cut the clearance cycle by 66% and processed around 200,000 checks in a 2-hour window with 99.9% accuracy. It also identified an average of 350 fraudulent checks per month, saving more than £50 million in potential fraud losses each year.

Westpac New Zealand improved the visibility and flow of customer and operational information, supported Reserve Bank-aligned reporting deadlines, strengthened audit processes and enabled faster, more accurate incident triage. Those are resilience outcomes: clearer data, better control and faster decisions under pressure. 

In insurance, MassMutual’s migration of existing applications to AWS improved flexibility for customers and advisers, reduced platform operating costs and accelerated product speed to market. The lesson for banking leaders is that modernization can support resilience when security, automation and recoverability are built into the change program. 



DXC Technology was the partner behind these financial services implementations. More broadly, DXC works with more than 350 active financial services clients and 17 of the top 20 global banks.

Our Hogan core banking platform supports 300 million deposit accounts and processes two-thirds of U.S. card transactions, while our cybersecurity services span threat intelligence, resilience, compliance, disaster recovery and forensics. 



The next move is a resilience decision

AI-powered cyber risk is a leadership test. It checks if financial institutions can protect trust when disruption is fast, ambiguous and potentially shared across the sector.

The next step is to treat cyber resilience as a core business capability: map critical services, test severe scenarios, challenge supplier dependencies, use AI responsibly on defense and make recovery a board-level measure of performance.

The institutions that do this now won’t simply reduce cyber exposure. They’ll strengthen the confidence on which modern finance depends.



About the author

Phillip Cranfield
Wealth Management Lead, DXC Technology