Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Credential abuse and AI-enabled fraud are reshaping financial risk


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: Financial firms are attacked up to 300x more often than other industries, ransomware spiked 900% during COVID-19, and valid corporate credentials now outvalue stolen cards because attackers increasingly live off the land, according to KnowBe4. The sector’s real problem is not volume alone but the combination of human-risk exposure, third-party entry points, and AI-amplified social engineering.

NHIMG editorial — based on content published by KnowBe4: Financial Sector Cyber Threats: The Shifting Landscape

By the numbers:

Questions worth separating out

Q: How should financial institutions reduce credential abuse in high-risk workflows?

A: They should combine phishing-resistant MFA, tight privilege scoping, short-lived access for elevated tasks, and continuous monitoring of administrative sessions.

Q: Why do AI phishing attacks create more risk than traditional phishing?

A: AI lowers the cost, time, and skill needed to produce personalised lures, so attackers can run more campaigns and iterate faster.

Q: What do organisations get wrong about third-party privileged access?

A: Organisations often treat vendor access as a one-time approval instead of a lifecycle that needs ownership, scope, monitoring, and offboarding.

Practitioner guidance

  • Strengthen privileged credential controls Prioritise MFA, phishing-resistant authentication, and session monitoring for finance, treasury, and administrator accounts that can move money or approve access.
  • Reduce reliance on human-only approval paths Require out-of-band verification and dual approval for payment changes, supplier bank-detail updates, and high-risk account recovery requests.
  • Treat vendors as governed identity populations Inventory third-party accounts, set explicit expiration dates, and review whether each supplier still needs access to the systems it can reach.

What's in the full report

KnowBe4's full report covers the operational detail this post intentionally leaves for the source:

  • Sector-specific breakdowns of the most common social engineering and credential abuse tactics affecting financial firms
  • Examples of how AI-powered fraud tooling changes phishing, impersonation, and extortion workflows
  • Additional discussion of ransomware, fourth-party risk, and the attack patterns that make finance a preferred target
  • Practical trend framing for leaders who need to brief on human risk, not just technical control gaps

👉 Read KnowBe4's report on financial sector cyber threats and AI-driven fraud →

Credential abuse and AI-enabled fraud are reshaping financial risk?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Credential governance has become the decisive control plane in financial cyber defence. The report’s emphasis on valid credentials over stolen payment data reflects a broader shift in attacker economics. Once an adversary can authenticate as a trusted user, many downstream controls become conditional rather than preventative. IAM, PAM, and human-risk controls now sit on the same defensive line, and practitioners should treat credential abuse as a primary business risk.

A question worth separating out:

Q: How can organisations tell if human-risk management is working?

A: Look for downward trends in behavioural susceptibility, improved performance in realistic simulations, and better targeting of coaching to higher-risk groups. If the programme only reports attendance or click rates, it is measuring activity, not security improvement.

👉 Read our full editorial: Financial sector cyber threats are shifting toward credential abuse



   
ReplyQuote
Share: