Skip to main content

What do AI-driven ‘bank heist’ attacks mean for defenders?

13 авг. 2026 г. · 23 min

Featured guest

Tom Kellermann

Tom Kellermann

VP of AI Security and Threat Research · TrendAI™

Hosts

Johnny Hand

Johnny Hand

Global CISO · TrendAI™

Dustin Childs

Dustin Childs

Head of Threat Awareness · ZDI

PortableText [components.type] is missing "span"

AI Security Brief Episode 9 with guest Tom Kellermann

About the episode

Attackers aren't just using AI to steal data; they're using it to fight back while you investigate them in real time. And once an adversary is inside, why would they ever want to leave? That's the unsettling reality Tom Kellermann, VP of AI Security and Threat Research at TrendAI, lays out in this episode. And the numbers prove it. According to a 2026 TrendAI survey of 46 financial-sector CISOs, more than 60% of respondents experienced counter-incident response, where adversaries actively disrupt live investigations. In addition, nearly 90% of these leaders reported more AI-enabled attacks year over year.

What you'll learn
  • Why ungoverned AI should be treated as a command-and-control (C2) channel, and how attackers use it for reconnaissance, lateral movement, and persistence
  • How agentic attacks work end-to-end, from jailbreaking LLMs through API attacks to dynamically spinning up C2s in minutes
  • What tactics are used most for bank crime, from the rise of reverse business email compromise (RBEC), deepfake "employee digital twins," and the theft of non-public market information for digital front-running
  • How strategic leadership alignment can improve AI defense

Episode chapters

  • 00:00 — Why APIs are an Achilles’ heel for AI security
  • 02:17 — How AI is changing attacks on financial institutions
  • 03:30 — What an agentic attack looks like end to end
  • 04:50 — Treating AI as a new attack surface
  • 06:46 — How AI strengthens business email compromise
  • 10:01 — Steganography and the growing AI attack surface
  • 12:12 — Why CISOs need greater authority and independence
  • 16:32 — How financial institutions use AI for defense
  • 18:07 — Hard-won guidance for security leaders

"Ungoverned AI should be seen as a C2. If it’s ungoverned and operating in an organization, it’s going to be a gateway for any adversary to move laterally."

— Tom Kellermann, VP of AI Security and Threat Research

Hosts

Johnny Hand

As the Global CISO for TrendAI™ and veteran of enterprise security, Johnny brings a security leader’s lens to every conversation, separating exploitable risk from theoretical noise. Johnny is the person you want explaining AI-era threats before your board asks about them.

Johnny Hand
Dustin Childs

Dustin Childs

As Head of Threat Awareness for the TrendAI™ Zero Day Initiative (ZDI), Dustin brings a vulnerability researcher's eye to the AI security conversation. He’s dedicated to making sure the industry understands exploit development before it becomes a crisis.

More episodes

  • AI Security Brief Episode 10 with guest Zach Evans

    Episode 10 · 27 авг. 2026 г.

    What does hospital downtime teach us about building AI-native organizations?

    Is your organization truly AI native, or did you just bolt AI onto existing infrastructure? Your answer could be an indicator to how much risk you’re carrying without realizing it.

  • AI Security Brief Episode 8 with guest Mark Houpt

    Episode 8 · 30 июл. 2026 г.

    Is AI security actually a physical problem?

    While AI might seem abstract, something that lives in "the cloud" is concrete. The AI applications we use every day run on GPUs in physical buildings, and Mark Houpt secures them.

  • AI Security Brief Episode 7 with guest Sundari Parekh

    Episode 7 · 16 июл. 2026 г.

    Who governs your AI agents?

    Your team spent a decade maturing privileged access management. Then AI agents arrived and they don’t log in like humans.

  • AI Security Brief Episode 6 with guest Rob Bair

    Episode 6 · 2 июл. 2026 г.

    Is the next frontier model your biggest threat or your best defender?

    If you think the recent wave of AI-discovered vulnerabilities is a problem, Rob Bair of Anthropic has a reframe for you.

  • AI Security Brief Episode 5 with guest Valentina Palmiotti

    Episode 5 · 18 июн. 2026 г.

    Can agentic AI really find zero-days? Ask the hacker who won Pwn2Own Berlin 2026

    At Pwn2Own Berlin 2026, a security researcher used agentic AI to help her win. The AI surfaced real, verified bugs, then wrongly called her winning bug “not unexploitable in practice.”

  • AI Security Brief Episode 4 with guest Dr. Grace Trinidad

    Episode 4 · 4 июн. 2026 г.

    Is your enterprise AI strategy delivering ROI yet?

    Your enterprise AI strategy isn’t as far along as you think. The reality for most organizations today is that AI is disrupting existing processes more than it’s delivering outcomes… so far.