In 2016, a cyberattack on the Central Bank of Bangladesh shocked the global financial community. Hackers infiltrated the bank’s internal network and used the SWIFT system to send 35 cross-border money transfer instructions, attempting to move nearly $1 billion. Five of these transactions were executed, with approximately $101 million laundered through casino systems in third countries. Post-incident investigations revealed that the transfer formats, verification procedures, and monitoring mechanisms all complied with existing regulations. The compromised element was the operational environment from which the instructions were sent.

In 2020, a bank officer in the United Arab Emirates received a call from a familiar client. On the other end was a recognizable voice, claiming the company was conducting an urgent acquisition and requesting an immediate transfer of $35 million. Soon after, emails arrived from both the client and their collaborating lawyer, complete with supporting documents and proofs. After verifying the call, emails, and documents, the officer proceeded with the transfer as per standard procedures. Subsequent investigations revealed that a criminal group had used social engineering to obtain email accounts, AI-generated voice replication to mimic the client, and forged documents to reconstruct a convincing decision-making scenario for the bank.

In 2024, Hong Kong reported its first deepfake multi-person video fraud case. A criminal syndicate used deepfake technology to create images of the 'Chief Financial Officer' and several 'colleagues' from a multinational company’s UK headquarters. During a video conference, they instructed financial staff at the Hong Kong branch to make 15 transfers, resulting in losses of approximately HK$200 million.

The following year, Singapore police disclosed a similar case: a financial executive at a multinational company mistook AI-generated images of multiple 'senior executives' for real people during a video conference and transferred about $500,000 as instructed. The funds were later moved to a Hong Kong account, but the bank detected anomalies and immediately reported the incident. Through cooperation between Singapore and Hong Kong police, the full amount was successfully recovered.

In less than a decade, criminal tactics have evolved from network intrusions and tampering with transfer instructions to reconstructing voices, images, and documents. While funds still move through established processes, what has fundamentally changed is the basis upon which financial institutions make their decisions.

Historically, anti-money laundering (AML) systems focused on tracking the flow of funds. Now that voices, images, and documents can all be synthetically generated, what needs to be identified may no longer be just the money itself.

For years, information security and AML have developed separately within financial institutions. IT departments focus on protecting networks, systems, and data, while compliance, AML, and risk management departments rely on customer identities, transaction histories, and risk models to conduct customer due diligence, transaction monitoring, and suspicious activity reporting. Different functions align with different regulations, resulting in siloed management structures.

As financial services become fully digitalized, the boundary between information security and AML is increasingly blurred. AML operations heavily depend on electronic data, automated analysis, and model computations. Meanwhile, information security now extends beyond hardware to safeguarding the quality of data that supports decision-making.

Recent cybersecurity incidents also show new patterns. After successfully infiltrating financial institutions, hackers may not immediately transfer funds. Instead, they often gain account access, adjust authentication settings, modify customer data or transaction records, or remain dormant within internal systems for extended periods. From a procedural standpoint, operations appear normal, but the underlying data has been altered without detection.

Customer identities, beneficial owners, transaction histories, risk ratings, and model analyses are all critical inputs for identifying anomalies. They form the shared data foundation for customer reviews, anomaly detection, risk analysis, and decision-making. If any of these elements are tampered with, subsequent analyses may gradually deviate from reality. Such data distortions may not immediately cause financial losses, but they can accumulate errors in daily operations, rendering compliance procedures ineffective even when fully executed.

With the widespread adoption of generative AI, the barrier to financial crime has lowered further. Deepfake videos, voice synthesis, forged documents, and fake identities no longer require advanced technical skills—publicly available tools can generate them rapidly. Criminals can repeatedly test verification mechanisms, refine content and tactics, and increase the likelihood of passing scrutiny. What is being challenged is not the AML process itself, but the authenticity of the content underpinning each decision.

In response to these changes, international regulatory thinking is evolving. The Financial Stability Board (FSB), Basel Committee on Banking Supervision (BCBS), and Financial Action Task Force (FATF) have recently included cyber resilience, third-party management, operational continuity, and information and communication technology (ICT) risk in their supervisory priorities. While these regulations serve different purposes, their focus is converging: financial institutions now face not only financial risks but also risks stemming from the digital environment.

The European Union passed the Digital Operational Resilience Act (DORA) in 2022. DORA does not treat information security as a technical task for IT departments but requires boards to take governance responsibility for ICT risks, covering incident reporting, resilience testing, third-party service management, and operational resilience. This elevates cybersecurity from a technical function to a board-level responsibility, integrating it into core business governance.

Taiwan’s regulatory direction is following a similar path. The Financial Supervisory Commission (FSC) launched the 'Financial Cybersecurity Action Plan' in 2020, updated to version 2.0 in 2022, and in late 2025 announced the 'Financial Cybersecurity Resilience Development Blueprint.' This outlines 29 measures over four years starting in 2026, covering governance objectives, comprehensive protection, ecosystem-wide defense, and robust resilience, including AI security, post-quantum cryptography, model management, outsourcing, and third-party risk.

As AI is increasingly integrated into financial services, the boundaries between compliance, risk management, and information security are no longer as clear. How models are built, data maintained, and external services managed are no longer isolated departmental tasks. When data quality directly impacts risk assessment, what corporate governance truly needs to integrate is not just information systems, but the governance capabilities of information, risk, and compliance.

Therefore, what financial institutions truly need to strengthen is not adding more controls, but connecting fragmented signals. Abnormal logins, permission changes, customer data modifications, device replacements, and high-risk transactions should not remain isolated in different systems. Instead, through common tagging, unified classification, and cross-departmental reporting, the full context must be reconstructed. Cybersecurity incidents involving customer identities or transaction records should be simultaneously incorporated into AML and fraud prevention analysis. Suspicious transactions accompanied by account anomalies or permission changes should trigger a review for cybersecurity indicators. The goal is not to add more procedures, but to enable departments to analyze and judge based on the same facts.

With the widespread adoption of cloud services, identity verification platforms, and external compliance tools, third-party vendors are now deeply embedded in financial services. Outsourcing can distribute workloads, but responsibility cannot be transferred. When vendors participate in identity verification, model analysis, or transaction monitoring, their cybersecurity standards directly affect the quality of anomaly detection. Therefore, contractual management, incident reporting, audit rights, and data return arrangements must be integrated into overall planning, not limited to IT outsourcing management.

The target of financial crime has also shifted. Previously focused on the flow of funds, criminals now aim to manipulate the content and processes that support decision-making. Competitive advantage may no longer lie in which institution has the most advanced AI model, but in which can detect anomalies early, connect scattered clues, and continuously maintain the integrity of its decision-making basis.

AML systems block abnormal financial flows, while information security protects the ability to identify anomalies. Only when the information underlying decisions is trustworthy can risk management and compliance stand on a solid foundation.

*Author is an adjunct faculty member at a higher education institution

FACT BOX

  • Source: PR Times
  • Category: News