Article

Claude Mythos and co.: New Cyber Risks for Financial Institutions

Fact sheet as a result of the webinar of Bank-Verlag in cooperation with the Association of German Banks and the Bankenakademie

André Nash
André Nash
Profilbild Oliver Seidel
Oliver Seidel

The webinar highlighted a range of perspectives, including the supervisory viewpoint, assessments from the national cybersecurity authority and practical insights from several financial institutions.

The situation from Bafin’s perspective

Key message: Cyber risks remain a key focus for supervisors due to the high threat level and the potential for cyber incidents to spread quickly beyond individual institutions, affecting both the wider financial system and the broader economy. Digital innovation is seen as essential to maintaining a functional, competitive and resilient financial system. At the same time, increasing utilisation of digital technologies is expanding the cyber risk landscape.

This applies equally to the opportunities and risks associated with new frontier AI models. From a supervisory perspective, full implementation of DORA and strong cyber hygiene provide a solid foundation for addressing the current challenges. However, additional measures are required. Financial institutions must be prepared to assess and remediate a growing number of new vulnerabilities within short timeframes, or to mitigate them using appropriate measures. A risk-based approach is vital, with priority given to protecting critical systems. Organisations must also develop strategies for legacy systems that can no longer be patched. In doing so, they need to consider not only risks within their own environments but also those affecting ICT third-party service providers.

Key drivers: Complex IT environments, geopolitical conflicts and concentrations and dependencies are key factors contributing to the elevated risk landscape. The growing use of AI is creating new risks.
Particular attention is currently focused on powerful frontier AI models such as Claude Mythos 5, GPT‑5.5 and MDASH. These models are expected to be capable of identifying and exploiting previously unknown vulnerabilities in ICT systems within a short period of time. As the provision of these models is concentrated among a small number of providers, this development could further increase dependencies on individual providers in third countries. The conditions governing access, data protection and legal requirements are currently evolving on an almost daily basis.

Further Reading: The importance of information sharing, discussion and the exchange of practical experience and best practices was highlighted throughout the webinar. Nikolas Speer’s full keynote is available here .

Factsheet Bank-Verlag englisch

PDF

Contact

André Nash

André Nash

Head of Banking Technology and Security

Contact

Profilbild Oliver Seidel

Oliver Seidel

Banking Supervision and Accounting

This might also interest you:

Cybersicherheit
Article

Cybersecurity Glossary

Many internet users have been victims of online fraud. But what different types of fraud are there and how can you protect yourself online?

AI prompt
Article

Prompt Injection: how cybercriminals manipulate AI responses

Have you experienced an AI suddenly recommending a fake website or asking you to enter personal information? A technique known as prompt injection could be behind it. This article explains how you can protect yourself from such attacks.

Junger Mann arbeitet am Laptop
Article

How to protect yourself from call and fixed term deposit scams

Be careful when searching for call and fixed term deposits with good conditions. Scammers commonly advertise seemingly excellent interest rates on websites that look very convincing. This article explains how to recognise fraudulent offers and protect yourself from scams.