AI Transforms Bank Breaches into 'Hostage Situations,' TrendAI Warns
Cybercrime groups are weaponizing AI to automate attacks, disable defenses, and hold financial institutions in a 'hostage situation,' according to TrendAI's Tom Kellermann.

Financial cybercrime has escalated into a high-speed contest between attackers and defenders, largely due to the pervasive integration of Artificial Intelligence (AI) and Machine Learning (ML) into cybercriminal toolkits. Tom Kellermann, vice president of AI security and threat research at TrendAI Security, highlights that cybercriminals are now adept at automating entire kill chains, actively disrupting incident response efforts, and leveraging compromised AI tools to maintain persistent control within banking environments.
This alarming trend is substantiated by findings from the Modern Bank Heists 2026 report, which indicates that nearly 90% of surveyed CISOs are confronting AI-driven attacks. These attacks manifest in various forms, including the use of deepfakes for social engineering, the creation of sophisticated ghost accounts for fraudulent activities, advanced supply chain compromises, the exploitation of jail-broken AI models to bypass security controls, and the deployment of dynamic command-and-control infrastructure that evades traditional detection methods.
Kellermann emphasizes a critical shift in the nature of bank breaches, stating, "The bank is no longer just being robbed. You're dealing with a hostage situation internal to the bank." Attackers are employing AI-powered tactics to systematically disable endpoint detection systems, erase critical logs that would aid investigators, and deploy destructive payloads designed to prevent defenders from regaining control or removing the malicious presence.
To combat this escalating threat, financial institutions must urgently adopt more robust and autonomous defense mechanisms. Kellermann advocates for the implementation of AI-enabled security information and event management (SIEM) systems, agentic extended detection and response (XDR) solutions, continuous threat hunting operations, automated attack-path mapping to identify and neutralize vulnerabilities proactively, and virtual patching to mitigate exploits in real-time.
Beyond technical defenses, Kellermann stresses the paramount importance of AI governance. Organizations must establish stringent practices for managing their internal AI systems and develop sophisticated methods for detecting malicious prompt injection attacks. These attacks aim to subvert AI agents, turning trusted tools into instruments of destruction or data exfiltration.
In a video interview, Kellermann further elaborated on specific techniques enabling these advanced attacks. He discussed how dynamic command-and-control infrastructure weakens traditional indicator-based detection, and how methods like steganography and the use of sophisticated malware such as Xworm help attackers maintain persistence within compromised networks. These advanced persistent threats are particularly challenging to eradicate.
Kellermann also outlined key strategies for risk reduction, including robust AI governance frameworks, the principle of least privilege to limit the potential damage from compromised accounts or agents, and rigorous input validation for AI systems to prevent manipulation. These measures are crucial for building resilience against the increasingly sophisticated AI-driven threat landscape facing the financial sector.
Kellermann's extensive experience in cybersecurity, including leadership roles at HITRUST, Contrast Security, VMware, and Trend Micro, provides a strong foundation for his insights. His past advisory roles, such as serving on the Commission on Cyber Security for the 44th U.S. president, underscore the gravity and strategic importance of the AI security challenges he addresses.