Learning Objectives:
-
Understand the severity and increasing frequency of cyber threats targeting the financial sector.
-
Identify the unique vulnerabilities of central banks compared to commercial financial institutions.
-
Analyse the impact of digitalisation on expanding the cyber attack surface for central banks.
-
Recognise the strategic shift from cyber attacks as isolated IT incidents to systemic financial stability risks.
1.1 The Escalating Cyber Threat Environment
The cyber threat landscape facing financial institutions and central banks has intensified dramatically over the past decade. A comprehensive study of 84 disclosed cyber attacks on 63 central banks between 2010 and 2025 has empirically verified that cyber risk, alongside climate risk, is currently one of the main challenges for central banks . The frequency of attacks is escalating, with the financial system facing a 29% increase in cyber incidents deemed “relevant” in 2025 compared to the previous year, according to data from one major central bank .
The threat landscape affecting financial institutions is now shaped by multiple converging factors, including AI-enabled attacks, rapid vulnerability exploitation, software supply-chain compromise, identity-centric intrusions, and deepfake-driven fraud . These threats are not theoretical; they are already impacting financial entities, ICT third-party providers, and public-sector infrastructures that the sector relies on. Regulators have emphasised that cyber threats now intersect with operational resilience, third-party concentration, customer protection, and financial-stability considerations, elevating cyber risk to a board-level strategic issue rather than just a technical concern .
The shift is illustrated by changing patterns in incident types. Until recently, the most common type of cyber incident in the financial system involved technology failures, such as service outages affecting customers. However, with the increase in cases, incidents classified as fraud—which include cyberattacks—have become the majority . In 2025, fraud-related incidents outnumbered IT failures by 39 to 27, a significant reversal from the previous year when only nine cases were classified as fraud . This pattern underscores the growing sophistication and prevalence of malicious cyber activity targeting financial infrastructure.
1.2 Unique Vulnerabilities of Central Banks
Central banks face a distinct set of vulnerabilities compared to commercial banks. Their unique position at the heart of the financial system makes them both high-value targets and high-impact vectors for systemic disruption . The academic literature has identified a significant gap in understanding the full impact of cyber attacks on central banks, with existing research primarily focusing on commercial banks and other financial entities .
Several factors contribute to the heightened vulnerability of central banks:
Critical Infrastructure Status: Central banks operate payment and settlement systems that are critical to national and international financial stability. A successful attack on these systems could disrupt the entire financial ecosystem, causing cascading failures across the economy. The Malaysian central bank’s foiled cyber heist in 2016, which involved fraudulent SWIFT transfer requests, demonstrated that even well-protected central banks are targets for sophisticated attacks .
Systemic Interconnectedness: Central banks are deeply interconnected with commercial banks, financial market infrastructures, and government institutions. A cyber incident at a central bank can rapidly propagate through these connections, creating systemic risk. The Sri Lanka Central Bank case, where hackers breached the treasury’s email system and diverted $2.5 million in debt repayments, illustrates how vulnerabilities in connected government systems can expose central banks to fraud .
High-Value Transactions: Central banks process enormous volumes of high-value transactions, making them attractive targets for financially motivated attackers. The potential financial gain from a successful attack is substantial, as demonstrated by the 2016 Bangladesh Bank heist, which resulted in the theft of $81 million .
Sensitive Information:Â Central banks possess highly sensitive information, including monetary policy deliberations, financial stability assessments, and confidential communications with financial institutions. State-sponsored actors may target this information for espionage purposes.
1.3 The Expanding Attack Surface
The digital transformation of central banking has significantly expanded the attack surface available to cyber adversaries. The adoption of advanced technologies, while improving efficiency and service delivery, has introduced new vulnerabilities. The ECB has noted that geopolitical threats are increasingly playing out in cyberspace, with state-sponsored cyberattacks targeting state institutions and critical infrastructures .
Key factors expanding the attack surface include:
-
Digital Currencies and Payment Systems:Â The development and implementation of central bank digital currencies (CBDCs) and real-time payment systems create new entry points for attackers.
-
Cloud Migration:Â The move to cloud-based infrastructure introduces third-party dependencies and new security challenges.
-
Remote Work:Â The shift to remote and hybrid work models has increased the exposure of central bank networks to potential breaches.
-
API Integration:Â The growing use of application programming interfaces (APIs) to connect with external systems creates new vectors for attack.
1.4 Cyber Risk as a Financial Stability Concern
Regulators and central banks increasingly recognise that cyber risk is no longer an isolated IT issue but a systemic threat to financial stability. The question is no longer whether an institution will become the target of a cyber attack, but how resilient it is in dealing with the attack . The quality of cyber resilience now lies not just in technology but in the interplay of governance, risk culture, technical protection, response capability, and recovery competence .
The ECB has observed that state-sponsored cyberattacks are playing an increasingly important role in the perpetration of hybrid conflicts, and that such attacks primarily target state institutions and critical infrastructures . A significant number of state-sponsored attacks are seen in some years, and cyberattacks are clearly linked to geopolitical tensions .
The Monetary Authority of Singapore (MAS) has identified both AI-driven cyber threats and quantum computing risks as serious near and medium-term threats to the financial sector, and has established a joint task force with the banking industry to strengthen defences . The MAS managing director has emphasised that frontier AI models can find and exploit system vulnerabilities, significantly compressing the timelines for patching, testing, and remediation . This recognition that cyber risk has become a strategic capability issue, not just a technical concern, represents a fundamental shift in how central banks must approach cybersecurity governance.