The financial sector is facing a fundamental threat from AI models that can find weaknesses in firms’ cyber defences faster than they can be patched, says Moody’s Ratings.
In a new report, the rating agency said that, in 2025, the median time for banks to fix software flaws was 69 days, whereas attackers were exploiting weaknesses, on average, within 44 days.
And, the growing gap between the capability of powerful AI models, such as Anthropic’s Mythos, to discover cybersecurity holes and timelines for firms to remediate those weaknesses, “is creating structural credit risks for banks, not incidental ones,” Moody’s said.
For instance, on its initial, restricted release, the Mythos model uncovered thousands of undetected flaws in every major operating system and web browser, it said, “marking a step change in the cyberthreat landscape.”
Financial firms, including banks, are prime targets for cyberattacks, given their central economic role, the assets they control, and the data they hold, the report noted — attacks that can have significant financial and reputational consequences for firms.
“[A] severe ransomware attack that disrupts services for an extended period could quickly become a threat to creditworthiness, potentially eroding confidence and liquidity,” it said.
Additionally, these costs cold be even greater in the current environment, the report suggested.
“With Mythos, the magnitude and sophistication of attacks are likely to increase, which could increase the total cost,” it said.
Therefore, as the threat landscape shifts due to the release of increasingly powerful AI models, firms in the financial sector will come under growing pressure to bolster their capability to defend against these attacks — and to speed up their cyber incident reaction times, it said.
“Legacy architecture is the primary weakness,” the report said. “Outdated internal systems where software has not been patched for years are the most vulnerable to exploitation by cyber attackers.”
And, while larger firms are bigger targets for potential attackers, smaller firms are more vulnerable as they have fewer resources for cyber defences, it noted.
So, as financial firms need to spend more to effectively defend themselves, the impact on profits will likely be larger for small firms, and smaller for large ones.
On the upside, industry firms can also use leading AI models to more quickly identify their own vulnerabilities — although they don’t provide quick solutions for fixing these weaknesses, which leaves firms “to manage the complexity and execution risk of implementing fixes without disrupting interconnected IT systems.”
“Patching should become more frequent and internal systems should operate on a zero-trust model to limit attackers’ movements through the organization in the case of a breach,” the report said.