The Financial Stability Board (FSB) has identified the impact of frontier AI on cyberattacks as the most immediate AI-related concern for the global financial system.
FSB Chair and Bank of England Governor Andrew Bailey warned G20 finance ministers and central bank governors that advanced AI could materially change the speed, scale and economics of cyberattacks, including by accelerating attackers’ ability to discover vulnerabilities.
The FSB also warned that many countries do not yet have adequate frameworks for managing the deployment of advanced AI models. In the financial sector, growing reliance on a small number of powerful technology providers could create concentrated risk and potentially undermine market confidence if those providers are disrupted.
Bailey called for a coordinated global approach to safe model deployment, along with stronger response and recovery capabilities across financial institutions and their critical third-party providers.
John Strand, Owner, Black Hills Information Security, Inc.:
“The problem with focusing on frontier AI is that attackers don’t need frontier AI to successfully break into financial institutions. A lot of the open-weight models available today can already help identify vulnerabilities, develop exploits, and automate attacks. They may be slower and less efficient, but in the right hands they can be every bit as deadly. We cannot solve this problem by focusing exclusively on the most advanced models. Financial institutions need an all-hands-on-deck effort to find and eliminate vulnerabilities, particularly in third-party software, before attackers get there first.”
Noelle Murata, Sr. Security Engineer, Xcape, Inc.:
“AI-accelerated vulnerability discovery and exploit scaling transform systemic market concentration into an immediate operational threat for global financial institutions. Cybersecurity practitioners have long warned that automated tooling drastically compresses the window from vulnerability disclosure to active exploitation, making the Financial Stability Board warning to G20 leaders a necessary wake-up call outside the technology sector. The current wave of optimism and heavy investment in frontier models echoes the dot-com bubble of the late 1990s, where speculative technology spending added fragility to an already volatile market. Concentration risk paired with borrowed capital means a minor AI stumble or containment failure can rapidly turn into a systemic market event. The operational burden now shifts to financial firms to prove their recovery workflows and third-party dependencies hold up at machine speed. Although the foundational AI adoption blueprints issued by international watchdogs remain non-binding today, they establish the exact regulatory template supervisors will grade institutions against tomorrow.
“To maintain operational resilience, security executives must audit vendor dependencies, enforce real-time integration monitoring, and validate recovery controls before automated threat campaigns disrupt core financial infrastructure.
“Critical Takeaways
- Global watchdog warnings elevate AI risk from routine security patching to systemic financial stability threats.
- Market concentration combined with speculative technology investment increases susceptibility to cascading outages from machine-speed exploits.
- Non-binding regulatory blueprints are setting the baseline standards that financial supervisors will use to audit vendor resilience and recovery speeds tomorrow.
“Building financial security on unproven technology models means betting global market stability on pure optimism.”
Ryan McCurdy, VP of Marketing, Liquibase:
“The biggest change AI introduces isn’t necessarily a new kind of cyberattack. It’s speed. Attackers can find vulnerabilities and exploit them faster, which gives financial institutions less time to respond.
“You can’t solve that by adding more people and manual controls. Financial institutions need to know what changed, whether it was authorized, and whether it meets policy before that change reaches a critical system. And when something does get through, they need the visibility to understand what happened and recover quickly.
“AI is forcing security and governance to operate at machine speed. The institutions that figure that out will be much more resilient than the ones still relying on humans to keep up.”
The key benefit to AI is speed. As in they can do attacks quickly and faster than most humans can. You therefore need to make sure that you can deal with AI at speed. Or you are guaranteed to be on the wrong end of things.
McKesson confirms data breach after ShinyHunters claims it stole 284M records
Posted in Commentary with tags Hacked on August 31, 2026 by itnerdPharmaceutical and healthcare technology giant McKesson confirmed it is experiencing intermittent service disruptions following a cyberattack involving a third-party application.
The company confirmed that attackers gained unauthorized access and exfiltrated data associated with customers in its oncology and surgical business units, although customers can continue using its systems and services. McKesson said it has received reasonable assurance that the attackers are no longer inside its systems.
The potential impact is significant given McKesson’s role in the healthcare supply chain: the company delivers approximately one-third of all prescriptions in North America and distributes pharmaceuticals, oncology drugs, medical-surgical supplies and laboratory equipment.
The ShinyHunters cybercrime group has claimed responsibility and threaten
Phil Wylie, Senior Consultant & Evangelist, Suzu Labs:
“The McKesson incident is another reminder that an organization’s attack surface extends well beyond the systems it directly controls. Third-party applications with access to sensitive data can provide attackers with a path around otherwise mature security controls.
“The potential impact is especially concerning in healthcare. When an organization sits at the center of the pharmaceutical and medical supply chain, a cyberattack is no longer just a data-security issue. Disruption can potentially ripple downstream to providers, pharmacies and ultimately patients.
“Organizations need to treat third-party access with the same scrutiny as internal access. That means limiting privileges, segmenting critical systems, continuously monitoring vendor connections and having an incident response plan that assumes a trusted third party could eventually be compromised.
“The reported 284 million records is a claim from the attackers and should be treated as unverified until McKesson confirms the scope. Regardless of the final number, this incident demonstrates why third-party risk has become one of the most important challenges in defending complex healthcare environments.”
John Strand, Owner, Black Hills Information Security, Inc.:
“This particular story highlights a major problem that I don’t think enough people spend time thinking about. Complexity is the enemy of computer security.
“The more third-party vendors you integrate with, especially SaaS providers, the larger your attack surface becomes. Every integration, API, application, and vendor relationship creates another potential path into your organization.
“I also don’t think enough is being done around supply chain security. Organizations should be asking harder questions of their SaaS providers, getting letters of attestation, understanding how these services are secured, and identifying exactly what access those vendors have to their environments.
“AI is going to make this problem even bigger.
“We’re seeing an explosion of custom-written SaaS applications because AI has dramatically lowered the barrier to building software. That’s fantastic in a lot of ways, but it also means we’re creating more applications, more integrations, more APIs, and ultimately more complexity at an incredible rate.
“We’re going to continue seeing vulnerabilities and compromises that originate with third parties. Attackers don’t necessarily need to attack you directly when they can attack something you trust.
“Once again, complexity is one of the easiest ways in.”
Damon Small, Board of Directors, Xcape, Inc.:
“When a third-party application breach hits a healthcare supply chain giant like McKesson, a single vendor integration can escalate into a national patient data crisis. The claim that 284 million records were exfiltrated is alarming, even if core delivery operations remain online. McKesson responded quickly by notifying the Securities and Exchange Commission and engaging external incident response specialists to contain the breach. However, given the company’s central role in drug and supply distribution across North America, organizations supporting critical infrastructure must apply far more rigorous scrutiny to the third-party software partners plugged into their environments. Security teams must enforce least-privilege access, continuously monitor data egress at vendor integration points, and audit partner security controls before a secondary application becomes a primary breach vector.
“Critical Takeaways
“When you deliver one-third of a continent’s medicine, your third-party vendors are no longer optional software; they are critical infrastructure.”
ShinyHunters have been busy. They pwned this company last week. That should tell you all you need to know about ShinyHunters, and what you need to do to defend against them.
UPDATE:ShinyHunters vished their way into a McKesson employee’s Okta credentials, then rode that single SSO account into Salesforce and Snowflake, pulling roughly a terabyte of data including Social Security numbers, medical records, and cause-of-death details, with a $55.2 million ransom demand and a 72-hour deadline attached.
iCOUNTER’s, Director of Counter Fraud Operations, Jason Brown said this:
“This is textbook third-party blast radius. The actual failure point wasn’t McKesson’s own perimeter, it was multiple employee SSO accounts, according to the attackers, that opened access to Salesforce and Snowflake, and that’s the exact chain most vendor risk questionnaires still don’t ask about, they check whether a vendor encrypts data at rest, not whether a single compromised identity can walk straight into critical SaaS platforms with no additional friction. From a fraud operations standpoint, the interesting clock now isn’t the breach, it’s the 72-hour deadline ShinyHunters set before publishing the stolen data, and once it’s published, the monetization happens fast because health data with Social Security numbers and diagnosis codes is high-value fuel for identity, medical, and synthetic identity fraud.”
Leave a comment »