top of page

Deepfake Fraud, Ransomware Comebacks and DORA With Teeth: Finance's Cybersecurity Reckoning Arrives

6 hours ago
5 min read
Deepfake Fraud, Ransomware Comebacks and DORA With Teeth: Finance's Cybersecurity Reckoning Arrives

As of this week, September 2026, banks are living through a security stress test they cannot outsource. Deepfake-as-a-service is cheaper than a Netflix subscription, DORA's grace period is over, and the EU digital identity wallet is landing on citizens' phones. Here is what the week actually tells us.

The week the theoretical threats stopped being theoretical


Cybersecurity in financial services has always had a rhetorical problem. The threats sound cinematic, the controls sound tedious, and boards sit through slide after slide of maturity curves and mean time to detect. That gap between drama and diligence has finally closed. In the last seven days, ransomware crews have returned to Deutsche Bank's supply chain, a small US software vendor called Marquis has confirmed a breach affecting 672,000 people, and the EU Digital Identity Wallet has hit a critical rollout milestone under eIDAS 2.0. Meanwhile, the Digital Operational Resilience Act is now in what practitioners call its active enforcement phase, with supervisors moving from readiness checks to real consequences.


If 2025 was the year banks were told to get ready, 2026 is the year they are being tested on it.


Deepfakes finally rewrite the fraud playbook


The most fundamental shift of the year is that deepfake fraud has moved from proof-of-concept to product. Recent analysis from Fourthline and CybelAngel converges on a bleak conclusion: deepfakes are now embedded in most high-impact fraud scenarios in banking, from onboarding and account takeover to payment authorisation and internal executive scams.


The old CEO email scam has been retired. Its replacement is a real-time video injection attack, where a finance officer receives what looks like a genuine video call from their CFO, correct voice, correct mannerisms, correct office background, instructing an urgent wire transfer. Reality Defender and IronVest have both documented attackers using virtual camera software to inject synthetic video streams directly into banking apps, bypassing liveness detection that was considered state of the art eighteen months ago.


The economics have flipped in the attackers' favour. Cyble's most recent research finds that deepfake-as-a-service subscriptions can be purchased for as little as 50 US dollars a month, and fraud operations increasingly resemble software companies, with customer support, tiered pricing and update cadences. Security Briefing calls this industrialisation of fraud the defining feature of the 2026 threat landscape, and it is hard to argue with the numbers.


The KYC vendor breach that made every CISO sweat


Concentration risk is no longer a slide in a slide deck. According to reporting from Cantina, the financial sector spent much of 2026 processing the fallout from a 160-million-identity theft at an identity verification vendor, alongside a 40 per cent surge in injection attacks. When a single KYC supplier holds the front door to hundreds of banks and fintechs, one breach becomes everyone's incident.


That is precisely why regulators shifted from a policy of encouragement to one of accountability. Under DORA, banks are now legally on the hook for the security posture of their critical ICT providers, not just their own perimeter. The consequence, per Cantina and confirmed by consolidation activity across the KYC and identity verification market this year, has been a sharp thinning of the vendor bench.


DORA in enforcement mode: less patience, more paperwork


The Digital Operational Resilience Act has been fully applicable since 17 January 2025, but 2026 is the year the tone changed. According to Enactia and the specialist regulation-dora.eu tracker, the informal tolerance period that characterised 2025 supervision is finished. National competent authorities are now conducting active reviews, cross-checking Register of Information data automatically, and issuing the first compulsion payments.


Fines vary by jurisdiction because DORA sets no EU-wide maximum. Article 50 obliges Member States to arm their competent authorities with penalty and remediation powers and leaves the numbers to national law. Italy's ceilings run up to 20 million euros or 10 per cent of annual turnover. Ireland allows up to 10 million euros or 10 per cent. Germany and the Netherlands distinguish between intentional and negligent breaches. Article 52 goes further still, allowing Member States to impose criminal penalties for severe violations, including imprisonment in extreme cases.


For any board that treated DORA as a documentation exercise in 2025, the 2026 message is straightforward: the auditors are back, the register is machine-read, and the excuses have expired.


Ransomware's boring, expensive return


While attention has drifted to AI-native fraud, the classic ransomware playbook has quietly reasserted itself. Sophos data cited across the industry shows that two thirds of financial services organisations were hit by ransomware in the most recent measurement period. Black Kite's 2026 State of Financial Services Report describes a two-front threat: a ransomware surge combined with a vulnerability deluge that keeps IT teams reactive rather than strategic.


The recent Deutsche Bank supply chain incident is a case in point. Cybernews reports that a ransomware crew has claimed access to internal Deutsche Bank systems via a third-party breach, posting what appear to be employee database records as proof on a leak site. Whether the material proves out or not, the reputational and regulatory clock has already started.


On the mid-market end, Marquis Software confirmed via a Fox News report that a ransomware attack has exposed personal and financial data, including Social Security numbers and bank account details, for 672,075 people. The average cost of a data breach in the financial sector hit 5.56 million US dollars in 2025, second only to healthcare, according to the IBM Cost of a Data Breach Report cited by DeepStrike. Q1 2026 incident volumes are up 76 per cent year-on-year, per DeepStrike, and no serious analyst expects that curve to bend by year-end.


eIDAS 2.0: identity infrastructure finally shipping


The good news, if there is any, comes from the EU Digital Identity Wallet. Under eIDAS 2.0, every EU Member State is now under a hard obligation to provide at least one wallet to citizens by December 2026, with September serving as a critical acceptance milestone for trusted service providers. Utimaco, Signaturit and the EUDI Wallet Hub all report that Italy, France and Finland are leading the rollout.


The design principle worth watching is selective disclosure. The wallet lets a user prove an attribute, over 18, resident of Belgium, licensed advisor, without handing over the underlying document. In a world where identity verification vendors are being breached at scale and deepfakes are cheaper than lunch, cryptographically attested attributes issued by governments start to look less like European bureaucracy and more like the missing primitive banks have wanted for a decade.


Financial institutions integrating the EUDI Wallet into onboarding, strong customer authentication and payment authorisation flows will find themselves less exposed to the KYC-vendor concentration risk that dominated this year's incident reports. Those that do not will find themselves explaining, next audit cycle, why they chose the more brittle path.


What the week actually tells us


The pattern across this week's news is not a series of unrelated incidents. It is a single, coherent shift. Attack tooling has industrialised. Vendor concentration has become the primary systemic risk in cyber. Regulators have shifted from patience to enforcement. And identity, the primitive on which every payment, onboarding and authorisation rests, is being rebuilt in public.


Banks that treat 2026 as a year to hold the line will be outrun by both the attackers and the auditors. The institutions that come out of the next twelve months in better shape are the ones already doing three unglamorous things: consolidating and interrogating their critical vendors, integrating deepfake-resistant liveness and injection-detection into onboarding and authorisation, and building serious plans to accept EUDI Wallet attestations at scale.

The cinematic threats have arrived. The tedious controls, at last, are the only story that matters.

 
 
bottom of page