Community Bank Cybersecurity from A to Z


From AI-driven fraud to vendor risk management, here are the cybersecurity challenges community banks face—and the defenses that work.

October 01, 2026 / By Anna Burgess Yang

Illustration by Ahoy There!

Cybersecurity threats move at machine speed, faster than any human can manage. The tools to stop them are evolving at an equal pace. Here are just some of the threats community banks are facing right now, along with solutions to detect and address attacks from bad actors.

Artificial intelligence

Type: Threat and solution

AI sits on both sides of cybersecurity: threat and solution.

On the threat side, the newest AI frontier models can create unprecedented cybersecurity risks and attacks. While many are not yet publicly available in the U.S., cheaper, open-source versions of those capabilities can trail the frontier models by anywhere from three to seven months. Community banks won’t be the first target, but they’ll get pulled in through their vendors (think CrowdStrike).

On the solution side, vendors are ramping up AI capabilities inside their cybersecurity offerings: round-the-clock scanning, vulnerability identification and triaging findings into a roadmap for banks to follow, with a human still in the loop.

“At the end of the day, community banks are critical infrastructure to America,” says Anjelica Dortch, vice president of operational risk and cybersecurity policy at ICBA. “So, we have to make sure we’re taking the necessary steps to stay resilient and leverage these new AI capabilities and cyber tools to help and arm our defenders.”

Two questions that should be on the minds of every bank leadership team: What AI tools can best protect the bank against the threat of AI cyber attacks, and what are you doing to upskill the employees who will operate them?

.bank domain

Type: Solution

With the proliferation of scammers, community banks have to convince customers that a message actually came from the bank. The .bank domain settles that question both on the web and via email.

With today’s AI capabilities, a fraudster could use a large language model (LLM) to spin up a website that looks nearly identical to a bank’s website and use it to siphon information. But registration of a .bank domain is restricted to verified financial institutions, so a fraudster can’t create a lookalike the way they can with a .com.

Though it should be a preventative measure, the .bank domain registry operator fTLD reports that many banks make the move after an incident, rather than before one. Visit register.bank to learn more.

Credential delegation

Type: Threat

Some bank customers have started handing their banking credentials to AI agents and letting agents transact on their behalf. From the customer’s side, it’s convenience. From the bank’s side, it’s accessing customers’ sensitive banking information and potentially putting the customer at risk for identity theft or financial loss.

Pending legislation would require agent providers to disclose they hold a customer credential and give the customer a way to revoke it. Until that settles, the exposure continues to grow: ChatGPT, for example, already asks subscribers whether they’d like to connect their banking information.

A reasonable working assumption for any community bank is that dozens of AI agents are moving through its systems at any moment.

Deepfakes

Type: Threat

Fraud has moved beyond email phishing schemes and now uses synthetic audio and video to gain access to a customer’s bank account. The mechanics of vishing (voice phishing) are unnerving: a customer answers a call, and the recording of their own voice becomes raw material. Voice cloning only needs three to five seconds of usable audio.

Deepfakes are a growing threat, and most people cannot detect them. Deloitte’s Center for Financial Services projects $40 billion in U.S. losses from AI‑enabled fraud by 2027.

Executive impersonation

Type: Threat

Community bankers pride themselves on knowing their customers. This puts bankers at risk for impersonation by attackers that trade on both trust and authority.

Executive impersonation carries risks for both the bank and its customers. The cloned voice of a bank president can be enough to get a wire approved. A phishing email “from” an executive encourages customers to click a link and sign up for a new product. The visibility of bank executives effectively hands an attacker the source material—and puts the bank’s reputation at risk.

Fourth- and fifth-party risk

Type: Threat

Banks are used to monitoring third-party vendor risk, but what about fourth- and fifth-party vendors? These are the vendors and subcontractors your vendors use. Almost no bank has visibility that far down the chain, and almost no vendor questionnaire asks the right questions to assess risk.

Verizon’s 2025 Data Breach Investigations Report found that third-party vendors were involved in 30% of breaches, which is double the prior year. Every layer beneath that third party carries the same risk. Community banks should assess their due diligence processes to see how they can be improved.

Help is at Hand

ICBA’s Community Banker AI Security Readiness Guide offers information and tactics that can help guard against threats—and it’s the most-downloaded guide ICBA has ever produced. Download it now.

Guardrails for AI

Type: Solution

Whether a community bank is addressing credential delegation from its customers or its employees’ use of AI, it must have guardrails in place.

On the customer side, once an online banking session is identified as an agent rather than a person, the bank should control what the agent is allowed to do, and an explicit policy sets up guardrails to protect your customers.

Internally, the same principles apply to employees. An acceptable-use AI policy should specify which AI tools are approved, what bank or customer information can (or can’t) be entered into them, and who reviews any output the tools produce. Without a policy in writing, employees will make those calls individually.

Harvest now, decrypt later

Type: Threat

Attackers are stealing encrypted data today with no ability to read it, but they expect that quantum computers will eventually open it for them in the future. To them, encrypted data is worth taking now.

The National Institute of Standards and Technology (NIST) in 2024 finalized its post-quantum cryptography standards, which are designed to withstand a cyber attack from a quantum computer. While the current risk is low, it’s something community banks (or their vendors) will need to address in the future as the risk materializes.

ICBA Education IT Institute

Type: Solution

At some community banks, technology responsibility sits with a small group of people who are often responsible for IT security, business continuity, managing vendors and identifying potential solutions.

ICBA’s IT Institute curriculum covers cybersecurity tactics, asset management, IT budgeting and systems selection, and emerging trends. Key employees will learn how to better safeguard both the bank and its customers. Learn more and register.

Jackpotting

Type: Threat

Jackpotting attacks use malware to make an ATM dispense its entire cash load with no authorization from the bank.

More than 700 attacks were recorded in 2025, with more than $20 million in losses. Many of the vulnerable machines run outdated versions of Windows that no longer receive security patches. Community banks should contact their ATM provider to learn what safeguards are in place—especially as AI starts to be integrated into ATM systems.

Keyloggers and infostealers

Type: Threat

30%

of 2025 breaches involved third-party vendors—double the previous year.

Source: Verizon

A keylogger records every keystroke on an infected machine, capturing passwords and account numbers as an employee types them in. Infostealers can pull saved passwords out of browsers and grab data straight from web forms. They can also capture an active web session and resume it without triggering multifactor authentication. While email phishing remains the top method of gaining access to systems, credential theft is the top attack enabler, according to Deepstrike. Infostealers contributed to the theft of more than 1.8 billion credentials in 2025.

Legacy software

Type: Threat

Aging systems and unpatched workstations are well-documented cybersecurity risks for community banks. Too often, patches are deferred until “the next update” because IT teams struggle to keep up. The fixes exist, but it’s critical for banks to install them promptly.

Community banks should also assess whether their existing products are even capable of meeting current security expectations. A fully patched system that can't support modern authentication or logging is still a weakness.

Multifactor authentication

Type: Solution

Two-factor authentication asks for a password plus one more piece of proof. Multifactor authentication (MFA) is the broader term, covering any combination of something you know (a password), something you have (a device) or something you are (biometrics).

Not all factors are equal. An authentication code sent by text is the weakest common form, because attackers can hijack the phone number itself. An authenticator app that generates a rotating code is stronger, though a customer can still be tricked into entering that code on a fraudulent site.

The strongest options are hardware security keys and biometrics that unlock credentials stored on a customer's or employee’s device, which won’t respond to a fraudulent site at all.

NIST Cybersecurity Framework 2.0

Type: Solution

The Federal Financial Institutions Examination Council’s Cybersecurity Assessment Tool gave community banks a standard way to measure their cyber risk. With the official sunset of that tool, many banks have adopted the National Institute of Standards and Technology’s Cybersecurity Framework (CSF) 2.0 in its place. It covers six functions: govern, identify, protect, detect, respond and recover. Examiners want to see board oversight, a documented risk assessment and supply chain risk management. Most institutions that selected CSF 2.0 haven’t finished the transition. Being mid-migration is defensible, but having no documented plan is harder to explain.

Operational resilience

Type: Solution

No cybersecurity program can eliminate every threat. The most important structures to have in place are the ones that let a community bank detect an incident, respond to it and recover—all while continuing to serve its customers. That means it’s tested its incident response and business continuity plans.

Resilience also extends to external factors the bank doesn’t control. If the electric grid goes down, is there a generator? If connectivity drops, is there satellite backup? Those questions may sound out of the realm of possibility, until they aren’t.

Passkeys

Type: Solution

A passkey replaces the password with a pair of cryptographic keys: one private, one public. The private key stays on the customer’s phone or laptop, protected by a fingerprint, face scan or device PIN. The bank stores the public half.

That eliminates two problems at once. There’s no password database for an attacker to steal, and there’s nothing for a customer to type into a fraudulent login page, because the passkey only responds to the bank’s real domain.

Note: A passkey replaces the “something you know” (a password) in MFA.

Quishing

Type: Threat

Quishing hides a malicious web address inside a QR code. Because the destination is an image rather than text, email security filters that would catch a suspicious link often let the message through.

Many banks have expanded their use of QR codes across marketing materials and branch signage, which trains customers to scan codes from an institution they trust. A sticker placed over a legitimate code on a flyer gives an attacker an easy way to redirect a customer.

Ransomware

Type: Threat

Ransomware attacks a bank’s systems and holds them hostage until the bank pays a ransom. Double extortion is now standard, where attackers also threaten to publish the stolen data, so clean backups alone no longer resolve the incident.

Ransomware-as-a-service has made this an even bigger problem. Criminals with no technical ability rent the tooling and support from operators who take a cut of the proceeds. The U.S. Treasury Department reported more than $700 million in ransomware payments in 2024.

Shadow AI

Type: Threat

Shadow AI runs in two directions. First, vendors switch on AI capabilities inside products a bank already uses, or vendors are using AI in their own operations in ways that access a bank’s data. Second, employees bring their own AI tools to work and enter bank data (sensitive or otherwise).

Community banks should start with the vendors their daily operations depend on and ask directly: Will you notify us when you activate new AI capabilities? What are the models doing with our data? Does that fall within our existing contract?

On the employee side, an acceptable-use policy only works if the bank enforces it. The bank needs to block access to unapproved AI tools on bank devices and networks. If a vendor has incorporated AI capabilities that the bank hasn’t assessed, they should be disabled so employees can’t access them.

Training and tabletop exercises

Type: Solution

Human behavior remains the biggest vulnerability at any bank. The most successful cyber incidents involve human error somewhere in the chain.

Training is not one-and-done. The material must be ongoing, current and something staff is tested on consistently. Training modules employees simply click through don’t change behavior.

ICBA partners with the Treasury Department’s Office of Cybersecurity and Critical Infrastructure Protection to give banks a structured way to test incident response playbooks through “tabletop exercises.” For example: a help desk employee clicks an email, hands over credentials and the bank is under attack. The exercise tests the bank’s response. Learn more.

User and entity behavior analytics

Type: Solution

20.4%

Increase in the number of CVEs (software security flaws) published in 2025 over the previous year.

Source: cve.org

User and entity behavior analytics (UEBA) establishes what normal activity looks like for each employee and system, then flags anything unusual. If a teller typically views 30 customer records a day and suddenly views 300, it’s outside of normal behavior.

That's how insider threats and compromised accounts come to light. The activity looks legitimate if a bank is only considering whether the login credentials are valid. When it adds a layer that compares the currently logged-in session with normal activity, it can identify a potential attack.

Vulnerability management

Type: Solution

A CVE, or common vulnerabilities and exposures entry, is a publicly disclosed security flaw in a piece of software. It’s assigned an identifier, so vendors and defenders are referring to the same problem. More than 48,000 were published in 2025, a 20.4% increase over the prior year.

No community bank is reading through the entire list of published vulnerabilities. Tools that provide continuous scanning against your technology stack are what make the volume manageable, because they tell you which of those flaws actually touches your systems.

Wearables

Type: Threat

Physical devices have become a security problem. Someone wearing AI smart glasses in a bank lobby can record continuously, then use the footage to study employees and lobby cameras. The audio side is even worse. A customer reading an account number aloud at the teller window has identified themselves to anyone recording nearby.

Branches are private property, and a community bank has every right to prohibit recording inside them. The practical steps are a conversation with employees about not wearing these devices at work and signage that lets customers know to turn recording off out of respect for other customers' privacy. Don’t rely on indicator lights on recording devices, since they can be tampered with.

X-factor: The human element

Type: Threat

A community bank can have well-thought-out security measures and expensive cybersecurity defenses, and one employee clicking one link can let an attacker access its systems.

The controls matter, but so does designing around the assumption that someone will make a mistake. A bank can scope permissions within software, so a single compromised account can’t reach everything. It can also create a culture where employees aren’t punished for a mistake, so they report issues immediately. Both of these limit the damage of a cyber attack.

Year-round due diligence

Type: Solution

Annual vendor review no longer matches the pace of change. A vendor might accurately respond to your January assessment and then have activated new AI capabilities by March.

Ongoing diligence is becoming the expectation, with more frequent diligence needed for the vendors a bank’s daily operations depend on. The cadence should follow how critical the vendor is, rather than applying additional due diligence evenly across hundreds of vendors.

Zero trust architecture

Type: Solution

Older security models worked like a locked building. Once someone was inside, they could move freely. Zero trust assumes the opposite, checking every request for access no matter who is making it or where they are.

For a community bank, that means logging in once in the morning doesn't give an employee unquestioned access for the rest of the day. Sensitive requests trigger another check, often happening in the background. These checks look at device health, location or how unusual the request looks. Most serious attacks depend on trust granted once and never questioned again. Zero trust removes that assumption.


Join ICBA Community

Interested in discussing this and other topics? Network with and learn from your peers with the app designed for community bankers. 

Join the community Example Text