Cyber Resilience: The New Layer of Financial Supervision

The IMF’s warning on the use of AI in cyberattacks places operational resilience at the center of the prudential agenda

Laura Oliboni · Originally published in JOTA, June 2026 · Portuguese original

On May 7, the International Monetary Fund (IMF) published on its blog a diagnosis that deserves the attention of financial regulators. The IMF presented data showing how artificial intelligence (AI) is drastically reducing the cost and time needed to identify and exploit vulnerabilities in digital systems.

The IMF thus concluded that the cyber risk associated with the use of new financial technologies is increasingly turning into systemic risk. Just five days after the IMF’s publication, the Central Bank of Brazil (BCB) announced the fourth incident of 2026 involving data linked to Pix keys (the identifiers used in Brazil’s instant payment system), this time under the responsibility of CredifitSociedade de Crédito Direto S.A.

The Credifit incident itself was small and contained. Registration data for only 46 Pix keys were exposed: name, Individual Taxpayer Registry number (CPF), account-holding institution, branch, account number and type, and the dates on which each key was created and last updated. The BCB itself noted that no passwords, balances, transaction records or other data protected by banking secrecy were exposed.

The takeaway, therefore, lies less in the significance of the incident itself than in the recurrence of attacks on the digital infrastructure of the financial system: four notices since the beginning of the year,[1] in an arrangement that processes billions of transactions every day and reaches roughly 80% of the population.

In ecosystems of this magnitude, registration data can fuel social engineering, personalized scams and chained fraud. The relevant attack surface is the entire ecosystem of participants, interfaces and providers, not merely the transaction infrastructure that was hit.

The IMF’s warning, in turn, calls for examining the interplay between the financial system, cybersecurity and AI-based technologies through new lenses. Advanced AI models can yield exploitable vulnerabilities at a radically different scale, speed and cost. Attacks that were once handcrafted become simultaneous, correlated and customizable.

When the underlying digital infrastructure is shared (software, cloud services, payment networks), a single failure can cascade across institutions. At that point, the issue moves beyond the realm of information technology and becomes a risk to the stability of the financial system. The potential effects of such attacks (payment disruptions, liquidity constraints, doubts about solvency, loss of confidence, market disruption) are the same as those of a classic financial crisis, even though their origin is different.

The IMF does, however, offer a necessary counterpoint: AI can also be part of the system’s defense, particularly in threat detection, fraud prevention and incident response. Innovation and security are therefore not inherently at odds. What is needed is to treat cyber resilience as a dimension of prudential regulation.

This reading resonates directly with the supervision of Brazil’s National Financial System (SFN), and the BCB’s own figures give the picture substance. At a cyber resilience forum held in April with critical service providers (BC Cyber Resilience Forum 2026 – Critical Providers), the BCB’s Director of Supervision, Ailton de Aquino, stated that cyber risk is “central” and constitutes a risk to financial stability.

The numbers bear out the diagnosis. Critical incident reports submitted to the BCB rose from 20 in 2020 to 76 in 2025, and incidents involving the theft of funds rose from 9 to 36 over the same period. The BCB’s Financial Stability Report (REF) of November 2025 had already identified recurring vectors that call for attention: access management, third-party dependency, attack automation, API design and the co-opting of employees.

As regards, more specifically, the adoption of AI-based tools by SFN participants, the REF survey adds a troubling layer. In a sample of 606 institutions accounting for 96% of SFN assets, 26.7% were already using AI models in their IT solutions, a share that reaches 100% among banks in prudential segments S1 and S2 (the two largest tiers).

More than half of these institutions, however, had no supplementary procedures in place to manage AI-related risks, and 56.2% had not adopted specific security controls for AI-enabled solutions.

At the same time, 72.6% of institutions use services through application programming interfaces (APIs), yet only a fraction periodically assess the associated risks. In the Brazilian financial sector, therefore, AI is more than an external threat. Brazilian financial institutions have been incorporating these technologies into fraud prevention, know-your-customer (KYC), customer service and internal control initiatives, with governance gaps of their own.

To address these gaps, the BCB’s regulatory response has focused on translating this diagnosis into concrete controls. National Monetary Council (CMN) Resolution No. 5,274/2025 and BCB Resolution No. 538/2025 moved cybersecurity policy from general guidelines to auditable requirements: annual, independent and documented penetration testing; stronger controls over the National Financial System Network (RSFN), Pix and the Reserves Transfer System (STR); and specific requirements for contracting data processing, data storage and cloud computing services.

In April, BCB Resolution No. 559/2026 empowered the BCB to require any Pix participant to submit a reasonable assurance report prepared by an independent auditor registered with the Brazilian Securities and Exchange Commission (CVM), and established a new ground for loss of participant status. The direction is clear: financial supervision is moving away from mere declaratory compliance and toward technological controls that ensure assurance, technical verification and accountability.

A resilience-first approach to financial regulation requires more than preventing incidents. It requires ensuring that critical functions keep operating under attack, with verifiable capabilities for detection, containment, response, recovery and accountability. Solvency and capital remain essential, but operational continuity under cyber stress now belongs on the same prudential map.

The expansion of Brazilian financial innovation (Pix, Open Finance, Banking as a Service (BaaS), APIs and the widespread use of AI) calls, in return, for an architecture of trust that cannot be taken for granted. Without it, the efficiency that made the Brazilian model an international benchmark would turn into reputational fragility at the first well-coordinated incident.

The IMF’s warning is an invitation to treat cyber resilience as a structural dimension of financial regulation. Recent BCB regulations show that the first steps of this journey are already being taken. The next step is to give this shift conceptual depth and to measure, over the coming years, how it will shape both the operational reality of financial institutions and the BCB’s supervisory and monitoring practices.

Leia também