Key Technology and Legal Risks in Digital Banking Operations
By: Rodolfo Ramírez, Corporate and International Manager

"The only constant is change." — Heraclitus
As is widely recognized, banking operations can generally be understood as the internal activities carried out by financial institutions to deliver their services. In a broader and more practical sense, the term also encompasses the commercial relationships that banks maintain with their customers. It is evident that a fundamental component of any commercial bank’s business strategy is to expand the reach of its services to increasingly broader segments of the population. Achieving this objective requires consideration of two key factors: operational efficiency and generational change. Interestingly, both challenges can be addressed simultaneously through the effective use of technology.
We maintain this position because the automation enabled by the Internet and Artificial Intelligence increasingly allows financial institutions to deliver a broader range of services more efficiently than through traditional, analog methods. At the same time, a growing number of younger individuals—digital natives—are entering the workforce. Due to their cultural and technological familiarity, they tend to prefer remote and digital channels for accessing and using banking services.
While these developments present significant opportunities, they are by no means free from risk. Just as fraud and counterfeiting posed threats to traditional banking operations, digital channels are likewise exposed to risks arising from cybercrime. These risks take various forms and can be broadly categorized as follows: Phishing, Spear Phishing, and Social Engineering Fraud (These attacks involve manipulating users through fraudulent mass emails or SMS messages, highly targeted attacks against specific individuals, deceptive phone calls made by malicious actors, or the use of Artificial Intelligence to impersonate voices and facilitate fraud.) Banking Malware and Financial Trojans (Malicious software designed to capture keystrokes, intercept transactions, or manipulate banking operations without the user's knowledge or authorization.) Credential Compromise and Brute-Force Attacks (Including risks arising from compromised or leaked credential databases, password reuse across multiple platforms, credential stuffing, and automated brute-force attacks), Electronic Payment and Instant Transfer Fraud (Risks arising from irrevocable instant transfers, forged payment instructions submitted through mobile banking applications, beneficiary impersonation, and other forms of electronic payment fraud.) Attacks on Mobile Banking and Digital Banking Channels (Including the manipulation of banking applications; tampering with the software development kits (SDKs) and libraries that applications rely on in order to steal data, intercept transactions, transmit information to attacker-controlled servers, or execute malicious code; device compromise through jailbreaking, rooting, or unauthorized privilege escalation; and overlay attacks, in which a malicious application displays deceptive screens over a legitimate banking app to trick users into disclosing sensitive information or authorizing fraudulent transactions.) Ransomware and Attacks on Critical Infrastructure the compromise of banking systems through encryption, accompanied by ransom demands or threats to leak sensitive data; andinsider threats. (That is, malicious or negligent actions by employees, contractors, or unauthorized third parties with privileged access to banking systems Artificial Intelligence-Assisted Fraud (Including voice and video impersonation (deepfakes), the use of intelligent bots, and the impersonation of banking executives or other trusted representatives to deceive customers or employees.) Denial-of-Service (DoS) Attacks (These attacks are designed to disrupt services or conceal simultaneous fraudulent activities, among others.
As expected, the government's response eventually took the form of enacting legal and regulatory frameworks to combat this type of criminal activity. However, these risks—together with others that will inevitably emerge as technology continues to evolve—require a sustained commitment to understanding, anticipating, and preventing them. In my view, prevention will ultimately prove to be the most effective tool for mitigating cyber risks and strengthening the resilience of digital banking systems.
Note: This article was developed with the assistance of artificial intelligence (AI) and reviewed by an editor.
