By Jack Madine
Banks have mastered identity security, but attackers are exploiting a new weak point: trusted files that can conceal malware, fraud and emerging threats.
For more than a decade, financial services have led the way in cybersecurity investment. Banks have embraced multi-factor authentication, adopted zero trust principles and invested heavily in identity and access management. Few industries have strengthened digital identity as successfully.
However, attackers never stop adapting. As banks have taken measures to strengthen identity security, cybercriminals have shifted their focus elsewhere. However, the new weapon of choice is the files that organisations accept, exchange and trust every day.
Why are cybercriminals using files in attacks?
During my time at Lloyds, I was also part of the Cyber Defence Alliance, working alongside security professionals from across the banking sector.
The biggest lesson I took away was that attackers rarely persist against the strongest defences and instead look for the weakest link. Today, that means embedding malicious software in the files that organisations allow into their environments.
It’s an issue that extends across every industry and research shows that more than half of organisations, across all sectors, have experienced at least one file-related breach in the past two years, with the average incident costing $2.7 million.
In the financial sector, whilst banks have invested heavily in strengthening identity security, comparatively less attention was paid to file security, and that imbalance is now being exploited.
This is a significant security gap as financial institutions receive thousands of external files every day. Attackers understand that if they can persuade an organisation to trust a malicious file, they can often bypass many of the controls designed to protect user identities altogether.
Modern file formats can contain macros, embedded hyperlinks, scripts and password-protected content, giving attackers multiple ways to conceal malware. Even when organisations disable macros, malicious links and other active content can remain, allowing threats to evade traditional antivirus tools.
As financial institutions continue their digital transformation, every uploaded identity document, supplier invoice, bank statement and third-party file has become a potential attack vector.
How is AI making the situation harder for security teams?
AI is capable of performing tasks that once required significant technical expertise and time. One of the clearest examples is document fraud. AI tools can produce convincing driving licences, passports and payslips at a standard that would have been unimaginable just a few years ago.
Combine that with the rise of digital onboarding, where opening an account may require little more than a few images and a short video, and fraudulent KYC submissions have become far easier to produce.
A bank may verify an individual’s identity correctly, but if it implicitly trusts the document itself, it creates a serious vulnerability.
Phishing campaigns also continue to rely heavily on malicious attachments, while supply chain attacks increasingly arrive through files exchanged between trusted business partners rather than traditional network intrusions.
I’ve seen first-hand how much damage a single compromised supplier relationship can cause because everyone downstream tends to trust that channel by default. That’s exactly the assumption attackers are relying on.
Why does inspecting files at the point of transfer matter more than catching them afterwards?
Trust has always been the foundation of banking. Traditionally, that trust has centred on identity. Today, it must also extend to the integrity of every file entering the organisation.
Too many security teams still inspect files only after they have entered internal systems, often relying on a single detection method. In many cases, that’s signature-based antivirus, which remains effective against known threats but offers limited protection against new or unknown attacks.
A far more effective approach is to establish trust before files cross the security perimeter. Every external file should be verified, analysed and sanitised before it reaches users or critical infrastructure.
Applying multiple inspection techniques not only improves detection rates but also reduces false positives. More importantly, it prevents malicious content from entering the environment in the first place, reducing the need for costly incident response further downstream.
How do you re-establish trust in files?
Since there are so many potential threats at play, file security needs a multi-layered approach. As files move between customers, partners and financial institutions, they should be inspected automatically using multiple complementary technologies.
Managed File Transfer (MFT) has traditionally been viewed as a secure way of moving sensitive data between organisations, but it should also function as a security layer.
Multi-engine antivirus scanning improves detection rates for known malware, while sandboxing safely executes suspicious files to identify previously unseen threats. Threat intelligence provides additional context by identifying indicators associated with known attack campaigns, while AI-powered document analysis can detect manipulated or fraudulent content that traditional security tools may overlook.
Finally, technologies such as Content Disarm and Reconstruction (CDR) remove potentially dangerous active content while reconstructing the document itself, allowing business processes to continue without interruption and protecting the organisation from unnecessary risk.
That distinction matters because blocking every suspicious file isn’t a practical solution. Banks depend on the seamless exchange of a huge number of documents and blocking every file until it’s been manually cleared would quickly create an operational bottleneck.
Financial institutions have got identity security right by embedding it within the infrastructure. File security now needs the same discipline. The goal is to make sure that by the time a file reaches someone, whether that’s a mortgage application that needs to be approved or an invoice that must be paid, it has already been verified as safe and secure.
About the Author
Jack Madine is Senior Product Manager for MetaDefender Aether at OPSWAT, specialising in file security and zero-day threat detection. He previously worked as a cybersecurity specialist at Lloyds Banking Group and spent four years at Adarma Security, bringing extensive financial services and cybersecurity experience to his current role.




























































