Bank of America Goes Shopping for Cyber Defense as AI-Powered Attacks Multiply

Bank of America said Thursday it plans to acquire UK-based information security firm MDSec Consulting Ltd, bolstering its capabilities against a wave of cyberattacks that companies worldwide are increasingly describing as AI-driven. FinancialMediaGuide notes that a bank of BofA’s scale choosing to acquire a specialist consultancy rather than build equivalent capabilities internally signals just how quickly AI-enabled attack techniques are outpacing what large in-house security teams can develop on their own timelines.

The deal is expected to close in the fourth quarter of 2026 following regulatory approval, the second-largest U.S. lender said in a statement, without disclosing the transaction’s value. MDSec, headquartered in Macclesfield, England, employs about 65 cybersecurity professionals and provides security-related consultancy services, adding specialized offensive and defensive expertise to Bank of America’s existing operations.

Bank of America already has a significant presence in the north of England, with more than 1,400 employees based nearby in Chester, where one of the bank’s cyber threat operations centers is also located, making MDSec a geographically convenient addition to its existing security footprint. FinancialMediaGuide highlights that proximity as more than a logistical detail, since co-locating newly acquired specialist talent near an existing threat operations center typically shortens the integration timeline that can otherwise blunt the value of a cybersecurity acquisition.

The deal arrives as the financial sector faces an intensifying threat environment: the industry experienced a 47% year-over-year increase in AI-enhanced malware, according to industry tracking data, and remains among the top targets for phishing, deepfakes and business email compromise fraud. Banking, financial services and insurance firms together account for more than a fifth of the global cybersecurity market by spending, reflecting how central the sector has become to overall industry demand.

Global information security spending is projected to reach $212 billion in 2026, up 15.1% from $193 billion in 2025, according to Gartner, with organizations now spending an average of $2,700 per employee on cybersecurity, according to Deloitte. FinancialMediaGuide points to that spending trajectory, more than doubling since 2020, as the broader financial backdrop that makes bolt-on security acquisitions like MDSec increasingly common among large banks rather than a one-off response to a specific incident.

Regulators have taken notice of the shift as well: the European Central Bank has called on supervised institutions to assess the impact of AI-enabled cyber threats and submit a comprehensive action plan to their Joint Supervisory Team by October 31, 2026, reflecting concern that artificial intelligence is accelerating how vulnerabilities are identified, exploited and weaponized. The White House separately said earlier this month it was launching a coordination group bringing together AI developers and critical infrastructure operators to share information on cybersecurity vulnerabilities identified by advanced AI systems and coordinate responses.

With both U.S. and European authorities now pushing financial institutions to formalize their defenses against AI-enabled threats on specific timelines, banks are under growing pressure to demonstrate concrete capability upgrades rather than general assurances. Financial Media Guide flags Bank of America’s MDSec acquisition as an early example of how that regulatory pressure is translating into actual dealmaking, and expects similar bolt-on cybersecurity acquisitions from other large banks as the ECB’s October deadline and comparable requirements elsewhere approach.

Share This Article