Aug 26, 2026

ASIC Sounded the Alarm. Mobile is Where the Attack Starts.

On May 8, Commissioner Simone Constant of the Australian Security Investments Commission (ASIC) sent an open letter directly to every bank, superannuation fund, insurer, and financial services licensee in Australia. Not a report. Not a consultation. A direct instruction to boards and risk committees demanding urgent action on AI and cyber risk. Here's the full threat picture every CISO needs to add to that conversation.

The message was precise: AI is accelerating cyber attacks, lowering the barrier to sophisticated activity, and enabling new forms of exploitation previously out of reach for most actors. And critically, ASIC was clear, these are not entirely new categories of risk. It means existing controls will be tested more often, more aggressively, and at a far greater scale.

Every gap in your security architecture just became more dangerous. But for most financial institutions, Mobile is the largest and most vulnerable attack surface, and it is being uniquely targeted by threat actors and their AI helpers.

Mobile is the primary interface between financial institutions and everyone they serve. Customers open accounts, transfer funds, and verify identity on mobile apps. Employees access corporate systems and receive sensitive communications on personal and corporate devices.

That shift has created the largest attack surface in the modern enterprise. Most security architectures weren't built for it. Perimeter defenses and endpoint controls were designed for a world where work happened at a desk. That world is gone. Attackers know it.

Cybercriminals already have a mobile-first attack strategy

Mobile devices are persistently connected, rarely monitored at the depth of traditional endpoints, and carry credentials and session tokens that unlock everything else. A compromised device isn't just a device problem, it is a gateway to corporate systems and networks, customer accounts, and financial transactions.

Mobile applications are targeted because most ship without adequate runtime protection. Attackers reverse-engineer them, inject malicious code, and clone them as fraudulent lookalikes. Malware harvests credentials silently. Bots automate account takeovers and fraudulent transactions at a scale no human analyst can match. Emulators spoof device identity, bypassing the trust signals apps rely upon to distinguish a genuine customer from an attacker. All of it happens on the device, in the app, in real time, and before any traditional backend control can respond.

Attackers didn't stumble into mobile as the primary attack vector. They chose it because the vast majority of mobile devices, even corporate owned devices, are unprotected. A blind spot that fraudsters can exploit silently. .

AI didn't create this problem. It multiplied it.

AI does not introduce entirely new categories of risk. It makes existing vulnerabilities faster to find, faster to exploit, and at a scale never before seen.. For mobile, that pressure is acute.

AI-generated phishing is now five times more convincing than traditional attacks. ASIC's letter called out phishing explicitly as an example of how a simple attack can now provide access to critical platforms and sensitive data. Mobile is where these messages land first, acted on fastest, with the fewest visual cues to trigger suspicion.

AI is also compressing the timeline between vulnerability discovery and exploitation. Financial apps without runtime protection are static targets in a dynamic threat environment. ASIC called for organisations to use AI defensively, including to identify vulnerabilities and secure software before release. That is a direct mandate for how Australian financial institutions build and protect their mobile applications.

ASIC's directive: What they're asking you to do right now

The letter was specific. These are clear directives from your regulator to company boards and executives:

  • Reassess your cyber plans and refocus on the most critical risks in today's threat environment. Confirm your governance frameworks account for the cumulative impact of interrelated vulnerabilities.
  • Identify and protect critical assets with a clear understanding of what matters most to your business and customers.
  • Strengthen fundamentals by regularly reviewing and validating core controls. Minimise attack surfaces by reducing exposure to untrusted networks.
  • Review user access and reassess privileges — insider threats are increasing. Patch promptly, recognising AI is accelerating vulnerability discovery and exploitation.
  • Implement layered, defense-in-depth architectures that assume breach and restrict lateral movement.
  • Prepare and exercise incident response plans.
  • Actively manage third-party risks.
  • Use AI defensively, including to identify vulnerabilities and secure software before release.

Every one of these steps has a mobile dimension. Most organisations have not addressed it.

What boards should be asking their CISOs

ASIC required this letter to be tabled at every board and risk governance committee. Three questions are worth getting ahead of:

  • What is our mobile attack surface? Employee devices, customer-facing apps, and the data flowing between them. Most institutions can inventory the first two. Very few have real-time telemetry to all three.
  • How are our mobile apps protected at runtime? Code protection, tampering detection, and on-device threat response are table stakes for any institution that moves money through a mobile interface.
  • What does our mobile incident response look like? A plan that doesn't account for a compromised customer device or a weaponised banking app isn't complete.

Start where the attacks start

Commissioner Constant closed with this: "The time to act is now, not by reinventing your approach, but by ensuring the basics are robust, resourced, and working effectively."

The basics still apply. But basics built without mobile coverage have always had a gap. AI just made that gap impossible to ignore.

Start where the attacks start.