On May 8, Commissioner Simone Constant of the Australian Security Investments Commission (ASIC) sent an open letter directly to every bank, superannuation fund, insurer, and financial services licensee in Australia. Not a report. Not a consultation. A direct instruction to boards and risk committees demanding urgent action on AI and cyber risk. Here's the full threat picture every CISO needs to add to that conversation.
The message was precise: AI is accelerating cyber attacks, lowering the barrier to sophisticated activity, and enabling new forms of exploitation previously out of reach for most actors. And critically, ASIC was clear, these are not entirely new categories of risk. It means existing controls will be tested more often, more aggressively, and at a far greater scale.
Every gap in your security architecture just became more dangerous. But for most financial institutions, Mobile is the largest and most vulnerable attack surface, and it is being uniquely targeted by threat actors and their AI helpers.
Mobile is the primary interface between financial institutions and everyone they serve. Customers open accounts, transfer funds, and verify identity on mobile apps. Employees access corporate systems and receive sensitive communications on personal and corporate devices.
That shift has created the largest attack surface in the modern enterprise. Most security architectures weren't built for it. Perimeter defenses and endpoint controls were designed for a world where work happened at a desk. That world is gone. Attackers know it.
Mobile devices are persistently connected, rarely monitored at the depth of traditional endpoints, and carry credentials and session tokens that unlock everything else. A compromised device isn't just a device problem, it is a gateway to corporate systems and networks, customer accounts, and financial transactions.
Mobile applications are targeted because most ship without adequate runtime protection. Attackers reverse-engineer them, inject malicious code, and clone them as fraudulent lookalikes. Malware harvests credentials silently. Bots automate account takeovers and fraudulent transactions at a scale no human analyst can match. Emulators spoof device identity, bypassing the trust signals apps rely upon to distinguish a genuine customer from an attacker. All of it happens on the device, in the app, in real time, and before any traditional backend control can respond.
Attackers didn't stumble into mobile as the primary attack vector. They chose it because the vast majority of mobile devices, even corporate owned devices, are unprotected. A blind spot that fraudsters can exploit silently. .
AI does not introduce entirely new categories of risk. It makes existing vulnerabilities faster to find, faster to exploit, and at a scale never before seen.. For mobile, that pressure is acute.
AI-generated phishing is now five times more convincing than traditional attacks. ASIC's letter called out phishing explicitly as an example of how a simple attack can now provide access to critical platforms and sensitive data. Mobile is where these messages land first, acted on fastest, with the fewest visual cues to trigger suspicion.
AI is also compressing the timeline between vulnerability discovery and exploitation. Financial apps without runtime protection are static targets in a dynamic threat environment. ASIC called for organisations to use AI defensively, including to identify vulnerabilities and secure software before release. That is a direct mandate for how Australian financial institutions build and protect their mobile applications.
The letter was specific. These are clear directives from your regulator to company boards and executives:
Every one of these steps has a mobile dimension. Most organisations have not addressed it.
ASIC required this letter to be tabled at every board and risk governance committee. Three questions are worth getting ahead of:
Commissioner Constant closed with this: "The time to act is now, not by reinventing your approach, but by ensuring the basics are robust, resourced, and working effectively."
The basics still apply. But basics built without mobile coverage have always had a gap. AI just made that gap impossible to ignore.
Start where the attacks start.