The FDIC's 2025 Report on Cybersecurity and Resilience, submitted to the House Financial Services and Senate Banking Committees under Section 108 of the Consolidated Appropriations Act, 2021 and posted in July 2025, warns that nation-state actors and cybercriminals are using generative AI to research targets and vulnerabilities, write malware, and run phishing campaigns, and that AI is being used to circumvent banks' identity and authentication controls. It states that generative AI, including large language models, can produce deepfakes and voice clones that make it harder to detect fraudulent or synthetic identities at account opening, transaction processing, and verification.
| Document | FDIC 2025 Report on Cybersecurity and Resilience — 2025 Report on Cybersecurity and Resilience |
| Issued by | Federal Deposit Insurance Corporation |
| Type | Report |
| Status | Final |
| Published | Jul 14, 2025 |
| Applies to | Report to Congress; informational for FDIC-supervised institutions |
| Official source | fdic.gov ↗ |
| Use cases | Cybersecurity · Fraud detection · Generative & agentic AI |
What are the key points of FDIC 2025 Report on Cybersecurity and Resilience?
- Annual report to Congress required by Section 108 of the Consolidated Appropriations Act, 2021; 2025 edition posted July 2025.
- Threat section: generative AI used by nation-state and criminal actors for reconnaissance, malicious code, and phishing.
- AI used to create fraudulent or altered documents, audio, and video, driving an increasing number of fraud cases.
- Deepfakes and voice cloning complicate detection of synthetic identities during onboarding and verification.
- Describes FDIC examination programs, the Computer-Security Incident Notification Rule, the NIST Cybersecurity Framework, and the sunset of the FFIEC Cybersecurity Assessment Tool.
What did FDIC 2025 Report on Cybersecurity and Resilience change for banks?
It confirms that FDIC IT and cybersecurity examinations now treat AI-enabled social engineering and identity fraud as a live threat, reinforcing expectations for multifactor authentication and identity-verification controls at supervised banks.
What does the FDIC say about AI in cybersecurity?
That generative AI is lowering the cost of reconnaissance, malware, and phishing for attackers and is being used to defeat identity and authentication controls through deepfakes and voice cloning.
Is this report binding on banks?
No. It is a report to Congress, but it reflects the threats FDIC examiners assess under existing safety-and-soundness and information-security standards.
| Date | Document | Status |
|---|---|---|
| Jun 4, 2026 | Hill House oversight testimony (Jun 2026) — Statement of Chairman Travis Hill: Oversight of Prudential Regulators | Final |
| Apr 17, 2026 | FDIC FIL-15-2026 — Agencies Revise the Interagency Model Risk Management Guidance | In force |
| Mar 26, 2026 | FDIC House testimony on AI and innovation (Mar 2026) — Innovation at the Speed of Markets: How Regulators Keep Pace with Technology | Final |
| Jan 10, 2025 | Hill 'Charting a New Course' speech — Charting a New Course: Preliminary Thoughts on FDIC Policy Issues | Final |
| May 22, 2024 | FDIC 2024 Risk Review — 2024 Risk Review — Section 5: Operational and Cyber Risks | Final |
| Jun 6, 2023 | FDIC FIL-29-2023 — Interagency Guidance on Third-Party Relationships: Risk Management | In force |
Follow every document these regulators publish
6 curated AI stories for banking executives · Every morning · Free
Subscribe to BankingNewsAI →