# FDIC 2025 Report on Cybersecurity and Resilience: 2025 Report on Cybersecurity and Resilience

Source: https://www.bankingnewsai.com/ai-regulation/documents/fdic-cybersecurity-resilience-report-2025
Last updated: Aug 26, 2026

The FDIC's 2025 Report on Cybersecurity and Resilience, submitted to the House Financial Services and Senate Banking Committees under Section 108 of the Consolidated Appropriations Act, 2021 and posted in July 2025, warns that nation-state actors and cybercriminals are using generative AI to research targets and vulnerabilities, write malware, and run phishing campaigns, and that AI is being used to circumvent banks' identity and authentication controls. It states that generative AI, including large language models, can produce deepfakes and voice clones that make it harder to detect fraudulent or synthetic identities at account opening, transaction processing, and verification.

## At a glance

| Field | Value |
| --- | --- |
| Authority | [FDIC](https://www.bankingnewsai.com/ai-regulation/fdic) |
| Type | Report |
| Status | Final |
| Published | Jul 14, 2025 |
| Applies to | Report to Congress; informational for FDIC-supervised institutions |
| Official text | https://www.fdic.gov/banker-resource-center/2025-report-cybersecurity-and-resilience.pdf |

## Key points

- Annual report to Congress required by Section 108 of the Consolidated Appropriations Act, 2021; 2025 edition posted July 2025.
- Threat section: generative AI used by nation-state and criminal actors for reconnaissance, malicious code, and phishing.
- AI used to create fraudulent or altered documents, audio, and video, driving an increasing number of fraud cases.
- Deepfakes and voice cloning complicate detection of synthetic identities during onboarding and verification.
- Describes FDIC examination programs, the Computer-Security Incident Notification Rule, the NIST Cybersecurity Framework, and the sunset of the FFIEC Cybersecurity Assessment Tool.

## What changed for banks

It confirms that FDIC IT and cybersecurity examinations now treat AI-enabled social engineering and identity fraud as a live threat, reinforcing expectations for multifactor authentication and identity-verification controls at supervised banks.

## Use cases it governs

- [Cybersecurity](https://www.bankingnewsai.com/ai-regulation/by-use-case#cybersecurity)
- [Fraud detection](https://www.bankingnewsai.com/ai-regulation/by-use-case#fraud)
- [Generative & agentic AI](https://www.bankingnewsai.com/ai-regulation/by-use-case#generative-agentic-ai)

## FAQ

### What does the FDIC say about AI in cybersecurity?

That generative AI is lowering the cost of reconnaissance, malware, and phishing for attackers and is being used to defeat identity and authentication controls through deepfakes and voice cloning.

### Is this report binding on banks?

No. It is a report to Congress, but it reflects the threats FDIC examiners assess under existing safety-and-soundness and information-security standards.

## Related documents

- [Hill House oversight testimony (Jun 2026)](https://www.bankingnewsai.com/ai-regulation/documents/fdic-testimony-oversight-prudential-regulators-2026) — Statement of Chairman Travis Hill: Oversight of Prudential Regulators (Jun 4, 2026)
- [FDIC FIL-15-2026](https://www.bankingnewsai.com/ai-regulation/documents/fdic-fil-15-2026) — Agencies Revise the Interagency Model Risk Management Guidance (Apr 17, 2026)
- [FDIC House testimony on AI and innovation (Mar 2026)](https://www.bankingnewsai.com/ai-regulation/documents/fdic-testimony-innovation-speed-of-markets-2026) — Innovation at the Speed of Markets: How Regulators Keep Pace with Technology (Mar 26, 2026)
- [Hill 'Charting a New Course' speech](https://www.bankingnewsai.com/ai-regulation/documents/fdic-charting-new-course-speech-2025) — Charting a New Course: Preliminary Thoughts on FDIC Policy Issues (Jan 10, 2025)
- [FDIC 2024 Risk Review](https://www.bankingnewsai.com/ai-regulation/documents/fdic-risk-review-2024) — 2024 Risk Review — Section 5: Operational and Cyber Risks (May 22, 2024)
- [FDIC FIL-29-2023](https://www.bankingnewsai.com/ai-regulation/documents/fdic-fil-29-2023) — Interagency Guidance on Third-Party Relationships: Risk Management (Jun 6, 2023)
- [FDIC FIL-27-2021](https://www.bankingnewsai.com/ai-regulation/documents/fdic-fil-27-2021) — Interagency Statement on Model Risk Management for Bank Systems Supporting BSA/AML and OFAC Compliance (Apr 9, 2021)
- [FDIC FIL-20-2021](https://www.bankingnewsai.com/ai-regulation/documents/fdic-fil-20-2021) — Request for Information and Comment on Financial Institutions' Use of Artificial Intelligence, Including Machine Learning (Mar 29, 2021)

Last reviewed Aug 26, 2026. Cite the official text (https://www.fdic.gov/banker-resource-center/2025-report-cybersecurity-and-resilience.pdf) for the rule and this page for the summary and dates.

---

Canonical page: https://www.bankingnewsai.com/ai-regulation/documents/fdic-cybersecurity-resilience-report-2025
Part of [BankingNewsAI](https://www.bankingnewsai.com/) — a free daily brief on AI in banking, an AI regulation tracker (41 authorities, 237 documents) and AI-strategy profiles of the 120 largest US banks. Markdown versions of every reference page: append `.md` to the page URL; index at https://www.bankingnewsai.com/llms.txt.
