Emerging cybersecurity threats and adaptive defence frameworks in online banking

Authors

  • Aditya Basu Professor, Dept. of Information Technology, JIMS Rohini, Delhi, India.
  • Harsh Jain MCA Student, Department of Information Technology, JIMS Rohini, Delhi, India.
  • Deepshika Aggarwaal Professor, Department of Information Technology, JIMS Rohini, Delhi, India.

Keywords:

Online Banking Security, Phishing Detection, Banking Trojans, Zero-Trust Architecture, Intrusion Detection Systems, AI-Driven Cyber Threats.

Abstract

The rapid digitalization of financial services has exposed online banking systems to sophisticated adversarial campaigns targeting authentication layers, transaction pipelines, and third-party dependencies. This paper investigates the evolving threat landscape encompassing phishing, banking Trojans, ransomware, insider threats, zero-day exploits, and artificial intelligence (AI)-augmented attacks through a mixed-methods design combining systematic literature analysis (2018–2025) with secondary breach-dataset examination and structured case-study review. Five landmark incidents are examined: the 2019 Capital One server-side request forgery (SSRF) incident, the 2020 SolarWinds supply-chain attack, the 2021 Flagstar Bank ransomware incident, the 2023 MOVEit Transfer zero-day exploitation, and a 2024 AI-assisted spear-phishing campaign documented by Mandiant. The primary contribution is the Adaptive Layered Security Architecture (ALSA), a five-tier conceptual framework encompassing identity assurance, behavioural intelligence, transaction integrity monitoring, network and infrastructure defence, and resilience governance. Each tier is designed for bidirectional information exchange, creating a continuous adaptive feedback loop. Comparative evaluation against the National Institute of Standards and Technology Cybersecurity Framework (NIST CSF) 2.0, Payment Card Industry Data Security Standard (PCI DSS) 4.0, and the Cybersecurity and Infrastructure Security Agency (CISA) Zero Trust Maturity Model (ZTMM) confirms ALSA's superior coverage of AI-generated and insider-risk threat scenarios. Quantitative analysis of 5,247 confirmed incidents reveals phishing as the dominant initial-access vector (36.2%), followed by public-application exploitation (22.7%). Findings provide theoretical grounding for security architects and actionable guidance for institutions navigating evolving regulatory mandates. Future research directions include quantum-resistant cryptography, federated fraud detection, and large language model (LLM)-based security operations center automation.

Published

2026-03-18

How to Cite

Aditya Basu, Harsh Jain, & Deepshika Aggarwaal. (2026). Emerging cybersecurity threats and adaptive defence frameworks in online banking. Journal of Corporate Finance Management and Banking System, 6(1), 57–69. Retrieved from https://journal.hmjournals.com/index.php/JCFMBS/article/view/6517

Similar Articles

1 2 3 4 5 6 > >> 

You may also start an advanced similarity search for this article.