The Vault Is Fine. It's the Side Doors.

Cyber has overtaken geopolitics as the risk Singapore's financial institutions cite most. Here are the four emerging side doors behind that number, and what risk and compliance teams can do about them.

Ewashi · Cybersecurity · Financial Services · ASEAN · 8 min readSeptember 2026

The trusted channel

A European bank received what looked like routine legal paperwork: European Investigation Orders, sent from genuine Italian government email accounts. The accounts were real. The people using them weren't.

Attackers had reportedly harvested credentials with infostealer malware, then used the government's own mailboxes to request data — deleting the evidence as they went. The bank's core systems were never breached. The attackers simply walked in through a channel the bank had every reason to trust.

That is the story of this year's MAS Financial Stability Review, in miniature.

What MAS just told us

MAS's Financial Stability Review 2026 (22 September) includes its Systemic Risk Survey of chief risk officers: 57 financial institutions, 98% response rate.

80%

Cyber & operational risks

Including AI-assisted cyber-attacks and third-party vendor concentration. Now the MOST CITED category.

77%

Geopolitical risk

Still ranks first on impact.

57%

Financial market stress from AI-driven fragilities

A new category in this year's survey.

AI is simultaneously the industry's newest threat vector and its newest bubble risk. Few technologies manage both in one survey.

A "level-shift"

Several FIs described AI-enabled cyberattacks as an upward "level-shift" in the threat landscape. MAS summarises three concerns:

1

Frontier AI models could make vulnerabilities easier to find and exploit.

2

Generative AI could enable more sophisticated fraud and social engineering.

3

Common reliance on shared cloud and AI infrastructure providers creates concentration risk.

This isn't a Singapore quirk

Regulators across the region want evidence, not intent.

Malaysia

BNM imposed an RM1 million penalty on Bank Kerjasama Rakyat Malaysia (January 2026) for cybersecurity and customer information protection breaches under RMiT.

Indonesia

OJK's PADK No. 1/2026 (in force 1 March 2026) tightens board accountability, IT risk management and oversight of IT service providers, building on POJK 11/2022 and SEOJK 29/2022.

Singapore

MAS and ABS formed the AI-Driven Cyber and Technology Risk Taskforce (July 2026); MAS TRM Guidelines set the baseline.

The four side doors

The concerns MAS names are no longer abstract. In the past two weeks, each has turned up in a real incident. None happened to a Singapore bank. All describe routes into one.

Door 1

The AI Assistant

Door 2

The New Hire

Door 3

The Code Pipeline

Door 4

The Patch Gap

Door 1. The AI assistant in your staff's pocket

MAS concern: AI-assisted cyber-attacks; concentration in AI infrastructure

Personal AI agents — reading email, sending messages, managing calendars — are being adopted at consumer speed. Meta's Muse passed half a million users in its first week. A security researcher then disclosed a zero-day in Muse's macOS app: any local app could capture its account token, handing control of connected email, WhatsApp, calendar, camera and files. Researchers at Gen Digital also report new infostealers harvesting AI agents' credentials and stored context.

What good looks like

  • Maintain an approved AI tool register; switch off user self-consent for third-party apps.
  • Treat agents as non-human identities: scoped, time-bound tokens, no standing privilege, included in access recertification.
  • Require human approval for high-impact agent actions (payments, external transfers, configuration changes).
  • Extend endpoint detection and DLP to agent token stores and connectors.

Evidence to have ready: AI tool register · consent and connector logs · access reviews including non-human identities.

Door 2. The new hire who isn't who they say

MAS concern: increasingly sophisticated fraud and social engineering

On 18 September, seven agencies from Japan, the US, Australia and Germany issued a joint advisory on North Korea-linked WaterPlum ("Contagious Interview"). Posing as recruiters, the group asks developers to run a "coding assignment" or fix a video-call error. Either task runs malware.

30,000+

PCs compromised

100+

Countries affected

7,000+

Wallets with funds or credentials taken

¥1.7B

≈US$10.7M moved to North Korea (Dec 2025 – Jul 2026)

Some members used AI face-swapping software in interviews. The advisory links WaterPlum to North Korean IT workers using laptop farms and borrowed identities to get remote jobs. A small number operate from Southeast Asia; once hired, some have leaked source code to extort employers. Paying one, even unknowingly via a contractor, may breach sanctions.

What good looks like

  • Strengthen identity assurance at offer and onboarding. Watch for: avoiding in-person meetings, crypto or third-party payment requests, IP/residence mismatches, repeated video "freezes", candidates who can't explain their own résumé.
  • Keep interview and test code off corporate endpoints; open unfamiliar VS Code projects in Restricted Mode.
  • Push screening and sanctions checks into outsourcing contracts, including how contractors are paid.
  • Brief developers and hiring managers specifically.

Evidence to have ready: contractor and vendor screening records · identity checks for remote roles · sanctions screening on contractor payments.

Door 3. The code pipeline you don't own

MAS concern: concentration risks from third-party vendors

A forgotten GitHub token — exposed via an earlier TanStack compromise — let attackers clone ~170 private CrowdSec repositories in nine minutes. A malicious npm package concealed its payload to evade install-time checks. On 17 September, CSA confirmed active exploitation of GitLab and Vite development servers.

What good looks like

  • Make credential revocation part of offboarding, including developer tokens and SSH keys; prefer short-lived credentials; scan for exposed secrets.
  • Control open-source intake: internal proxy with allow-listing, pinned versions, a cooling-off period for new releases.
  • Require SBOMs and secure development attestations from critical software vendors.
  • Harden build pipelines: least-privilege runners, protected branches, signed artifacts.

Evidence to have ready: offboarding checklists covering developer credentials · SBOMs for critical apps · third-party software assurance records.

Door 4. The patch gap

MAS concern: frontier AI making vulnerability discovery and exploitation easier

In thirteen days — 9 to 21 September — CSA issued ten security alerts. Six of those flagged vulnerabilities already under active exploitation. The asymmetry is widening: in a controlled test, frontier AI models fully fixed the vulnerability in only 26% of more than 6,000 patches. Attackers find faster; defenders fix slower.

What good looks like

  • Prioritise by exploitation, not just severity: CSA alerts, known-exploited catalogues, exploit-likelihood scoring, tiered remediation timelines.
  • Monitor your external attack surface continuously.
  • Formalise compensating controls in an exceptions register with owners and expiry dates.
  • Test AI-generated fixes rigorously; write patch-notification timelines into vendor contracts.

Evidence to have ready: remediation timeline metrics · exceptions register · vendor patch-notification clauses.

One more door & what it all means

What this means for risk and compliance teams

None of the four doors needs a new framework. MAS TRM, BNM RMiT and OJK's IT regulations already expect these controls. What's changed is where they must reach:

Identity

Identity now includes AI agents.

Third-party risk

Third-party risk now includes vendors' developer credentials and open-source intake.

Personnel screening

Personnel screening must assume the candidate might be the attack.

Patch management

Patch management now runs against an AI-accelerated clock.

The vault is in good shape. The CROs are telling us where to look next: the side doors.

By the numbers

80%

of Singapore FI CROs cite cyber and operational risk

MAS FSR 2026

57

FIs surveyed, 98% response rate

6

actively exploited vulnerabilities flagged by CSA

9–21 Sep 2026

26%

of AI-generated patches fully fixed the flaw in one large test


Start with the newest door.

AI agents are the side door most institutions have the least visibility into. Ewashi's AI Endpoint Risk Snapshot gives risk and compliance leaders a prioritised view of AI exposure: a confidential 10-question intake (under 5 minutes), reviewed by an Ewashi practitioner, with your Snapshot delivered within 3 business days.

Request Your AI Endpoint Risk Snapshot

Sources

© Ewashi · ewashi.com