
Cyber has overtaken geopolitics as the risk Singapore's financial institutions cite most. Here are the four emerging side doors behind that number, and what risk and compliance teams can do about them.
A European bank received what looked like routine legal paperwork: European Investigation Orders, sent from genuine Italian government email accounts. The accounts were real. The people using them weren't.
Attackers had reportedly harvested credentials with infostealer malware, then used the government's own mailboxes to request data — deleting the evidence as they went. The bank's core systems were never breached. The attackers simply walked in through a channel the bank had every reason to trust.
That is the story of this year's MAS Financial Stability Review, in miniature.
MAS's Financial Stability Review 2026 (22 September) includes its Systemic Risk Survey of chief risk officers: 57 financial institutions, 98% response rate.
Including AI-assisted cyber-attacks and third-party vendor concentration. Now the MOST CITED category.
Still ranks first on impact.
A new category in this year's survey.
AI is simultaneously the industry's newest threat vector and its newest bubble risk. Few technologies manage both in one survey.
Several FIs described AI-enabled cyberattacks as an upward "level-shift" in the threat landscape. MAS summarises three concerns:
Regulators across the region want evidence, not intent.
BNM imposed an RM1 million penalty on Bank Kerjasama Rakyat Malaysia (January 2026) for cybersecurity and customer information protection breaches under RMiT.
OJK's PADK No. 1/2026 (in force 1 March 2026) tightens board accountability, IT risk management and oversight of IT service providers, building on POJK 11/2022 and SEOJK 29/2022.
MAS and ABS formed the AI-Driven Cyber and Technology Risk Taskforce (July 2026); MAS TRM Guidelines set the baseline.
The concerns MAS names are no longer abstract. In the past two weeks, each has turned up in a real incident. None happened to a Singapore bank. All describe routes into one.
The AI Assistant
The New Hire
The Code Pipeline
The Patch Gap
Personal AI agents — reading email, sending messages, managing calendars — are being adopted at consumer speed. Meta's Muse passed half a million users in its first week. A security researcher then disclosed a zero-day in Muse's macOS app: any local app could capture its account token, handing control of connected email, WhatsApp, calendar, camera and files. Researchers at Gen Digital also report new infostealers harvesting AI agents' credentials and stored context.
Evidence to have ready: AI tool register · consent and connector logs · access reviews including non-human identities.
On 18 September, seven agencies from Japan, the US, Australia and Germany issued a joint advisory on North Korea-linked WaterPlum ("Contagious Interview"). Posing as recruiters, the group asks developers to run a "coding assignment" or fix a video-call error. Either task runs malware.
Some members used AI face-swapping software in interviews. The advisory links WaterPlum to North Korean IT workers using laptop farms and borrowed identities to get remote jobs. A small number operate from Southeast Asia; once hired, some have leaked source code to extort employers. Paying one, even unknowingly via a contractor, may breach sanctions.
Evidence to have ready: contractor and vendor screening records · identity checks for remote roles · sanctions screening on contractor payments.
A forgotten GitHub token — exposed via an earlier TanStack compromise — let attackers clone ~170 private CrowdSec repositories in nine minutes. A malicious npm package concealed its payload to evade install-time checks. On 17 September, CSA confirmed active exploitation of GitLab and Vite development servers.
Evidence to have ready: offboarding checklists covering developer credentials · SBOMs for critical apps · third-party software assurance records.
In thirteen days — 9 to 21 September — CSA issued ten security alerts. Six of those flagged vulnerabilities already under active exploitation. The asymmetry is widening: in a controlled test, frontier AI models fully fixed the vulnerability in only 26% of more than 6,000 patches. Attackers find faster; defenders fix slower.
Evidence to have ready: remediation timeline metrics · exceptions register · vendor patch-notification clauses.
None of the four doors needs a new framework. MAS TRM, BNM RMiT and OJK's IT regulations already expect these controls. What's changed is where they must reach:
Identity now includes AI agents.
Third-party risk now includes vendors' developer credentials and open-source intake.
Personnel screening must assume the candidate might be the attack.
Patch management now runs against an AI-accelerated clock.
MAS FSR 2026
9–21 Sep 2026
AI agents are the side door most institutions have the least visibility into. Ewashi's AI Endpoint Risk Snapshot gives risk and compliance leaders a prioritised view of AI exposure: a confidential 10-question intake (under 5 minutes), reviewed by an Ewashi practitioner, with your Snapshot delivered within 3 business days.
© Ewashi · ewashi.com
The Vault Is Fine. It's the Side Doors.