Saturday, August 1, 2026Sat, Aug 1
HomeTechItaly's Banking Sector Spends €500M to Fight AI-Powered Fraud Targeting 2.9M Residents
Tech · Economy

Italy's Banking Sector Spends €500M to Fight AI-Powered Fraud Targeting 2.9M Residents

Italian banks invest €500M in cybersecurity in 2026. Learn about AI scams, new fingerprint payment cards, and 7 safety rules to protect your money.

Italy's Banking Sector Spends €500M to Fight AI-Powered Fraud Targeting 2.9M Residents
Italian bank employees working at computer stations with AI data visualization on screens

The Italian Banking Association has announced that digital security across the banking sector will remain a top investment priority, with institutions committing roughly €500M in 2026 alone to protect customers from an escalating wave of sophisticated cyberattacks. This follows nearly €2.5B spent between 2020 and 2025, as fraud attempts leveraging artificial intelligence now affect more than 2.9M Italians annually, causing losses exceeding €880M.

Why This Matters

Your money is a moving target: Over 2,600 cyberattacks per week hit Italian organizations in June 2026, an 11.5% monthly increase.

AI-powered scams are now indistinguishable: Phishing messages mimicking Intesa Sanpaolo, Poste Italiane, INPS, and Agenzia delle Entrate are generated by AI and contain zero grammatical errors.

Biometric cards arrive soon: Fingerprint-authenticated payment cards will roll out in Italy between 2026 and 2027, eliminating PIN codes.

New EU rules bite: The DORA regulation (Digital Operational Resilience Act) comes into full force this year, requiring banks to stress-test systems and report critical vendor dependencies.

The New Threat Landscape

Italy recorded 148 ransomware attacks in the first half of 2026, with over 13,400 gigabytes of data reportedly stolen. Manufacturing bore the brunt, but financial services remain a prime target. Attacks have become "multilocalizzati," hitting multiple sectors simultaneously rather than focusing on a single industry.

Phishing and smishing campaigns detected by CERT-AGID jumped to 433 active operations between February and March alone. Unlike the clumsy spam of years past, these messages are now crafted by generative AI models that replicate official bank communications with pixel-perfect logos, correct legal disclaimers, and personalized greetings. Victims receive SMS or emails appearing to come from their actual bank, complete with spoofed sender addresses.

Vishing—voice phishing conducted via phone—has also evolved. Callers impersonate Polizia Postale officers or bank staff, using number-spoofing technology to display what appears to be an official contact. They request one-time passwords, authorization codes, or permission to "cancel" fraudulent transactions that never existed.

The Banca d'Italia has flagged a troubling development: latest-generation AI models can now identify software vulnerabilities and generate exploit code in compressed timeframes, accelerating every phase of an attack from reconnaissance to payload delivery.

What the Banking Sector Is Doing

CERTFin, the Computer Emergency Response Team for Italian finance—jointly overseen by the Banca d'Italia and ABI—serves as the sector's frontline intelligence-sharing hub. Banks relay threat data in real time, enabling rapid collective defense. Approximately 8% of total IT budgets now flow toward security, with a growing slice earmarked specifically for anti-fraud solutions and digital identity management.

Resilience, not just defense, defines the current investment cycle. Priorities include Threat-Led Penetration Testing (mandatory under DORA), vendor risk oversight, and maintaining a comprehensive Registro Informazioni (information registry) for regulatory inspection. By year-end, all intermediaries must submit a report to the Banca d'Italia detailing their risk profile and a mitigation roadmap that accounts for AI-related vulnerabilities, including those tied to biometric data collection.

Around 80% of Italian banks now rank artificial intelligence among their top ten investment priorities. Beyond cybersecurity, AI powers fraud detection engines, automates compliance workflows, and underpins the next wave of "agentic" systems capable of orchestrating complex transactions across legacy platforms.

Biometric Authentication Arrives

Fingerprint-sensor payment cards—already piloted in northern Europe—will reach Italian consumers starting late 2026 or early 2027. Instead of entering a PIN at the terminal, cardholders simply rest a fingertip on an embedded scanner. The biometric template is stored locally on the chip, not transmitted to merchants or banks, addressing some privacy concerns.

Survey data cited by the sector suggests that more than half of credit cardholders would consider switching banks if biometric options were unavailable, viewing the technology as both more convenient and more secure than memorized codes. Yet the Garante Privacy has imposed strict conditions: mass scraping of biometric data via untargeted collection is prohibited under Italy's coordination with the EU AI Act.

Financial institutions must also integrate biometric authentication with SPID (the national digital identity system), CIE (electronic identity cards), and the forthcoming European Digital Identity Wallet (eIDAS 2), creating a federated identity architecture that spans public and private services.

Seven Rules for Staying Safe Online

ABI, working with CERTFin, has published a fresh set of guidelines aimed at reducing customer exposure:

Deploy unique, complex passwords for each service—mixing uppercase, lowercase, numbers, and symbols. Password managers can simplify this.

Avoid public or open Wi-Fi networks when accessing banking apps. Use your own mobile data or a trusted home connection.

Install antivirus software and enable automatic updates to catch newly discovered exploits.

Limit personal information shared on social media, as scammers harvest details to personalize phishing messages.

Verify sender authenticity before clicking links or downloading attachments. Cross-check phone numbers and email domains against your bank's official contact list.

Treat unsolicited calls with suspicion. No legitimate bank or police officer will request OTP codes, passwords, or account credentials by phone.

React immediately if compromised. Contact your bank's fraud hotline, then file a report with Polizia Postale or local authorities. Speed limits damage.

The association emphasizes that banks will never ask for sensitive credentials via email, SMS, or unsolicited calls—a message that bears repeating as AI-generated voice clones grow more convincing.

Impact on Residents and Businesses

For retail customers, the practical upshot is a mixed experience: stronger protections behind the scenes, but also new friction points. Multi-factor authentication can feel cumbersome, especially for older users unfamiliar with app-based tokens. Biometric cards promise to smooth this trade-off, though privacy advocates continue to scrutinize how templates are stored and whether law enforcement could compel access.

Small and medium enterprises face steeper compliance costs. The PSD2 directive mandates strong customer authentication (SCA) for online payments and data-sharing with authorized third parties under Open Banking rules. Many SMEs still rely on outdated accounting software that struggles to integrate with modern APIs, creating security gaps.

Corporate treasurers must now map their entire supply chain of cloud providers, payment processors, and fintech vendors to satisfy DORA's critical-vendor registry. Any third party handling sensitive financial data becomes subject to supervisory oversight, potentially slowing vendor onboarding but raising baseline security standards across the ecosystem.

WeSec: The Sector Gathers in Milan

ABI and ABIServizi will convene WeSec – Il Salone della Sicurezza on September 22–23, 2026, at the Allianz MiCo in Milan. The event replaces the long-running "Banche e Sicurezza" conference with an expanded format that includes an exhibition floor for technology vendors and over 20 thematic sessions across five halls.

Topics span cybersecurity and fraud prevention, AI governance, sovereign monetary infrastructure (blockchain, tokenized assets, stablecoins), physical and operational resilience, and geopolitical risk. Representatives from the Banca d'Italia, Polizia Postale, CERTFin, ABI Lab, OSSIF, and the financial-education foundation FEduF will lead panels alongside industry practitioners and academic researchers. Deloitte serves as knowledge partner.

Director General of ABI, Marco Elio Rottigni, framed security as an enabler of economic development and innovation, rather than a purely defensive cost center. Attendance is free upon registration via the event website, and the full agenda—including workshop schedules—will be published closer to the date.

What Comes Next

The twin pressures of regulatory compliance (DORA, PSD2, AI Act) and escalating cyber threats are driving a fundamental shift in how Italian banks architect their technology stacks. Legacy mainframes coexist uneasily with cloud-native microservices, and many institutions are adopting Zero Trust models that treat every access request as potentially hostile, even from inside the corporate perimeter.

Identity management emerges as the linchpin: seamless enough to avoid abandoning customers mid-transaction, yet rigorous enough to block AI-assisted impersonation. The forthcoming European Digital Identity Wallet aims to harmonize authentication across member states, but rollout timelines remain uncertain and interoperability hiccups are expected.

For residents, the practical advice remains straightforward: treat every unsolicited message as suspicious, verify through independent channels, and act fast if something feels wrong. The arms race between attackers and defenders will not pause, but awareness remains the cheapest and most effective layer of defense.

Author

Luca Bianchi

Economy & Tech Editor

Covers Italian industry, innovation, and the digital transformation of traditional sectors. Believes that economic journalism works best when it connects data to real people.