Trend Micro, a global leader in cybersecurity solutions, today published research showing that significant new European banking rules could significantly increase cyberattacks on financial services firms and their customers.
The new research analyses the impact of the European Union’s Revised Payment Services Directive (PSD2), which is designed to give users greater control over their financial data and the option to share the new range of innovative financial technologies (FinTech). This is globally known as “Open Banking”.

“The financial sector has always been an extremely attractive target for hackers , and PSD2 and Open Banking will provide hackers with even more opportunities to steal sensitive personal and financial information,” said Ed Cabrera, senior vice president at Trend Micro. “Our concern is that the industry may not be fully prepared to deal with these very widespread attacks, so we wanted to understand the risks before they occur, to alert companies to better handle the situation.”
The report highlights several possible attack scenarios under the new regulatory regime:
- API Attacks: Public APIs are at the heart of Open Banking, allowing authorized third parties to access users’ banking data to provide innovative new financial services. Flaws in these APIs will allow attackers to exploit back-end servers to steal data.
- Attacks on FinTech companies: Users will be forced to build a new trust relationship with providers that may have fewer resources than their banks and lack a track record of data protection. In a quick survey of OpenTraining FinTechs, Trend Micro found that they have an average of 20 employees and no dedicated security professional. This makes them ideal targets for hackers and raises concerns about security gaps in mobile apps, APIs, data sharing techniques, and security modules that could be implemented incorrectly.
- Attacks on apps or mobile platforms: Most Open Bank services will be deployed as mobile apps, making them a prime target for attackers. Finding the username, password, or encryption keys within the app would allow a criminal to retrieve the user. Even if the apps are not authorized to make payments, they could contain transaction data, allowing a hacker to create a highly accurate profile of victims .
- Attacks against the user: Because new Open Banking applications will become the primary means of users accessing financial data and services, phishing attacks could reap large sums of money as rewards for attackers.
To prepare for the changing landscape, Trend Micro explains how financial institutions can improve cyber resilience. These include ensuring that sensitive information is never included in so-called URL paths, prioritizing secure protocols , and eliminating risky practices.
In the meantime, developers and users of Open Banking applications must adopt a secure design approach, including regular software audits.
