The IMF is sounding the alarm about the cybersecurity risk that AI poses to the financial services sector, citing Anthropic’s recent controlled release of its Claude Mythos Preview, which comes at a time when CRM systems are becoming more deeply embedded into financial institutions.
The Claude Mythos large language model (LLM) has been able to find and exploit vulnerabilities in major operating systems and web browsers, and Anthropic has given vendors like Microsoft early access to the model to help patch such security flaws.
In an IMF blog post, Tobias Adrian, Tamas Gaidosch and Rangachary Ravikumar warned that:
“This foreshadows how fast‑moving, AI‑driven cyber risks could destabilize the financial system if not managed carefully, and why authorities must focus on building resilience through supervision and coordination—rather than treating these developments as purely technical or operational issues.”
The post added that while AI is transforming how the financial system deals with vulnerabilities and reacts to incidents, “it is also amplifying cyber threats that can undermine financial stability when the offensive capabilities of intruders outpace defenses.”
The institution’s analysis indicates that severe cyber incidents could create funding strains and disrupt wider financial markets.
The IMF has previously found that “[t]he financial sector is uniquely exposed to cyber risk. Financial firms—given the large amounts of sensitive data and transactions they handle—are often targeted by criminals seeking to steal money or disrupt economic activity.”
Attacks on financial firms account for nearly one-fifth of the total number of attacks, and among those, banks are the most exposed.
Advances in AI are changing the risk equation. As the IMF put it:
“Models such as Mythos illustrate the nature of the challenge because they amplify existing cyberattack techniques by operating at machine speed. Attackers have the advantage over defenders because discovering and exploiting vulnerabilities can occur faster than patching and remediation.”
In a financial system built on common software and shared service providers, this can create simultaneous security vulnerabilities across multiple institutions. The IMF also warned that cyber risk increasingly transcends individual sectors because financial services share digital infrastructure with energy, telecoms and public services.
“The Mythos episode also highlights governance challenges,” the post noted. “Cyber risk does not respect borders. As AI capabilities spread across countries, inconsistent oversight could weaken a globally interconnected system.”
There are some mitigating factors for now, as advanced AI cyber capabilities are not yet widely accessible to hackers, and closed, industry‑specific financial software is harder to target than open‑source infrastructure, the IMF noted. “But these buffers are likely to erode quickly as model training expands, capabilities diffuse, and leaks occur. Temporary containment is unlikely to substitute for durable defenses.”
Why Financial CRM Is Becoming a Cybersecurity Flashpoint
The warning comes as CRM platforms are becoming increasingly embedded in the operational core of financial services.
As banks, insurance firms, wealth managers, and fintechs deploy GenAI and agentic workflows, they are moving beyond collecting data around customer interactions to implementing purpose-built AI agents for finance work, AI-driven customer intelligence suites and vertical CRM systems that embed AI directly into Salesforce-based advisory workflows to manage and deepen customer relationships.
That convergence is turning CRM from a front-office productivity layer into an increasingly attractive target.
Modern financial CRM environments now aggregate personally identifiable information (PII), transaction histories, customer communications and AI-generated customer insights among other data points. These platforms increasingly connect directly into core banking systems, cloud infrastructure, customer service environments, compliance tooling and third-party AI models.
The IMF identifies this growing interconnectedness as a source of systemic cyber risk, because advanced AI models can dramatically reduce the time and cost needed to identify and exploit vulnerabilities.
And the risk goes beyond the financial sector, which shares digital foundations with energy, telecoms and public services. AI‑assisted attacks can propagate across sectors that rely on the same infrastructure.
“Confidence effects, payment disruptions, liquidity strains, and fire‑sale dynamics could follow if multiple institutions are affected simultaneously,” the IMF warned. “For financial authorities, the question is whether the system is prepared to absorb cyber incidents without destabilizing core financial functions.”
AI Moves Into Finance’s Operational Backbone
The expansion of AI inside financial services is changing how banks run core processes.




