trilicity

NewsTrading Bots & Algorithms

Why AI-Driven Cyberattacks Are Overwhelming Traditional Trading Infrastructure

Kaspersky's APAC Managing Director Adrian Hia has recast the current threat landscape as a "race against invisibility," arguing that AI-backed attackers now exceed organizational capacity to see, parse, and contain intrusions.

Why AI-Driven Cyberattacks Are Overwhelming Traditional Trading Infrastructure

For operators of algorithmic trading stacks, exchange API pipelines, and automated execution infrastructure, the relevant shift is from perimeter defense to supply-chain and dependency-layer exposure.

Attack surface in numbers

Daily unique malicious file detection rose 7% year-over-year in 2025, reaching 500,000 samples per day according to figures cited by Kaspersky. The higher-leverage vector for quantitative desks is agentic-AI supply-chain exposure: Kaspersky reports identifying over 15,000 malware samples disguised as agentic AI software within the current year. Because agents depend on third-party frameworks, APIs, and plugins, a single compromised upstream dependency cascades laterally across downstream systems — the same architectural topology that underpins modern bot orchestration, signal aggregation, and execution routing.

The Compromise Assessment data quantifies the detection lag. In 31% of analyzed incidents, malicious activity persisted for more than three months. 52% of high-severity compromises surfaced only after 90 days. The oldest incident identified over the last year remained undetected for four years. For infrastructure holding private keys, signing routines, or model inference endpoints, that dwell-time profile converts stealth intrusion into cumulative capital exposure.

Operational implications

The trend set Hia flagged — AI-assisted attacks, cyber sabotage targeting IT/OT environments, and more sophisticated cyberespionage — intersects trading operations at the dependency layer rather than the endpoint. Incidents referenced in the briefing include a logistics disruption at Nichirei Corp and sustained ransomware pressure across India's manufacturing sector; in both cases, operational technology downtime translated directly into revenue loss. The equivalent for an algorithmic desk is downtime of execution venues, market data feeds, or model serving infrastructure.

Hia's framing centers SOC maturity as the discriminating variable. Reactive monitoring extends dwell time; continuous detection with unified telemetry compresses it. For trading systems, the analogous control surface is real-time anomaly detection on API call patterns, withdrawal authorization flows, and dependency version drift across bot stacks.

What to instrument

Three practical entry points for quantitative teams. First, log every dependency hash, not merely version strings, and alert on changes. Second, treat third-party model weights and signal-provider code as supply-chain artifacts requiring provenance verification before deployment. Third, track time-to-detect on internal red-team exercises as a leading indicator of intrusion survivability. The 90-day detection floor in Kaspersky's data is the benchmark to beat.