Wednesday, September 30, 2026 | 12:25 AM ISTहिंदी में पढें
Business Standard
Notification Icon
userprofile IconSearch

AI slashes cost of launching cyberattack to under $3, says Mastercard

Technology, public and financial sectors account for 44 per cent of cyberattacks in India, while firms are strengthening governance as AI agents pose new risks

artificial intelligence, nukes

Even as AI models make it cheaper to mount cyberattacks, models are being utilised to strengthen cyber defence

Ajinkya KawaleSubrata Panda Mumbai

Listen to This Article

Wider access to large language models and their rapid development have brought the cost of turning a known software flaw into a working cyberattack down to less than $3, according to a report by global card network Mastercard.
 
This comes at a time when the technology, public and financial sectors together account for about 44 per cent of cyberattacks in India.
 
Business systems and customers' personal and financial information make up over half of all assets attacked, according to the report.
 
“Frontier models today are almost 90 times faster in identifying the zero-day vulnerabilities as compared to last day and age models,” said Reshmi Ghosh, senior vice-president, services, Mastercard.
 
 
Even as AI models make it cheaper to mount cyberattacks, models are being utilised to strengthen cyber defence. However, defence still depends on improving execution, the report added.
 
It said that 86 per cent of AI-planted vulnerabilities can now be identified, leading to an improvement in scam and impersonation detection.
 
In the financial year 2025 (FY25), frauds worth ₹36,000 crore were reported to the Reserve Bank of India (RBI).
 
The focus on cybersecurity also comes as AI agents, software that can act and transact on a user's behalf, create new risks for platforms and businesses, with few rules yet on how to verify an agent's identity or who is liable when one goes wrong.
 
Companies such as Visa, Mastercard, Google, and in India, NPCI (National Payments Corporation of India), are defining protocols or rule-based guardrails for agents and their verification.
 
“The protocols that are coming up and then converging across are on discoverability, agent-to-agent communication, checkout, among others. Where the universe is still kind of discussing is the identity and verification of the agent,” Ghosh explained.
 
She added that the reason agentic flows were gradually being opened up, rather than through a mass rollout, was that firms were going slow as agents have the tendency to go rogue.
 
“Governance is becoming increasingly important. One of the reasons to do that is how do you open the system up very slowly, because it has to be very well-governed and has to be done as per the risk,” she added.

Don't miss the most important news and views of the day. Get them on our Telegram channel

First Published: Sep 30 2026 | 12:14 AM IST