DATANEWS

Bank of America to Acquire Cybersecurity Firm MDSec

Reuters · 2026-07-30

Bank of America plans to acquire UK-based MDSec Consulting, bringing offensive-security expertise inside the bank as financial institutions confront ransomware, fraud and AI-assisted attacks.

Why it matters: Financial institutions are moving from buying periodic security advice to owning offensive-security capability inside the enterprise.

Bank of America plans to acquire British cybersecurity specialist MDSec Consulting as financial institutions increase investment in defenses against ransomware, fraud and AI-assisted attacks.

MDSec is based in Macclesfield, England, and employs roughly 65 cybersecurity professionals. The firm's work includes security consulting and offensive testing designed to identify weaknesses before attackers exploit them.

The transaction is expected to close in the fourth quarter of 2026, subject to regulatory approval. Financial terms were not disclosed.

The deal will expand Bank of America's internal cybersecurity capabilities and complement its existing cyber-threat operations presence in Chester.

The strategic signal is larger than the transaction size. Large financial institutions have traditionally relied heavily on outside security firms for offensive testing and specialist assessments. Bringing that expertise in-house may allow Bank of America to run more continuous testing and respond faster as threat activity changes.

Banks are especially exposed to AI-enabled fraud, including convincing phishing messages, synthetic identities, voice cloning and automated vulnerability discovery. Owning specialist expertise can shorten the distance between threat discovery, remediation and executive accountability.

Source and attribution →