Cybersecurity M&A Shows Banks Preparing For Machine-Identity Risk
PYMNTS reported that cybersecurity acquisitions are concentrating on AI security, machine identities, browsers, industrial systems and fraud signals as the enterprise attack surface expands.

Cybersecurity buyers are spending on the attack surface that AI is creating.
PYMNTS reported more than 215 mergers and acquisitions in the first half of the year, worth above one hundred billion dollars, with deals clustering around machine identities, browsers, industrial systems and fraud signals.
Acquisition Wave
The deal flow reflects a workplace where employees are no longer the only actors with access.
AI agents, applications and machines can now read data, execute workflows and communicate across cloud services, making identity and context central to deciding whether an action should be trusted.
Buyers are responding by joining identity, network, application, behavioral and operational data.
The goal is to see who or what is acting, what the action touches and whether it signals fraud, unauthorized automation or a threat to physical operations.
Identity And AI Targets
AI security is already shaping transactions.
Databricks agreed to acquire Panther Labs for its security-lakehouse strategy, Rubrik bought Strata to preserve authentication during cyber disruptions, and Cisco’s WideField deal closed July 31 to connect identity and session data with Splunk analytics.
The logic is simple: AI agents need permissions, and every permission creates a machine identity that attackers can abuse.
Acquirers are buying controls for those identities before autonomous software becomes routine inside enterprise workflows.
Payments Fraud Controls
Payments provide the clearest commercial test.
Visa’s planned $2.4 billion acquisition of BioCatch, announced Aug. 3, adds behavioral fraud detection used by more than 350 banks in 21 countries.
The system evaluates application, device and network signals, including keystrokes and device handling, to distinguish legitimate users from fraudsters.
The 2025 “State of Fraud and Financial Crime in the United States,” a PYMNTS Intelligence report produced with Block, found that 68% of financial institutions increased fraud-detection budgets year over year.
It also found that 46% reported increasingly sophisticated schemes, up from 35% a year earlier.
Another PYMNTS Intelligence report, “Payment Protection: Why Firms Still Aren’t Real-Time Ready,” produced with Plaid, found that 57% of firms in payment-heavy industries face more fraud.
Browser And Industrial Reach
Security spending is also moving closer to browsers and physical operations.
Akamai completed its LayerX acquisition in July for about $205 million, while CrowdStrike announced a $420 million deal for Seraphic.
Both transactions push controls into the web interfaces and SaaS applications where employees increasingly handle corporate information.
Industrial systems extend the same problem beyond office software.
Security platforms need visibility into assets, installed software, communications and supply-chain vulnerabilities before a compromised identity or automated action becomes an operational disruption.
The acquisition wave is therefore drawing the boundaries of the next security platform.
The winners will be the companies that can connect identity and behavior quickly enough to judge an action before it becomes a breach or a fraudulent payment.




















