In its first acquisition in five years, Bank of America is buying an England-based cybersecurity company, underscoring financial firms' challenges as they seek to protect themselves against cyber threats.
The Charlotte, N.C.-based lender said on Thursday afternoon that it plans to acquire MDSec Consulting Limited, known as MDSec, an information-security specialist based in Macclesfield, England.
Bank of America said it expected to close the deal in the fourth quarter, subject to regulatory approvals. MDSec has 65 cybersecurity professionals, according to a press release. BofA, the second-largest U.S. bank, has some 1,400 employees in the North of England.
A BofA spokeswoman said the terms of the deal weren't disclosed. The acquisition is the bank's first since 2021, when it bought healthcare-payments company AxiaMed for an undisclosed sum.
In a statement, the bank's chief information security officer, Kris Fador, said the firm had "long admired" the MDSec team, and that BofA and its clients "will now further benefit from their work."
The deal reflects how significantly banks and other financial institutions are investing in their cybersecurity capabilities, particularly as nascent artificial intelligence technologies pose threats to clients.
In April, BofA Chief Executive Officer Brian Moynihan told analysts on a conference call to discuss earnings that "our team's job is to benefit" from new technologies such as AI, but that position comes with risks.
"It creates issues about cybersecurity and things like that, that you're reading about in the paper. We take those extremely seriously and invested heavily to do it," Moynihan said, adding that the bank works "to ensure the safety and security of our architecture."
The firm keeps its customers' data "out of the models," he said.
The broader industry is on watch. This week, an executive with the American Bankers Association, the lobbying group, testified before the Senate Special Committee on Aging about the urgency around preventing financial exploitation among older Americans.
"The central point of my testimony is straightforward: generative AI is not replacing traditional scams. It is industrializing them," said Paul Benda, the group's executive vice president for risk, fraud, and cybersecurity. "A criminal can now create a convincing voice, video, photograph, text message, advertisement, or online persona with little technical skill and at very low cost."