Lessons From A Bank Hacker
Banks operate in one of the most heavily regulated and security-conscious industries, but that does not make them immune to real-world attack. We pen test and red team financial institutions throughout the year, and this talk focuses on the techniques we see actually work in 2026. We will walk through how professional attackers gain initial access, abuse of identity and trust relationships, move through Windows and cloud environments, and combine technical, social, and physical attack paths to reach meaningful objectives. Just as importantly, we will cover what stopped us, what slowed us down, and the practical controls banks can put in place to make these attacks significantly harder.

Tanner Shinn is a cybersecurity leader with more than 15 years of experience in security engineering, red teaming, penetration testing, and network infrastructure. As Principal Security Engineer at Alias Cybersecurity, he leads advanced security research and offensive security operations, helping organizations identify and address complex security risks. Prior to Alias, Tanner spent nearly a decade at Dell Technologies in senior network engineering and analyst roles. He holds numerous industry certifications across cybersecurity, networking, and enterprise technologies and serves on the Canadian Valley and Francis Tuttle Advisory Committees, supporting cybersecurity education and workforce development.