作者:CNA
編譯:深潮 TechFlow
深潮導讀:新加坡金管局罕有成立專項工作小組,應對 AI 騙局和量子計算威脅,要求銀行於 2030 年前完成量子加密遷移。當監管機構開始為 5-10 年後的技術風險制定時間表,說明傳統金融安全體系正在遭遇代際危機。
新加坡金融管理局(MAS)於週二宣布,已與新加坡銀行公會(ABS)聯合成立工作小組,以應對人工智慧和量子計算對金融機構帶來的網路安全與詐騙風險。

圖:新加坡金融區高樓林立。來源:Channel News Asia。
Financial Supervisory Commission Director Hsieh Te-chun stated at the press conference that the task force will focus on enhancing financial institutions' professional capabilities in using AI for cybersecurity, testing advanced tools, and developing industry guidelines and new countermeasures for AI-driven threats.
Besides AI, Hsieh Teh-chun also pointed out that quantum computing technology poses a "significant risk" to the data security and communications of financial institutions. Although the technology is still in its early stages of development, the HKMA will release a set of "regulatory expectations" later this year to establish a phased timeline for financial institutions to address quantum security issues.
「我們的目標是讓金融機構在本世紀末之前實現量子安全,」他說。
新型威脅與挑戰
金管局與銀行公會在聯合聲明中表示,成立「AI 驅動網絡與技術風險工作組」(ACT)是為了應對前沿 AI 模型帶來的新兴風險。該工作組自今年 5 月起開始運作。
工作小組成員包括金管局以及星展銀行、華僑銀行、大華銀行、新加坡交易所、NETS 和銀行電腦服務公司的高級技術與網絡安全負責人。
金管局與銀行公會表示,工作小組將促進行業分享 AI 網絡安全用例和經驗,提升網絡防禦知識,並強化金融機構的網絡安全態勢。
The Chairman of the Banking Association, Wang Aiwen, said: "AI is reshaping the landscape of cyber threats, and the financial industry must continue to work together to maintain resilience."
謝德俊指出,AI 使網絡釣魚詐騙能夠「規模化」地實現個性化和說服力。數位銀行交易中的摩擦機制仍有助於阻撓詐騙者,但銀行必須利用 AI 並強化控制措施,以更好地防禦日趨複雜的手法。
金管局將審查銀行提升欺詐檢測模型有效性的努力,包括其 AI 使用水平。
金管局正與政府科技局、警方及五家銀行合作,測試基於跨行和公私部門數據訓練的 AI 模型能否提升詐騙交易的整體檢測能力,測試結果預計於明年出爐。
Xie Dejun also stated that advanced AI models can identify and exploit system vulnerabilities, posing a threat to the cybersecurity defenses of financial institutions.
Advanced AI models can discover more vulnerabilities and shorten the time from discovery to exploitation. “These factors collectively significantly compress the window for patching, testing, and remediation.”
在今年 4 月,金管局發佈公告,呼籲金融機構強化網絡防禦;7 月又要求關鍵金融機構對面向互聯網的關鍵系統進行 AI 輔助的「紅隊」測試,即使用先進 AI 模型識別潛在攻擊路徑。
這些要求即將進一步升級。金管局將發布監管預期,要求關鍵金融機構制定並提交全面評估和行動計劃,以強化對 AI 驅動網絡威脅的防禦能力。
這些計劃將涵蓋金融機構大規模檢測和修補漏洞、在實施前測試系統變更,以及在發生中斷時備份、恢復和重啟關鍵系統和服務的能力。
量子計算風險
Xie Dejun stated that quantum computing poses a "significant risk" to the data security and communications used by financial institutions in the medium term.
專家估計,量子計算可能在 5 至 10 年內破解現有加密技術。他表示,向量子安全實踐的過渡需要時間。
「現在做認真準備絕對不算太早,」他說。
關於今年晚些時候發布的監管預期,謝德俊表示金管局將為金融機構設定漸進式時間表:建立加密資產清單、制定脆弱資產向量子安全方案遷移的優先級,並建立技術能力和治理框架以支持量子安全遷移。
過去幾年,金管局已開始為量子安全金融行業奠定基礎,例如於 2024 年向金融機構發布過渡措施建議,並與行業及國際夥伴就加密技術方案開展技術工作。
In addition, Xie Dejun stated that Singapore has implemented significant measures and made notable progress in enhancing the resilience of digital financial services against fraud, operational disruptions, and cybersecurity threats.
例如,銀行推出了「鎖錢」功能,可將資金鎖定為無法數字轉賬的狀態。截至 2026 年 5 月,該功能保護的資金達到 470 億新元,較一年前翻倍。
新加坡 2025 年的詐騙案件數量和損失金額均有所下降。
金管局亦一直與金融機構合作,提升風險管理框架的有效性,並增強零售支付的韌性。
自去年 8 月起,在銀行系統中斷期間,非接觸式 NETS 借記支付可在一定額度內繼續使用。金管局還在與主要銀行合作,推出能在系統中斷期間繼續支付和轉賬的功能。
