What P2P Lending Providers Are Doing About Greater Cybersecurity Risks From AI
While 4thWay’s specialists have an exceptionally deep understanding of lending risks (such as risks from bad debts) and that is where their greatest strength lies, no-one here doing any 4thWay research ignores cyber risks as well.
The team here obtains soft searches of website security to look for obvious weaknesses, such as a lack of website monitoring or firewalls to prevent malicious actors, as welll as to look for signs that the technology the P2P lending providers’ websites are based on is outdated and with a higher risk of being hacked.
We also routinely ask questions and probe further about various aspects of cyber defences that the providers have to protect data, their websites, their apps and of course lenders’ money.
And by now 4thWay’s specialists write up, reassess and maintain a section on cybersecurity in our reviews into online lending providers. (At least in most of the reviews, with a few more still be to written up.)
Obviously, none of this is the same as 4thWay hiring security experts to run penetration tests (attempting to hack in to find weaknesses), but it has still sometimes exposed areas of improvement for providers or obvious areas of weakness.
Now that AI has arrived, there’s more to think about and stay on top of
Of increasing concern is how AI is making it easier for criminals to find more weaknesses and exploit them quickly.
4thWay is beginning to follow this evolution of AI now, and we are going to endeavour to establish what is best practice and what is required across the industry to keep on top of threats.
To kick things off, we asked P2P lending and other online lending providers about this at the end of June.
We asked providers: “Have you looked to step up your website security, data security, IT security and software security due to the growing surge in AI helping hackers find and exploit weaknesses more swiftly? Could you describe a little?”
We’ve given them plenty of time to answer, so here is what we got back:
AxiaFunder’s response
To date we have focused on password protecting claim-related documents; restricting particular files to specific servers; and ensuring we are only using GDPR-compliant AI LLMs. We are looking at getting cyber insurance but have not lined it up yet.
In Q2 we rolled out 2 factor authentication for investors’ accounts. We rely on ShareIn to manage the investor facing website and they have done a good job keeping it cyber secure.
More on cybersecurity in the AxiaFunder Review.
CapitalRise’s response
Cyber and data security remain a key focus for us, particularly as AI is increasing the sophistication and scale of cyber threats.
Some of the steps we have taken include:
- Annual independent penetration testing of our systems. The latest test was completed in January 2026, and we changed providers during the last year to ensure our testing approach reflects the current threat landscape. Testing covers areas such as application security, infrastructure, access controls, roles and permissions.
- Enhanced email security and phishing protections, including measures to help detect malicious links and increasingly sophisticated social engineering attacks.
- Regular reviews of our technology platforms, third-party providers and software components (plugins) to identify risks, apply updates and maintain security standards.
- Ongoing investment in our cyber security controls and processes, alongside formal data and cyber security policies.
- We are also currently evaluating additional threat monitoring capabilities to further improve proactive identification of vulnerabilities within our environment.
As threats continue to evolve, we regularly review and strengthen our security approach to ensure it remains appropriate for the business and our customers.
CapitalStackers’s response
We’re alert to the risk and proactively keep our technology aligned with the latest advancements associated with AI. We view AI as a double-edged sword and seek to manage it accordingly.
Defensively, we have leveraged AI and automation in our internal development to detect system bugs and deploy enhancements at a scale we could not have achieved previously as a very small CapitalStackers team. Conversely, we are highly cautious regarding the use of Large Language Models (LLMs) and risks of feeding/sharing sensitive information to public LLMs. We enforce strict policies to ensure no proprietary code or sensitive business information is ever shared with publicly accessible AI platforms.
To date, we have not experienced an increased risk profile, largely thanks to the robust firewalls and containerization technology backing our Azure cloud infrastructure. However, we recognize the evolving threat landscape and are continuously monitoring our cloud security posture as AI integration deepens.
We are living in interestingly scary times as perfectly illustrated by the recent press report of Open AI’s model going rogue, hacking into and severely damaging at least one SME business.
More on cybersecurity in the CapitalStackers Review.
Crowd2Fund’s response
We have an internal IT team backed by an external developer team for support. We conduct all necessary security updates and monitor our logs. We have always done so. At various instances we have conducted external and independent testing.
Over the last several months we have continued to strengthen our security posture in response to the evolving cyber threat landscape, including the increased use of AI-assisted tools by attackers to identify vulnerabilities, automate reconnaissance and accelerate phishing and credential-based attacks.
We migrated from G-Suite to Microsoft in Jan of this year for security reasons.
And now use a trusted 3rd party to manage our tech.
We have been implementing continued security improvements over the last months. As an example conditional access policies etc.
In short, I have always taken cyber security very seriously and AI is just another layer to think about.
Biggest threats usually come from internal vulnerabilities in my experience so doing the basics well is very important.
Toby later added the following, which I should probably pick from and then use the rest elsewhere:
Our approach focuses on a layered security model rather than relying on any single control. From an identity and access perspective, we have implemented Microsoft Conditional Access policies that enforce Multi-Factor Authentication (MFA), block legacy authentication protocols, restrict access from unsupported device types, and provide enhanced access control through location and device-based security policies. These controls significantly reduce the risk of account compromise.
In addition to identity protection, users connect through NordLayer secure VPN services, providing encrypted connectivity and allowing trusted network controls to be applied. End-user devices are protected by DNSFilter, which helps prevent access to known malicious websites, phishing domains and command-and-control infrastructure before a connection can be established. Devices are also protected by SentinelOne Endpoint Detection and Response (EDR), providing advanced threat detection, behavioural analysis, ransomware protection and automated containment capabilities should malicious activity be identified.
Key security benefits of this approach include:
- Reduced risk of compromised credentials being successfully used through mandatory MFA.
- Prevention of legacy authentication attacks that bypass modern security controls.
- Protection against phishing, malicious websites and DNS-based threats through DNSFilter.
- Advanced endpoint protection and ransomware defence through SentinelOne.
- Encrypted remote connectivity through NordLayer VPN.
- Restriction of access to trusted users, trusted devices and approved locations.
- Improved visibility and control over how company data is accessed and from where.
FOLK2FOLK’s response
FOLK2FOLK acknowledged receipt of the questions but did not respond in time.
Read about cybersecurity in the FOLK2FOLK Review.
HNW Lending’s response
It’s always been a priority and we’ve never had a breach so it’s not a matter of stepping up but keeping going with the previous high level of alertness.
More on cybersecurity in the HNW Lending Review.
Housemartin’s response
Housemartin did not respond to requests for information.
Read about cybersecurity in the Housemartin Review.
Invest & Fund’s response
Invest & Fund did not respond to requests for information.
Read about cybersecurity in the Invest & Fund Review.
Lande’s response
As the cybersecurity landscape continues to evolve, including the growing use of AI to identify and exploit vulnerabilities, we continuously review and strengthen our security measures. As a regulated crowdfunding platform, information security remains one of our highest priorities.
Access to our internal systems is protected with multi-factor authentication (2FA), while access to sensitive systems and investor data is strictly limited to authorized personnel through controlled access processes. Investor data is protected using industry-standard security practices.
Our infrastructure is continuously monitored to detect unusual activity, potential service disruptions, and malicious traffic. We also employ protective measures against threats such as DDoS attacks and other unauthorized access attempts.
In addition, we perform regular security reviews, keep our software and infrastructure up to date with the latest security patches, continuously assess emerging risks, and maintain regular backups to support business continuity and disaster recovery. We also periodically verify and test our backup restoration procedures to help ensure data can be recovered when needed.
These measures help safeguard our platform’s operations and protect our investors’ personal and financial information.
Lendwise’s response
We have an internal IT team backed by an external developer team for support. We conduct all necessary security updates and monitor our logs. We have always done so. At various instances we have conducted external and independent testing.
More on cybersecurity in the Lendwise Review.
Loanpad’s response
4thWay is due to have a meeting with Loanpad about topics including this, but the meeting mutually needed to be put back so we don’t yet have the answers. Prior to the meeting, they did briefly write:
Perhaps at the outset, it is worth flagging that we are ISO 27001 certified which is the leader in certification for data security. The logo is on our website and similar ones you’ll see in banks etc.
More on cybersecurity in the Loanpad Review.
Proplend’s response
We conduct extensive annual Pen Tests. Also one of our investors is a leading cyber security authority.
Rebuildingsociety’s response
Rebuildingsociety did not respond to requests for information.
Somo’s response
Som acknowledged receipt of the questions but did not arrange answers on time.
Read about cybersecurity in the Somo Review.
Unbolted’s response
The best protection is still regular upgrades via our hosting providers on the base infrastructure and ourselves on the application infrastructure. We also use some of these AI tools to identify potential weaknesses. But more broadly, we don’t store the sort of information that many hackers try to extract (card details for example).
Having said that, this is definitely an increased risk going forward – I can see a world with autonomous hacker AI agents very soon.
More on cybersecurity in the Unbolted Review.
Independent opinion: 4thWay will help you to identify your options and narrow down your choices. We suggest what you could do, but we won't tell you what to do or where to lend; the decision is yours. We are responsible for the accuracy and quality of the information we provide, but not for any decision you make based on it. The material is for general information and education purposes only.
We are not financial, legal or tax advisors, which means that we don't offer advice or recommendations based on your circumstances and goals.
The opinions expressed are those of the author(s) and not held by 4thWay. 4thWay is not regulated by ESMA or the FCA. All the specialists and researchers who conduct research and write articles for 4thWay are subject to 4thWay's Editorial Code of Practice. For more, please see 4thWay's terms and conditions.
*Commission, fees and impartial research: our service is free to you. 4thWay shows dozens of P2P lending accounts in our accurate comparison tables and we add new ones as they make it through our listing process. We receive compensation from AxiaFunder, CapitalRise, CapitalStackers, HNW Lending, Housemartin, Lande, Loanpad, Proplend and Somo, and other P2P lending companies not mentioned above either when you click through from our website and open accounts with them, or when you make an investment, or to cover the costs of conducting our calculated stress tests and ratings assessments. We vigorously ensure that this doesn't affect our editorial independence. Read How we earn money fairly with your help.