See why 4thWay now accepts ethical ads.
What P2P Lending Providers Are Doing About Greater Cybersecurity Risks From AI
While 4thWay’s specialists have an exceptionally deep understanding of lending risks (such as risks from bad debts) and that is where their greatest strength lies, no-one here doing any 4thWay research ignores cyber risks as well.
The team here obtains soft searches of website security to look for obvious weaknesses, such as a lack of website monitoring or firewalls to prevent malicious actors, as welll as to look for signs that the technology the P2P lending providers’ websites are based on is outdated and with a higher risk of being hacked.
We also routinely ask questions and probe further about various aspects of cyber defences that the providers have to protect data, their websites, their apps and of course lenders’ money.
And by now 4thWay’s specialists write up, reassess and maintain a section on cybersecurity in our reviews into online lending providers. (At least in most of the reviews, with a few more still be to written up.)
Obviously, none of this is the same as 4thWay hiring security experts to run penetration tests (attempting to hack in to find weaknesses), but it has still sometimes exposed areas of improvement for providers or obvious areas of weakness.
Now that AI has arrived, there’s more to think about and stay on top of
Of increasing concern is how AI is making it easier for criminals to find more weaknesses and exploit them quickly.
4thWay is beginning to follow this evolution of AI now, and we are going to endeavour to establish what is best practice and what is required across the industry to keep on top of threats.
To kick things off, we asked P2P lending and other online lending providers about this at the end of June.
We asked providers: “Have you looked to step up your website security, data security, IT security and software security due to the growing surge in AI helping hackers find and exploit weaknesses more swiftly? Could you describe a little?”
We’ve given them plenty of time to answer, so here is what we got back:
AxiaFunder’s response
To date we have focused on password protecting claim-related documents; restricting particular files to specific servers; and ensuring we are only using GDPR-compliant AI LLMs. We are looking at getting cyber insurance but have not lined it up yet.
In Q2 we rolled out 2 factor authentication for investors’ accounts. We rely on ShareIn to manage the investor facing website and they have done a good job keeping it cyber secure.
More on cybersecurity in the AxiaFunder Review.
CapitalRise’s response
Cyber and data security remain a key focus for us, particularly as AI is increasing the sophistication and scale of cyber threats.
Some of the steps we have taken include:
- Annual independent penetration testing of our systems. The latest test was completed in January 2026, and we changed providers during the last year to ensure our testing approach reflects the current threat landscape. Testing covers areas such as application security, infrastructure, access controls, roles and permissions.
- Enhanced email security and phishing protections, including measures to help detect malicious links and increasingly sophisticated social engineering attacks.
- Regular reviews of our technology platforms, third-party providers and software components (plugins) to identify risks, apply updates and maintain security standards.
- Ongoing investment in our cyber security controls and processes, alongside formal data and cyber security policies.
- We are also currently evaluating additional threat monitoring capabilities to further improve proactive identification of vulnerabilities within our environment.
As threats continue to evolve, we regularly review and strengthen our security approach to ensure it remains appropriate for the business and our customers.
CapitalStackers’s response
We’re alert to the risk and proactively keep our technology aligned with the latest advancements associated with AI. We view AI as a double-edged sword and seek to manage it accordingly.
Defensively, we have leveraged AI and automation in our internal development to detect system bugs and deploy enhancements at a scale we could not have achieved previously as a very small CapitalStackers team. Conversely, we are highly cautious regarding the use of Large Language Models (LLMs) and risks of feeding/sharing sensitive information to public LLMs. We enforce strict policies to ensure no proprietary code or sensitive business information is ever shared with publicly accessible AI platforms.
To date, we have not experienced an increased risk profile, largely thanks to the robust firewalls and containerization technology backing our Azure cloud infrastructure. However, we recognize the evolving threat landscape and are continuously monitoring our cloud security posture as AI integration deepens.
We are living in interestingly scary times as perfectly illustrated by the recent press report of Open AI’s model going rogue, hacking into and severely damaging at least one SME business.
More on cybersecurity in the CapitalStackers Review.
Crowd2Fund’s response
We have an internal IT team backed by an external developer team for support. We conduct all necessary security updates and monitor our logs. We have always done so. At various instances we have conducted external and independent testing.
Over the last several months we have continued to strengthen our security posture in response to the evolving cyber threat landscape, including the increased use of AI-assisted tools by attackers to identify vulnerabilities, automate reconnaissance and accelerate phishing and credential-based attacks.
We migrated from G-Suite to Microsoft in Jan of this year for security reasons.
And now use a trusted 3rd party to manage our tech.
We have been implementing continued security improvements over the last months. As an example conditional access policies etc.
In short, I have always taken cyber security very seriously and AI is just another layer to think about.
Biggest threats usually come from internal vulnerabilities in my experience so doing the basics well is very important.
Toby later added the following, which I should probably pick from and then use the rest elsewhere:
Our approach focuses on a layered security model rather than relying on any single control. From an identity and access perspective, we have implemented Microsoft Conditional Access policies that enforce Multi-Factor Authentication (MFA), block legacy authentication protocols, restrict access from unsupported device types, and provide enhanced access control through location and device-based security policies. These controls significantly reduce the risk of account compromise.
In addition to identity protection, users connect through NordLayer secure VPN services, providing encrypted connectivity and allowing trusted network controls to be applied. End-user devices are protected by DNSFilter, which helps prevent access to known malicious websites, phishing domains and command-and-control infrastructure before a connection can be established. Devices are also protected by SentinelOne Endpoint Detection and Response (EDR), providing advanced threat detection, behavioural analysis, ransomware protection and automated containment capabilities should malicious activity be identified.
Key security benefits of this approach include:
- Reduced risk of compromised credentials being successfully used through mandatory MFA.
- Prevention of legacy authentication attacks that bypass modern security controls.
- Protection against phishing, malicious websites and DNS-based threats through DNSFilter.
- Advanced endpoint protection and ransomware defence through SentinelOne.
- Encrypted remote connectivity through NordLayer VPN.
- Restriction of access to trusted users, trusted devices and approved locations.
- Improved visibility and control over how company data is accessed and from where.
FOLK2FOLK’s response
FOLK2FOLK acknowledged receipt of the questions but did not respond in time.
Read about cybersecurity in the FOLK2FOLK Review.
HNW Lending’s response
It’s always been a priority and we’ve never had a breach so it’s not a matter of stepping up but keeping going with the previous high level of alertness.
More on cybersecurity in the HNW Lending Review.
Housemartin’s response
Housemartin did not respond to requests for information.
Read about cybersecurity in the Housemartin Review.
Invest & Fund’s response
Invest & Fund did not respond to requests for information.
Read about cybersecurity in the Invest & Fund Review.
Lande’s response
As the cybersecurity landscape continues to evolve, including the growing use of AI to identify and exploit vulnerabilities, we continuously review and strengthen our security measures. As a regulated crowdfunding platform, information security remains one of our highest priorities.
Access to our internal systems is protected with multi-factor authentication (2FA), while access to sensitive systems and investor data is strictly limited to authorized personnel through controlled access processes. Investor data is protected using industry-standard security practices.
Our infrastructure is continuously monitored to detect unusual activity, potential service disruptions, and malicious traffic. We also employ protective measures against threats such as DDoS attacks and other unauthorized access attempts.
In addition, we perform regular security reviews, keep our software and infrastructure up to date with the latest security patches, continuously assess emerging risks, and maintain regular backups to support business continuity and disaster recovery. We also periodically verify and test our backup restoration procedures to help ensure data can be recovered when needed.
These measures help safeguard our platform’s operations and protect our investors’ personal and financial information.
Lendwise’s response
We have an internal IT team backed by an external developer team for support. We conduct all necessary security updates and monitor our logs. We have always done so. At various instances we have conducted external and independent testing.
More on cybersecurity in the Lendwise Review.
Loanpad’s response
Loanpad’s answer below was mostly through an interview with the chief technology officer:
[The risks are] shifting so fast – we have to keep our ears to the ground.
Perhaps at the outset, it is worth flagging that we are ISO 27001 certified which is the leader in certification for data security. The logo is on our website and similar ones you’ll see in banks etc.
These AI agents are not finding for a platform like ours [that] suddenly they can walk through every firewall.” [Loanpad developed that point by saying to 4thWay that AI’s strength in any malicious act is that it can more quickly and independently look for and exploit weaknesses.]
We already use AI as a coding tool and part of that is putting it against security systems and saying “Is this secure?”
There is a difference between defensive and adversarial. We have external penetration testers tasked with this. We can’t check our own homework. They are tooling themselves up with the latest AI tech.
Penetration testers have always used automated tools. So where that is upgraded to is AI doing it in an automated manner. [Although he added that this still has to be alongside manual tests/human testers.]
You have an attack surface in the cybersecurity space. So if I have 10 services on the internet, I have a comparably large surface. Because we are fanatic about keeping things simple, we have one API endpoint that needs authorised access, and all the rest branches out from there. It can only go through via a content distribution network that has a firewall on it and through the main ports with SSL and encryption.
So the gateway that AI has to go through is very well defined. It only has a very small and narrow gap to try and start to find vulnerabilities.
[So] if we write code wrong the usual thing of breaking in to a network then moving sideways to find secrets – we don’t have that same sort of ability for AI to attack us by those methods or a lot of other methods.
We don’t host servers in-house. It’s cloud based. So we have reduced what AI and any adversary can attack.
More on cybersecurity in the Loanpad Review.
Proplend’s response
We conduct extensive annual pen tests. Also one of our investors is a leading cyber security authority.
Rebuildingsociety’s response
Rebuildingsociety did not respond to requests for information.
Somo’s response
Advances in AI are allowing cybercriminals to identify vulnerabilities and develop increasingly sophisticated attacks more quickly. Cybersecurity is therefore treated as an ongoing operational priority across our investor platform, software, infrastructure and data practices.
Our investor platform is custom-built and maintained in-house by a dedicated senior developer who has detailed knowledge of the entire codebase and is available 24/7 to respond to urgent technical issues. This direct ownership gives Somo close oversight of the platform and allows potential issues to be investigated and addressed quickly, without relying entirely on an external software provider or a collection of generic third-party plugins.
The platform is regularly scanned using updated vulnerability-assessment tools, and security best practice is incorporated into the development of new features and functionality. Multi-factor authentication is also used for certain sensitive actions within investor accounts.
We reduce data-related risk by limiting the information we retain as far as possible while continuing to meet our legal and regulatory obligations. We also maintain backup and disaster-recovery procedures designed to enable services to be restored quickly in the event of disruption.
Further work is underway as part of a planned server migration, including additional server-hardening measures. We are also planning the introduction of an AI-based intrusion-detection system to help identify unusual activity and emerging threats more quickly.
We recognise that no organisation can eliminate cyber risk entirely, particularly as threats continue to evolve. Our focus is therefore on maintaining direct oversight of our systems, reducing unnecessary exposure, identifying potential weaknesses early and continually strengthening our ability to prevent, detect and respond to incidents.
Read about cybersecurity in the Somo Review.
Unbolted’s response
The best protection is still regular upgrades via our hosting providers on the base infrastructure and ourselves on the application infrastructure. We also use some of these AI tools to identify potential weaknesses. But more broadly, we don’t store the sort of information that many hackers try to extract (card details for example).
Having said that, this is definitely an increased risk going forward – I can see a world with autonomous hacker AI agents very soon.
More on cybersecurity in the Unbolted Review.
To get the best lending results, compare all P2P lending and IFISA providers that have gone through 4thWay’s rigorous assessments.
Independent opinion: 4thWay will help you to identify your options and narrow down your choices. We suggest what you could do, but we won't tell you what to do or where to lend; the decision is yours. We are responsible for the accuracy and quality of the information we provide, but not for any decision you make based on it. The material is for general information and education purposes only.
We are not financial, legal or tax advisors, which means that we don't offer advice or recommendations based on your circumstances and goals.
The opinions expressed are those of the author(s) and not held by 4thWay. 4thWay is not regulated by ESMA or the FCA. All the specialists and researchers who conduct research and write articles for 4thWay are subject to 4thWay's Editorial Code of Practice. For more, please see 4thWay's terms and conditions.
*Commission, fees and impartial research: our service is free to you. 4thWay shows dozens of P2P lending accounts in our accurate comparison tables and we add new ones as they make it through our listing process. We receive compensation from AxiaFunder, CapitalRise, CapitalStackers, HNW Lending, Housemartin, Lande, Loanpad, Proplend and Somo, and other P2P lending companies not mentioned above either when you click through from our website and open accounts with them, or when you make an investment, or to cover the costs of conducting our calculated stress tests and ratings assessments. We vigorously ensure that this doesn't affect our editorial independence. Read How we earn money fairly with your help.