MTS Bank Is the First in Russia to Use Graph Neural Networks to Detect Cyberattacks
The algorithms effectively identify hackers who disguise themselves as ordinary users.

Artificial intelligence is reaching a growing number of industries, including cybersecurity, where it is beginning to play an increasingly active role. One reason is that hacking techniques are becoming more sophisticated as well. Today, even detecting that an outside actor has breached a system can be a difficult task.
More Than 90% of Intrusion Attempts Detected
MTS Bank recently announced that it has begun using graph neural networks to detect attacks on its infrastructure. It is the first financial institution in Russia to adopt this type of tool. Bank representatives say its engineers have developed an entire “ensemble” of neural networks that detects more than 90% of hacker lateral-movement scenarios inside the network that remain invisible to conventional security systems.
As noted above, modern attack techniques have advanced to the point where cyberattacks can leave almost no trace. Attackers have learned to closely mimic administrator behavior: they use legitimate accounts, connect through standard protocols during working hours and move only along familiar routes using forgotten access keys. With that kind of camouflage, hackers can remain undetected for months or even years.

Moving to a New Level of Analysis
To detect these threats, MTS Bank turned to graph neural networks. This class of AI analyzes relationships between events rather than individual events in isolation. The system monitors interactions among individual accounts, servers and sessions. It identifies threats by detecting unusual chains of movement through the network.
Five neural networks provide the bank’s digital defense, each with its own specialty. One detects disruptions in behavioral rhythms, another catches movement between network segments, and a third identifies unusual routes. Each can make mistakes on its own; together, they almost never do.

Tested by Ethical Hackers
The pilot was tested for a year. During that time, ethical hackers repeatedly tried to breach the system. It successfully detected 90% of all their movements. In total, the bank conducted 22 penetration tests and one Red Team assessment, with all activity detected during the lateral-movement stage inside the infrastructure.
Meanwhile, the bank stresses that using neural networks does not mean abandoning conventional security tools. Firewalls, antivirus software and monitoring systems will continue to operate as before. The neural networks simply add another layer that can cover their “blind spots.”

Hybrid Defense
“We are not trying to replace existing defenses. We are giving them something they did not have before – the ability to see relationships,” said Ilya Zuev, vice president for information security at MTS Bank.
In fact, the use of graph neural networks in banking has been developing for several years. In 2023, researchers at the Institute of Cybersecurity and Information Protection at Peter the Great St. Petersburg Polytechnic University created a graph neural network model capable of distinguishing suspicious transactions from legitimate ones and fraudsters from legitimate users. The model specifically analyzed patterns that could reveal malicious actors. When filtering transactions, the neural network examined timestamps that helped determine how long a person had been part of the banking environment and which institution served the customer.
By 2025, banks were continuing to expand their use of neural networks for security. Participants at the CNews FORUM Cases event said that, in experiments they conducted, 38% of fraud was detected solely by AI analyzing transactions.
MTS Bank’s experience may point to the beginning of a shift toward new cybersecurity tools. For now, a hybrid approach appears the most effective: conventional defenses are supplemented with AI that can evaluate individual events while also identifying patterns across them. MTS Bank itself plans to gradually scale its technology across its entire infrastructure and further develop the graph-based approach together with other participants in the cybersecurity market.









































