HackMyIP
← Back to News
2026-07-30 SecurityWeek

Bank of America to Acquire UK Cybersecurity Firm MDSec

RegulationThreat Intel

Bank of America announced on Thursday that it will acquire MDSec Consulting Limited, a UK-based technical information security consultancy headquartered in Macclesfield, England. The deal brings approximately 65 cybersecurity professionals into the Charlotte, North Carolina-based bank and strengthens its existing footprint in northern England, where it already operates a cyber threat operations center in Chester and employs more than 1,400 people. Bank of America chief information security officer Kris Fador said the firm has long admired the "exceptional ability of the MDSec team" and welcomed their integration into the bank's broader security practice.

MDSec co-founder Dominic Chell framed the acquisition as a multiplier for the firm's research-led approach, noting that joining a global financial institution will allow the consultancy to "take that ambition to the next level" in developing offensive and defensive security capabilities. MDSec is well known in the industry for its technical red-team, incident-response, and vulnerability research work, and its absorption into a Tier-1 bank signals a continued shift among major financial institutions toward in-housing elite offensive security talent rather than relying solely on external vendors. The acquisition also means Chell and the firm's specialists will increasingly be focused on protecting Bank of America's own perimeter, where researchers and defenders alike routinely probe for exposed services using tools such as a port scanner and an SSL/TLS checker.

The transaction is expected to close in the fourth quarter of 2026, subject to customary regulatory approvals in both the UK and the United States, though financial terms were not disclosed. The pending review is likely to draw scrutiny from UK regulators given MDSec's work on sensitive government and financial-sector engagements, as well as from US authorities assessing the competitive impact of the consolidation. Organizations monitoring their own external attack surface during this period of consolidation can quickly verify domain ownership and hosting details with a WHOIS lookup.

Industry analysts view the deal as part of a broader pattern of vertical integration in financial cybersecurity, where banks are absorbing boutique consultancies to deepen threat intelligence, accelerate incident response, and close capability gaps exposed by an increasingly hostile threat landscape. For practitioners tracking how these moves reshape the talent market and the supply of advanced security services, the Bank of America–MDSec combination is one of the more notable acquisitions of the year.

Source: SecurityWeek →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →