South Korea Investigates Possible AI Role in Banking Cyberattacks

South Korean authorities have launched an investigation into a series of cyberattacks targeting financial institutions after President Lee Jae Myung warned that artificial intelligence may have been used to carry out some of the hacks.

More than seven financial institutions, including major banks, have reported customer data breaches over the past week, according to South Korean authorities.

The Financial Services Commission said more than 68,000 people have been affected by the incidents.

“There are signs that artificial intelligence was used in some hacking attacks, causing considerable concern and anxiety among the public,” Lee told a cabinet meeting on Tuesday.

The president warned that advances in AI could allow people with limited technical expertise to conduct increasingly sophisticated cyberattacks.

“We have now reached a point where AI can make (hacking) easy for even those without special skills,” he said.

Major banks among those affected

Shinhan Bank, one of the financial institutions targeted, said information connected to loan applications belonging to about 25,000 customers had been leaked.

The exposed information reportedly included customers’ names, telephone numbers and annual income.

Lee said the increasing sophistication of AI-powered hacking posed a threat to governments, businesses and the wider public.

“With advances in AI technology, hacking methods are becoming increasingly sophisticated, while the scope of the damage is spreading across all areas on a scale that is difficult to compare with the past,” he said.

He urged government agencies, companies and the public to remain vigilant.

Police said Tuesday that they had opened an investigation following the president’s directive.

Officials examine possible use of Chinese AI tool

A South Korean government official told AFP that it was “highly likely” that Artex AI, an open-source security testing tool believed to be a Chinese AI system, was used in the attacks.

However, officials stressed that the possible use of the tool does not establish that Chinese hackers were responsible.

Park Sang-won, head of the Financial Security Institute, said investigators could not determine an attacker’s nationality solely from an internet protocol address.

“Attackers can move between and use IP addresses in multiple locations, so it is impossible to identify an attacker based on an IP address alone,” Park said.

The investigation will therefore need to establish how the attacks were conducted, what tools were used and who was behind them.

The incidents come amid growing international concern over the ability of advanced AI systems to identify software vulnerabilities and potentially assist cybercriminals in attacking banks, corporations and government infrastructure.

Japan also reports major data breaches

The cyber incidents have not been limited to South Korea.

In Japan, at least three companies have reported data leaks in recent days, while 10 others said their information may have been compromised after unauthorised access to servers and websites.

Car-sharing company Times Car said data linked to about 6.6 million accounts had been leaked.

A Japanese barbecue restaurant chain also reported that personal information belonging to more than 10 million users of its app had been exposed.

The incidents across East Asia highlight growing concerns over the scale and sophistication of cyberattacks as businesses and governments increasingly rely on digital infrastructure.

South Korean authorities are now working to determine whether AI played a direct role in the recent attacks and whether the technology enabled attackers to carry out operations that would previously have required more specialised expertise.

Leave a reply

Follow
Search
Loading

Signing-in 3 seconds...

Signing-up 3 seconds...