Symbolic imageSouth Korea probes AI use in bank hacks after data exposed at seven firms
President Lee Jae Myung said on Tuesday there are signs AI models were used in recent hacks on South Korean banks. Police have opened a full investigation.
At a cabinet meeting on Tuesday, 6 October, Lee said hacks over the past week had exposed user data at seven financial firms, with evidence of AI use in some. No stolen funds have been reported. Moon Jong-hyun, head of Genians Security Center, said on Friday that evidence suggested Artex, a Chinese-language, open-source AI tool for finding and testing system vulnerabilities, was used in some attacks. One official told the Financial Times it feels like "a completely new kind of crisis" but could happen anywhere.
Third-party systems targeted
The hackers appear to have gone after less secure third-party systems rather than core payment networks. In one case an attacker bypassed identity checks on a loan broker portal, exposing about 25,000 Shinhan Bank customers; about 40,000 Yegaram Savings Bank customers and 2,200 Welcome Savings Bank corporate clients were also affected. Similar IP addresses suggest one attacker may be behind at least some of the incidents.
Authorities respond
Financial Services Commission chair Lee Eog-weon called on Sunday for "the highest level of vigilance" and for defending "against AI attacks with AI". The science ministry and its cyber security agency run a 24-hour emergency response and have asked cloud providers to block suspect overseas IP addresses.