Hackers attacked banks using AI: data on thousands of customers has been leaked

The South Korean authorities have reported signs that AI tools were used in a series of cyberattacks. Customer data from several financial institutions has been compromised.

0

South Korea is investigating a series of cyberattacks on banks and other financial institutions, during which artificial intelligence tools may have been used. The country’s president, Lee Jae-myung, has spoken of indications that AI was used. Several institutions have suffered leaks of customers’ personal data, and the financial regulator has already linked the attacks to dozens of IP addresses in various countries. However, there is currently no evidence of money being stolen from accounts.

The South Korean President has spoken of a new type of threat

Lee Je-myung raised the issue of the attacks at the government meeting on 6 October. According to him, in some instances there were signs that the hackers had used artificial intelligence models.

The President has instructed that the circumstances of the attacks be established as quickly as possible and that the necessary resources be allocated to minimise the consequences. Meanwhile, the police have launched a large-scale investigation into a series of breaches of commercial banking systems.

The authorities have not yet disclosed the extent to which the AI operated autonomously or exactly what operations it carried out. It is therefore too early to speak of a fully autonomous «hacking of banks by artificial intelligence». However, the investigation already has specific technical leads.

Data belonging to 25,000 customers has been leaked from Shinhan Bank

One of the worst affected was Shinhan Bank. The bank reported a data breach affecting approximately 25,000 customers. The compromised data included names, telephone numbers and information on annual income.

Hana Bank has confirmed a data breach affecting 89 customers. KB Kookmin Bank, Woori Bank and NH Nonghyup Bank were also targeted. According to Yonhap, the latter two institutions were able to block unauthorised access before the data breach occurred.

The Financial Times reports that, in total, the incidents affected at least seven financial firms. In particular, the data of around 40,000 customers was compromised at Yegaram Savings Bank, and that of a further 2,200 corporate customers at Welcome Savings Bank.

The trail leads to the ARTEX AI tool

The most interesting detail was uncovered during an analysis of the infrastructure that could have been used to attack Shinhan Bank. Traces were found on one of the servers ARTEX AI — an open-source tool based on a large language model, designed for the automated testing of systems for vulnerabilities.

Such systems are capable of automatically detecting vulnerabilities, to map out a possible route of infiltration and carry out some of the operations that previously required constant human involvement.

This does not yet prove that ARTEX was directly responsible for the breach. Investigators have merely identified signs of its presence on infrastructure linked to the attack. Nor is there any reason to automatically link the attack to China. ARTEX is distributed as an open-source tool and can be used from any country.

The regulator identified 28 IP addresses in 12 countries

South Korea’s Financial Supervisory Service has established 28 IP addresses, which may have been used during the attacks. They are located in the US, Japan and ten other countries. It has not yet been possible to determine the exact geographical origins of some of the traffic — the attackers may have used relay servers or other infrastructure to conceal their location.

The addresses obtained were passed on to financial companies so that they could block suspicious traffic and check their own systems. South Korean banks are currently carrying out urgent security audits, and the authorities have set up a round-the-clock response system to deal with new attacks.

AI is changing the very nature of cyberattacks

Before the advent of modern AI agents The automation of hacking operations has been around for a long time. However, new systems can combine several stages at once: analysing the system, searching for vulnerabilities, generating commands and adapting subsequent actions depending on the outcome.

Lee Je-myung called for the creation of a cyber defence system tailored not to the previous generation of attacks, but to «the AI era».

The incident involving the Korean banks does not yet provide grounds for talking about autonomous AI that independently «decided to hack a bank». However, it does highlight another trend: tools capable of automating part of a complex cyberattack can already be used against real-world financial infrastructure.

WRITE A REPLY

enter your comment!
enter your name here