South Korea Says AI Helped Hackers Break Into Banks

AI cyberattacks

South Korea has reportedly seen evidence of artificial intelligence involvement in recent cyberattacks on banks.

    Get the Full Story

    Complete the form to unlock this article and enjoy unlimited free access to all PYMNTS content — no additional logins required.

    Subscribe to our daily newsletter, PYMNTS Today.

    By completing this form, you agree to receive marketing communications from PYMNTS and to the sharing of your information with our sponsor, if applicable, in accordance with our Privacy Policy and Terms and Conditions.

    As the Financial Times (FT) reported, President Lee Jae Myung said on Tuesday (Oct. 6) that hacks had revealed user data at seven financial firms, with indications of AI use in some of these incidents “causing considerable public concern and anxiety.”

    According to the report, the hackers seem to have gone after less secure systems used by third parties, instead of the banks’ core payment networks. In one instance, a hacker bypassed identity checks on a portal where loan brokers monitored customers’ applications, exposing the details of roughly 25,000 Shinhan Bank customers.

    While no money has been reported stolen, one official with knowledge of the situation described it as “a completely new kind of crisis,” the report added.

    We’d love to be your preferred source for news.

    Please add us to your preferred sources list so our news, data and interviews show up in your feed. Thanks!

    “Generative AI was used to identify vulnerabilities and launch an attack. It’s not that South Korea has weak cybersecurity— this sort of thing could happen anywhere.”

    The FT added comments from Moon Jong-hyun, head of Genians Security Center, who said last week that it seems as if Artex — a Chinese-language, open-source tool that uses AI to spot and test computer system vulnerabilities — had been employed in some of the attacks.

    In a LinkedIn post, he likened Artex to a kitchen knife that could either be used by a chef or “as a weapon by a criminal,” the report added.

    Writing about this topic last week, PYMNTS argued that artificial intelligence isn’t creating a new problem for cybersecurity professionals, but industrializing an existing one.

    “Finding vulnerabilities traditionally required expensive human labor,” that report said. “Researchers had to map applications, inspect documentation, understand authentication flows, test configurations, analyze code and repeatedly probe systems for unusual behavior. Artificial intelligence can increasingly perform or accelerate portions of that work.”

    The report cited two recent cases in which security researchers — one 16 years old, the other 19 — were able to uncover vulnerabilities at Microsoft and the Department of Justice. In both cases, the report said, “the cyber vulnerability itself was not something out of science fiction,” although the leverage was, with a single researcher using automation to conduct work that historically would have required significantly greater time, specialized expertise or manpower.

    “Enterprises may spend millions building and protecting increasingly complex technology estates while a teenager with the right AI tools can search them for weaknesses at a fraction of the historical cost,” the report said. “That asymmetry should concern CISOs and CFOs alike.”