Cyberattacks on South Korean banks affected over 68,000 people, with Shinhan Bank reporting 25,000 customers had data exposed. President Lee Jae Myung said, "There are signs that artificial intelligence was used in some hacking attacks." Authorities are investigating if AI made these breaches easier, as banks face rising third-party risks.
A wave of cyberattacks on South Korean financial institutions is raising a new question for banks around the world: could artificial intelligence make sophisticated cyberattacks faster, cheaper and easier to replicate? More than 68,000 people have been affected by recent breaches in South Korea, with President Lee Jae Myung warning that AI may have been used in some of the attacks.
"There are signs that artificial intelligence was used in some hacking attacks, causing considerable concern and anxiety among the public," Lee told a cabinet meeting on Tuesday.
"We have now reached a point where AI can make (hacking) easy for even those without special skills," he said.
Police have launched an investigation, but authorities have not established that AI definitively carried out the attacks.
Shinhan Bank said information linked to loan applications belonging to about 25,000 customers had been exposed. The data included names, telephone numbers and annual income.
A government official told AFP it was "highly likely" that Artex AI, an open-source security testing tool believed to be a Chinese AI system, was used in the attacks. That does not establish who carried them out.
Customer information was exposed at several firms, including:
A sophisticated cyberattack traditionally requires people with different skills to identify vulnerabilities, develop malicious code, create phishing messages, steal credentials and analyse stolen data.
AI can potentially speed up several of those tasks.
It could help attackers search for weaknesses, generate convincing phishing messages, analyse information obtained during a breach or modify an attack as a target's defences change.
That could reduce the amount of human labour required for an attack. A smaller group could potentially attempt attacks against more organisations in less time.
Banks rely on a vast network of third-party systems for services such as loan processing, customer verification, payments, cloud infrastructure and software support. These systems allow banks to offer services at scale without building every function themselves, but they also create additional entry points for attackers.
For hackers, targeting a weaker third-party system can be easier than breaching a bank's heavily protected core network. Once inside a connected system, attackers may be able to access or extract customer information without directly penetrating the bank's central infrastructure.
That means an attacker does not necessarily have to break directly into a bank's core infrastructure to cause damage.
A weakness in a vendor or another connected system could provide an entry point. If attackers discover a technique that works against one organisation, AI could potentially help them adapt it for other targets.
That does not mean one attack can simply be copied across every bank. Different institutions use different systems and security controls. But automation could make adapting attacks less time-consuming.
"With advances in AI technology, hacking methods are becoming increasingly sophisticated, while the scope of the damage is spreading across all areas on a scale that is difficult to compare with the past," Lee said.
"The government, companies and our society as a whole need to recognise the seriousness of the [current] situation and remain particularly vigilant."
The concern is that techniques developed against financial institutions could eventually be adapted to companies, government agencies or other critical services.
