HomeMalware & ThreatsSouth Korea Investigates Potential Use of AI Tool in Bank Customer Data...

South Korea Investigates Potential Use of AI Tool in Bank Customer Data Theft

Published on

spot_img

Investigations Underway in South Korea After Data Breach at Multiple Banks Linked to AI Tool

In a significant cybersecurity incident, South Korea is grappling with the theft of sensitive customer data from several banks, raising alarm bells about the potential use of an artificial intelligence-powered penetration testing tool. This breach is believed to involve personal information from approximately 66,000 individuals and 2,200 corporate accounts across seven financial institutions, as reported by The Korea Herald.

In response to the alarming discovery, President Lee Jae Myung has vowed to conduct a comprehensive investigation. The National Police Agency has swiftly assembled a dedicated task force comprising 28 members to delve into the matter, led by the Cyber Terror Investigation Unit. The urgency of the probes is underscored by the multifaceted nature of the attack, with police collaborating with international law enforcement agencies to track the origin of the breaches. It has been reported that the attacks have been traced to at least 28 different IP addresses situated across a dozen countries, including notable mentions such as Germany, Japan, and the United States. However, investigators caution that the physical location of these servers does not necessarily indicate the perpetrators’ geographical origin, as cybercriminals often exploit legitimate servers to obscure their online trails.

Crucially, investigators have identified indications pointing to the use of a freely available Chinese-language AI penetration testing tool named Artex. This revelation comes from an analysis of HTML file headers from command-and-control servers suspected in the attacks. The header contained a tag identifying the tool, affirming suspicions about its involvement. Moon Jong-hyun, a prominent figure at the South Korean cybersecurity firm Genians, highlighted this discovery in a detailed post on LinkedIn.

Artex, devised by Li Puhua, a cybersecurity engineer known as Autumn, serves as an automation platform utilizing various large language models to facilitate an "AI-powered autonomous penetration testing system." Since its launch on GitHub in July, the tool has been freely accessible to the public. Notably, it gained recognition last September after winning the "Agent+" attack and defense challenge organized by Baidu, a major technology firm in China.

Genians’ Moon elaborated on Artex’s multifaceted capabilities, asserting that it is designed to streamline processes such as collecting information about potential attack targets, identifying vulnerabilities, planning attack vectors, executing security tools, and verifying vulnerabilities. While such tools were originally intended for enhancing security checks and penetration testing, they can be misused, a phenomenon well recognized in the cybersecurity domain. As Moon aptly stated, these technologies are often described as a "double-edged sword," capable of both bolstering security measures and facilitating cyberattacks.

An official from the Korea Financial Security Institute, which acts as a computer emergency response team, clarified that despite evidence of AI tool usage, the attacks were not fully automated. The official emphasized that while AI played a role, human operators were actively involved, employing the AI tool as an assistive resource in orchestrating the breaches.

The fallout from these cyberattacks has been severe. The initial signs of the breaches surfaced with Shinhan Bank revealing that information associated with 25,729 customers had been compromised. Reports indicated that sensitive personal data linked to loan applications, including customers’ names, phone numbers, and financial details, had been exposed. Authorities believe the breach at Shinhan Bank occurred on September 30, prompting the bank to issue a public apology and establish a dedicated page for customers to verify their potential exposure.

Shortly thereafter, Hana Bank reported a breach affecting 89 customers, with similar personal data compromised. Other institutions, including Yegaram Savings Bank, KB Kookmin Bank, Welcome Savings Bank, and Hyundai Capital, also reported significant breaches, affecting tens of thousands of customers. While NH NongHyup Bank and Woori Bank were targeted, they have not officially confirmed any breaches.

In light of these incidents, President Lee has urged a rapid shift towards adopting AI-driven cybersecurity technologies throughout the nation, particularly in critical infrastructure sectors. He argued that traditional approaches to cybersecurity, which involve reactive measures after threats materialize, are no longer sufficient. There is a pressing need to develop capabilities for proactively detecting and intercepting attacks before they occur, underscoring the importance of speed in the adoption and implementation of enhanced cybersecurity measures.

Simultaneously, South Korean financial authorities have thrown a spotlight on the emerging risks of phishing schemes and loan scams in the aftermath of these data breaches. They have mandated all banks to conduct thorough evaluations of their cybersecurity protocols and report back on their findings. Fortunately, officials have noted that, as of yet, there have been no confirmed instances of phishing scams resulting in financial losses directly attributable to the leaked data, providing some reassurance to depositors.

The Financial Services Commission (FSC), the nation’s financial regulatory body, alongside the Financial Supervisory Service (FSS), has convened meetings with banking representatives to ensure immediate assistance for affected customers. Additionally, they have mandated that banking institutions enhance monitoring controls for online loan applications and any sweeping transfer of funds associated with breach victims.

In conclusion, the breaches at multiple South Korean banks have unveiled a complex web of cybersecurity vulnerabilities exacerbated by the deployment of advanced AI tools. As investigations unfold, the focus will not only be on identifying the culprits but also on fortifying the defenses of financial institutions against an increasingly sophisticated landscape of cyberthreats.

Source link

Latest articles

OT Coalition Calls on CISA to Require Federal OT Security Measures

OT Cybersecurity Coalition Advocates for Mandatory Regulations The Operational Technology Cybersecurity Coalition (OTCC) has made...

Denmark’s National ID System Breach Exposes Personal Data of 8.8 Million

Denmark Strengthens Security Measures Following Major Data Breach In a significant security breach, Denmark is...

Anthropic Expands AI Cyber Capabilities for Approved Security Teams

Expanded News Article on Access Tiers for Cybersecurity In an increasingly digital world where cyber...

Building an Effective Cybersecurity Awareness Program

Rethinking Cybersecurity Awareness Programs: A Strategic Approach to Risk Management Effective cybersecurity awareness programs play...

More like this

OT Coalition Calls on CISA to Require Federal OT Security Measures

OT Cybersecurity Coalition Advocates for Mandatory Regulations The Operational Technology Cybersecurity Coalition (OTCC) has made...

Denmark’s National ID System Breach Exposes Personal Data of 8.8 Million

Denmark Strengthens Security Measures Following Major Data Breach In a significant security breach, Denmark is...

Anthropic Expands AI Cyber Capabilities for Approved Security Teams

Expanded News Article on Access Tiers for Cybersecurity In an increasingly digital world where cyber...