[Holes in Financial Security] 6. AI Changes the Hacking Playbook… IMF, BIS: “Hacking Is at Machine Speed, and the Golden Window Is Shrinking”

Since the emergence of generative and agentic AI
Faster, broader discovery of system vulnerabilities enables attacks
“AI-enabled attacker activity up 89%…average time to move internally: 29 minutes”

Hacking possible without skille

Digital security threats facing the financial sector have entered a new phase since the advent of generative artificial intelligence (AI). In the past, skilled hackers had to search for vulnerabilities one by one. Now, AI can use nothing more than a prompt to attack numerous servers and web services indiscriminately in a short time and steal information. A series of recent hacking incidents targeting financial institutions illustrates how AI can become a powerful weapon for threatening the sector’s security systems. The International Monetary Fund (IMF) and the Bank for International Settlements (BIS) have voiced concern that AI hacking using AI agents will become commonplace, warning that the window of opportunity to defend against attacks is shrinking.

AI-Powered Attacks Surge in a Year…Autonomously Find Weaknesses and Break In




View original image

According to the financial sector on October 8, the BIS Financial Stability Institute (FSI) warned in a report published last month, titled “The Machine’s Attack: Frontier AI Cyber Threats in the Financial Sector and Policy Responses,” that advances in frontier AI could make cyberattacks exploiting AI more frequent.

Frontier AI refers to the most advanced, high-performance AI models currently available. These models can independently identify system vulnerabilities, develop means of attack, and even carry out complex, multistage cyberattacks. The BIS expects that as these capabilities advance, the expertise, time, and cost required to mount sophisticated attacks will fall significantly.

The biggest change AI brings is not the emergence of entirely new types of cyberattacks, but the ability to find and exploit the “weak links” in existing systems much faster and on a much wider scale. The BIS identified autonomous vulnerability detection and exploitation as a major change brought about by frontier AI. According to an analysis by Verizon cited in the report, vulnerability exploitation was used as the initial access vector in 31% of all breaches, making it the most common entry point.

“This means that vulnerability exploitation has become the most common initial access vector,” the BIS said. “As AI’s ability to detect vulnerabilities advances rapidly, the time financial companies have to identify and patch vulnerabilities may continue to shrink.”

The problem is speed. According to CrowdStrike data cited in the IMF’s report “Artificial Intelligence and Cybersecurity in the Financial Sector,” published in June 2026, the activity of attackers using AI increased by 89% between 2024 and 2025. The average “breakout time” – the time it takes an attacker to move to another system after an initial breach – fell to 29 minutes, 65% shorter than the previous year.

The time between the discovery of a vulnerability and its use in an actual attack is also rapidly shrinking. The IMF said that “with the spread of autonomous AI hacking and automation, offense and defense are moving into the realm of ‘machine speed,’ surpassing the pace of human response.” It added that as zero-day attacks, which exploit vulnerabilities before they are publicly disclosed, become more common, defenders have even less time to detect, assess, and respond.

The BIS likewise said that “the speed of intrusion and lateral movement determines how quickly defenders must respond to limit the costs and damage caused by a breach,” adding that “as frontier AI automates the discovery and exploitation of vulnerabilities, the time available to detect, assess, and respond to attacks is shrinking significantly.” In other words, the “golden time” for stopping cyberattacks is itself getting shorter.


[Holes in Financial Security] 6. AI Changes the Hacking Playbook... IMF, BIS: "Hacking Is at Machine Speed, and the Golden Window Is Shrinking"


View original image

The Barriers to “Anyone Being Able to Hack” Have Fallen…Financial Sector on Alert

Recent hacking incidents in South Korea’s financial sector also resemble the widespread form of AI hacking described in the report: attacks that used AI agents to exploit weak links in relatively vulnerable external systems.

Vulnerabilities were exposed to attacks in Shinhan Bank’s inquiry service for loan recruiters, KB Kookmin Bank’s mobile work-support system for employees, and Hana Bank’s sales-support system. The targets were not core financial services such as mobile banking, on which financial companies have focused their security capabilities, but external web services with relatively weak authentication or access controls.

Attacks targeting so-called “side doors” existed in the past, but automation using AI has made it easier to scan multiple systems for vulnerabilities and repeatedly attack them in a short time. In other words, attackers can now attempt large-scale attacks with fewer people and less time than before.

The financial sector is also on alert because AI lowers the technical barriers to carrying out attacks. “In the past, someone had to study for a certain amount of time before they could hack, but these days the barriers have fallen so much that even people with no knowledge can do it easily if they know how to use the tools,” said Park Chan-am, CEO of Stealien. “There have been quite a few hacking attempts in the past, too, but I think the problem is that anyone can now use the tools effectively to carry out hacking at an intermediate level.”

Cases have also emerged in which AI has taken over a substantial part of the attacker’s role. An analysis by global security firm Gambit Security of a breach involving Mexican government agencies found that one attacker used commercial AI to target multiple agencies and steal the personal information of more than 190 million people. According to Gambit’s forensic analysis, about 75% of remote hacking activity was carried out through an inexpensive subscription-based AI service, Claude Code, costing $20 per month (about 20,000-30,000 won). The attacker used more than 1,000 prompts to execute over 5,000 commands and used AI to analyze information collected from hundreds of internal servers. Tasks that once required multiple skilled hackers could now be carried out on a large scale by a small number of attackers with AI assistance.


[Holes in Financial Security] 6. AI Changes the Hacking Playbook... IMF, BIS: "Hacking Is at Machine Speed, and the Golden Window Is Shrinking"


View original image

“Hacking at an Individual Financial Company Could Trigger a Financial System Crisis”…Security Investment Must Increase

The IMF also highlighted the possibility that an incident at an individual financial company could spread into a problem for the financial system as a whole. This is because global financial companies rely on common digital infrastructure, including cloud services, operating systems, and open-source software.

“If a vulnerability at one institution is exploited simultaneously at multiple financial companies or triggers cascading outages, the shock could spread throughout the financial system through interconnectedness,” the IMF said. It added, “The key concern from a financial stability perspective is not so much that AI creates entirely new attack methods, but that it can spread existing attacks much faster and more widely. Defense must also improve the speed of detection, assessment, and response to keep pace with the ‘machine speed’ of attacks.”

The BIS said financial companies should first ensure that their basic cybersecurity frameworks are operating more rigorously. “There is no need to start from scratch and create AI-specific regulations or security systems,” the BIS said. “The priority should be to repeatedly review basic security practices and access controls, promptly patch vulnerabilities, and strengthen the resilience of external providers and shared infrastructure.”

South Korean experts emphasize that this will require active investment in security. “The recent web service hacking incident was not beyond the ability of financial companies’ security teams to fix. The problem was that it fell down the priority list because resources – such as budget, personnel, or the authority to take swift action – were limited,” Park said. “In the era of AI hacking, financial companies and the government alike must invest sufficiently in the most important area of security, especially the protection of customer information.”

This content was produced with the assistance of AI translation services.

© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.

Click Here For The Original Source

——————————————————–

..........

.

.