Officials warn against AI-aided cybercrime | #cybercrime | #infosec


PHISHING FEST:
Those looking to extort companies and individual people might use AI to increase the scope and effectiveness of their nefarious ambition, officials said

  • By Shelley Shan /
    Staff Reporter

Cybercriminals using artificial intelligence (AI) could make ransomware more automated and targeted, while employing double-extortion tactics that involve stealing sensitive data and threatening to leak it publicly, the Administration for Cybersecurity said yesterday.

The administration said that ransomware would forcibly encrypt important data after gaining entry through phishing, malicious sites, network loopholes and illegal software, making them inaccessible to users. Hackers then demand that victims pay a ransom in exchange for a decryption key, it said.

Attack trends showed that hackers would steal sensitive information before encrypting it and threaten to make the data public if the ransom is not received by the deadline, putting psychological pressure on victims, the administration said.

By Chiu Chiao-chen, Taipei Times

AI further facilitates ransomware attacks by increasing their speed, automation and precision, it said.

The IC3 Annual Report published by US FBI showed that the bureau recorded 3,611 ransomware complaints last year, up by 14 percent compared with 2024, the administration said.

Reported financial losses surged to US$32.32 million last year, rising from US$12.47 million, it added.

In Taiwan, public information, including material information listed companies must file with the Taiwan Stock Exchange, showed that at least seven companies and medical institutions reported ransomware attacks last year, the administration said.

As of Wednesday last week, at least five companies had reported ransomware attacks this year. The affected companies span industries ranging from papermaking and biotechnology manufacturing to semiconductor equipment and electronic components.

On July 17, a hacker using the alias “I’m Rois” posted a message on Telegram identifying Taiwan as the target and uploaded a file titled “Taiwan Sample Access.txt.” The post said buyers can choose their targets and enclosed contact information for negotiations.

The post featured a Taiwanese flag as its cover image and included a sample list claiming access to more than 90 Taiwanese organizations, including AUO Corp (友達光電) , Hiwin Technologies Corp (上銀科技), Wan Hai Lines (萬海航運) and others.

Asked about the potential attacks, Administration for Cybersecurity Director-General Tsai Fu-lung (蔡福隆) said that the administration investigated the information and is asking corporations to upgrade their equipment.

“Corporations that are on the target list should check for suspicious login activity in their virtual private networks, firewalls and cloud services. They should also consider disabling unnecessary externally accessible interfaces, and updating credentials and software on Internet-facing systems and devices,” Tsai said.

Lin Yu-chieh (林郁傑), director of the administration’s Cybersecurity Audit Division, said that ransomware attacks typically involve attackers infiltrating a system, lying dormant, then encrypting files before demanding a ransom. He urged the public, businesses and government agencies to keep systems and software up to date, use strong passwords with two-factor authentication, and remain alert to suspicious messages, e-mails and AI-generated phishing scams.

If a ransomware attack is suspected, organizations should immediately disconnect affected systems from the network, preserve evidence, seek assistance from cybersecurity experts and avoid paying the ransom, Lin said.

They should report the incident to police and Taiwan’s Computer Emergency Response Team/Coordination Center and restore systems and data from backups, he added.



Click Here For The Original Source.

——————————————————–

..........

.

.

National Cyber Security

FREE
VIEW