With information leakage damage from hacking spreading from commercial banks to mutual savings banks and capital companies, the entire financial sector has been placed on high alert. It has been revealed that a total of seven financial companies have suffered damage from hacking suspected to involve a new method utilizing AI. Financial authorities have rushed into emergency meetings.
For the first news report, here is reporter Jeon Hyeong-u.
[Reporter]
Financial authorities have confirmed that seven financial companies have suffered information leakage damage so far.
Following four commercial banks including Shinhan, Kookmin, Hana, and Busan, as well as Yegaram Savings Bank and Hyundai Capital, it was additionally confirmed that corporate customer information was leaked from Welcome Savings Bank.
It is estimated that around 2,200 pieces of corporate customer-related information, such as corporate managers’ names, emails, and phone numbers, were leaked.
As some companies outside of these seven successfully blocked hacking attempts, this hacking attack occurred simultaneously across multiple parts of the financial sector.
In response, financial authorities held an emergency inspection meeting during the holiday period, attended by representatives from the entire financial industry, including commercial banks, secondary financial institutions, internet-only banks, and fintech companies.
Financial authorities believe there is a possibility that this hacking utilized AI tools.
[Lee Eok-won / Chairman of the Financial Services Commission: We cannot rule out the possibility of hacking attacks utilizing AI. We must hurry to establish a security system that defends against AI attacks with AI.]
According to investigation results so far, the same attacker’s internet protocol (IP) address was discovered in multiple breach sites, and it was found that they continuously launched attacks while changing IPs.
The hackers targeted subsidiary systems with relatively lax security rather than heavily secured payment systems.
Web page servers or mobile devices used for work by loan agents or employees served as the “backdoors” for data theft.
There were also cases where customer information was stolen after installing malicious code on servers and acquiring administrator privileges.
President Lee Jae-myung instructed that “thorough investigations and full preparations for countermeasures be made” regarding this issue.
Financial authorities have instructed banks and card companies to complete emergency inspections by the 6th, and securities, insurance, and savings banks by the 8th.
(Photo: Cho Choon-dong, Video Editing: Kim Jin-won)
—
[Anchor]
This hacking is estimated to have been carried out simultaneously against multiple financial companies using AI tools. This is because AI can automate vulnerability scanning and attacks much faster than human hackers. New security countermeasures to block this are urgently needed.
Next, let’s watch the report by reporter Hong Young-jae and delve deeper into questions you might have.
[Reporter]
This is an AI tool called “Artex” uploaded to a platform where developers share code and work details.
The description in Chinese reads “AI Autonomous Penetration Testing System.”
Originally, it is an AI program developed to perform mock hacking that independently finds vulnerabilities in a system.
A domestic security company analyzed a server web page suspected of being used in this financial sector hacking and stated that the phrase “Artex” was identified in the attack traces.
[Moon Jong-hyun / Head of Genians Security Center: If someone uses this for actual attacks rather than a real penetration test, it is a powerful enough tool to be used immediately in genuine attacks.]
More precise investigation is needed to determine whether AI tools such as Artex were actually utilized in the hacking.
However, the government acknowledged the possibility because large-scale automated attacks were carried out simultaneously against multiple financial companies in this attack.
The biggest advantage when utilizing AI tools as hacking weapons is “speed.”
AI can discover internet-connected equipment, software types, and vulnerabilities within a short time that hackers in the past had to search for individually.
Experts point out that a comprehensive inspection must be conducted not only on core financial network systems with relatively high security levels, but also on areas that have previously slipped in management priority, such as employee mobile devices or external systems used by loan agents.
[Kim Seung-joo / Professor at Korea University Information Protection Graduate School: How many PCs do we actually have, what operating systems and software are installed on them, and how many of them are connected to the internet—conducting a complete asset survey like this is the most urgent task.]
They also advise that since various AI hacking tools are already public besides Artex, and hacking performance can rise as AI models become more sophisticated, security countermeasures should not stop at blocking just one specific AI tool.
[Anchor]
Reporter Hong Young-jae, who covered this story, is here with us.
Q. ‘AI Hacker’ Work?
[Reporter Hong Young-jae: Hacking attacks suspected of utilizing AI have already been reported multiple times overseas. Evaluations suggest that the threat of AI hacking has surfaced in earnest in our country as well, triggered by this financial sector incident. There are several reasons why financial authorities suspect that AI tools were utilized in the hacking. While past methods often involved infiltrating a specific company’s server and plundering databases all at once to extract massive amounts of information, this time the attacks targeted multiple financial companies simultaneously, finding relatively vulnerable points exposed externally at each company to scrape information. The frequency and method of the attacks, as well as the traces left by the attacker—such as the phrase indicating the AI tool Artex—are points that raise suspicion of AI utilization.]
Q. Resolved by ‘Relaxing Network Separation Regulations’?
[Reporter Hong Young-jae: Currently, financial companies are subject to so-called network separation regulations that isolate internal computer networks from the internet. However, many recent AI security technologies must be connected to external clouds or AI models to be utilized. If network separation is too strict, it can restrict the introduction of security technologies that allow AI to analyze numerous attack attempts in real-time, find abnormal signs, and block them. Therefore, the government intends to ease network separation regulations to allow the utilization of AI security technologies, while concerns are conversely raised that lifting network separation could increase contact points connected to the outside, creating new passage routes for attacks.]
Q. Are My Information and Assets Safe?
[Reporter Hong Young-jae: The government stated that so far, core financial service security such as internet and mobile banking has not been directly breached through this incident, and there have been no cases of monetary damage. However, sensitive personal information such as names and mobile phone numbers has been leaked, and since this information could potentially be maliciously used in secondary crimes such as voice phishing or smishing, it is not a situation where we can feel safe.]
(Photo: Kim Seung-tae, Video Editing: Lee So-young, Design: Lim Chan-hyuk)
Reported by Jeon Hyeong-u, Hong Young-jae | Produced by SBS Digital News
※ Please note: This article was translated by AI and may contain errors.
Click Here For The Original Source.
