Some of South Korea’s biggest banks have been hacked with the assistance of an artificial intelligent agent, opening up a new front in the AI and cybersecurity worlds.
Officials say at least seven financial firms were included in the attack, which saw personal information for 68,000 people stolen, including annual income and loan limits. This marks one of the first times AI tools have been used to disrupt global financial stalwarts.
It’s notable, since banks and other financial institutions typically have a higher level of security than other businesses or even some government agencies. Officials say they haven’t identified the people responsible for the attacks, which originated from over two dozen IP addresses spread out over several countries, including the U.S. and Japan. (Hackers frequently spoof their IP address to remain anonymous.)
South Korean officials are urging banks to boost their defenses. And the intrusions could serve as a warning shot for banks in the United States and other countries as well.
“AI gives attackers more opportunities to exploit gaps before defenders respond,” Yagub Rahimov, CEO of Polygraf AI, told Fast Company. “My advice to bank leadership is to take a step back and invest in threat mapping. Trace the actual paths to sensitive data through employee activities, vendor connections, applications, APIs and human and machine identities. They need to identify the systems that are reachable.”
The hackers apparently used Artex AI, an open-source agent developed in China, that ironically was designed as a cybersecurity tool that helped users find vulnerabilities in their network. Artex has since updated its user guidelines to say the tool should not be used for malicious reasons.
AI-assisted hacking on the rise
While the attacks on the South Korean banks represent a new level, there has been a consistent uptick in AI-assisted hacking for some time now. A report from the SANS Institute, issued in July, found that 78% of organizations saw either a confirmed or suspected AI-enabled attack in the past year.
The method of those attacks was evenly spread, though. Occurrences of phishing, deepfakes, and vulnerability exploitation were all virtually the same.
“AI tools are maturing, and so are the criminals using them — they moved from scaling phishing campaigns to autonomously probing defenses, chaining exploits, and adapting mid-attack,” Vakaris Noreika, cybersecurity expert at NordLayer Intelligence by NordStellar told Fast Company. “Going forward, we should expect attacks to grow in both scale and sophistication, which means defenses must keep pace with an AI-enabled threat landscape.”
The SANS Institute study showed a disparity between concern of possible AI-enhanced hacks and preparedness. Virtually every respondent—some 95%– said they believe threat actors are using AI today to enhance their attacks, with 58% saying the believe the use of AI is significant. Yet only 16% say they have shifted their priority to defend against those.
Corrupting a tool
While Artex was designed to help protect users, the hackers’ use of this agent shows the range of possible threats that exist.
“The same capability that helps a security team investigate a weakness is also being used by an attacker to identify gaps for malicious purposes,” said Rahimov. “AI can connect tasks that previously required more manual work, making repeated attacks more economical – but even this can be turned around. Businesses should prepare for that capability to spread across tools and operators.”
Noreika warns that it’s not just smaller agents AI tools that can be corrupted, either. Most open-source AI models from a major lab possess the same advanced capabilities to hide malicious activity as security testing. That should put CEOs of banks and any other business on alert.
“The best way for companies to protect themselves is to adopt a hacker’s mindset — leveraging the very same AI tools to evaluate, stress-test, and strengthen their own security defenses,” said Noreika.