SBS NEWS

"Even Banks Breached"... How to Protect Your Account in the Age of AI Hacking


Add SBS News to Google preferred sources
Main image - SBS News

▲ AI Hacking

As large-scale account theft attacks using artificial intelligence (AI) recently shake the defense systems of major commercial banks in South Korea, including Shinhan Bank, KB Kookmin Bank, and Hana Bank, attention is turning to personal security measures that users must take into their own hands.

While individuals cannot prevent security breaches occurring at companies upfront, secondary damages—where leaked account information spreads to other financial and shopping accounts—can be significantly reduced depending on how users respond.

The cybersecurity industry emphasizes that simply using separate passwords for each site and turning on multi-factor authentication (MFA) drastically lowers the risk of account theft.

The immediate threat following a data breach is "credential stuffing."

This is a technique where IDs and passwords stolen from one service are fed into automated tools to attempt mass logins across banks, open markets, portals, and social networking services (SNS).

It exploits the fact that many users use the same account information across multiple sites simply because it is easy to remember.

Recently, with the addition of generative AI and sophisticated automated scripts, the scale and precision of these attacks have grown simultaneously.

Not only do they flood a massive amount of login attempts in a short time, but they also weave together scattered personal data to select targets.

The number one defense recommended by experts is to stop reusing passwords.

AhnLab recommended creating completely different passwords for each service.

The company explained that minor modifications, such as attaching a number or one or two special characters to the end of an existing password, are easily figured out by attack tools and should be avoided whenever possible.

The area that requires the most attention is the email account.

Email is used as the channel for identity verification and password reset across most web services.

If a single email account is compromised, bank and shopping mall accounts linked to it can be breached in succession.

If you receive a notification that your personal information has been leaked from a certain site, changing the password for just that site is insufficient.

You must track down all other sites using the same password and change them one by one to prevent the damage from spreading.

The next line of defense after passwords is MFA, also known as two-step verification.

Even if an ID and password fall into the hands of an attacker, the likelihood of unauthorized access drops significantly because they must clear additional hurdles such as biometric authentication or an authentication app (OTP).

If you receive a verification code or approval request notification on your smartphone when you have not logged in, you should never approve it and instead change your password immediately.

Phishing and smishing text messages flooding in after a personal data breach incident must also be guarded against.

Attackers induce clicks on malicious links (URLs) with phrases such as "check personal information leak," "compensation payment," or "account protection application."

Because they often masquerade as official guidance from financial companies using actually leaked names or phone numbers, it is easy to click them unthinkingly.

You must never click links in text messages or emails from uncertain sources.

A habit of directly launching official financial company apps or typing the address directly into the browser address bar is required.

Checking login history frequently is also helpful.

If there are traces of access from an unfamiliar region or an unrecognized device, or if you receive a password change notice you did not request, you should click "Log out of all devices" and reset your password.

It is also necessary to check whether the recovery phone number or backup email has been changed to someone else's.

On shared PCs used by multiple people, you should not use the browser's auto-login or password saving features, and you must log out after use.

Personal PCs and smartphones should also be periodically scanned with antivirus software, and operating systems (OS) must be kept up to date to prevent malware infections that steal account information saved in browsers.

Since individuals cannot stop all cybercrimes no matter how careful they are, companies handling customer data directly must pay close attention to their security systems.

AhnLab pointed out that companies should tighten application programming interface (API) authentication and access controls, and build monitoring systems capable of detecting abnormal repetitive calls or massive lookups in real-time.

It stated that the monitoring scope should extend beyond customer-facing web and apps to internal administrator networks and external contractor-linked systems.

It also called for data management principles that minimize the customer personal data stored in the first place.

An official from AhnLab emphasized, "Once account credentials are leaked, attackers use them as a stepping stone to launch chain attacks. Users must follow basic rules such as separating passwords by site and applying multi-factor authentication, while enterprises must operate multi-layered defense networks, such as upgrading abnormal login detection systems."

※

※ Please note: This article was translated by AI and may contain errors.
Copyright Ⓒ SBS & SBSi. All rights reserved.
Copying, redistribution, and unauthorized use in AI training are strictly prohibited.
Yoo Younggyu View More Articles
AD
AD
AD
AD