News

Quick Attacks by Finding Vulnerabilities: Are My Personal Information and Assets Safe?

[Anchor]

It is presumed that this recent hacking attack was carried out simultaneously against multiple financial companies using AI tools. This is because AI can automate vulnerability scanning and attacks much faster than human hackers. Urgent new security measures are needed to block this.

Next, we will look at the report by reporter Hong Yeongjae and then delve deeper into some questions you might have.

[Reporter]

This is an AI tool called "Artex" uploaded to a platform where developers share code and work details.

The description in Chinese states that it is an "AI Autonomous Penetration Testing System."

It is an AI program originally developed to perform mock hacking by autonomously finding vulnerabilities in systems.

A domestic security company analyzed a server webpage presumed to have been used in this financial sector hacking incident and stated that the phrase "Artex" was found in the attack traces.

[Moon Jong-hyun, Head of Genians Security Center: If someone uses this for actual attacks rather than penetration testing, it is a powerful enough tool to be immediately deployed in real-world attacks.]

More accurate investigations are needed to determine whether AI tools such as Artex were actually utilized in the hacking.

However, the government acknowledged this possibility because a large volume of automated attacks was carried out simultaneously against multiple financial companies in this attack.

The biggest advantage of using AI tools as hacking weapons is "speed."

AI can find internet-connected equipment, software types, and vulnerabilities in a short period of time—things that hackers previously had to search for manually.

Experts point out that a comprehensive inspection should be conducted not only on core financial networks with relatively high security levels, but also on areas that have previously been neglected in management priorities, such as employee mobile devices or external systems used by loan recruiters.

[Kim Seung-joo, Professor at Korea University Graduate School of Information Security: Conducting a complete asset survey—figuring out exactly how many PCs we have, what operating systems and software are installed on them, and how many of them are connected to the internet—is the most urgent task.]

They also advise that since various AI hacking tools besides Artex have already been disclosed and hacking performance can increase as AI models become more advanced, countermeasures should not stop at blocking just one specific AI tool.

[Anchor]

Reporter Hong Yeongjae, who covered this story, is here in the studio.

Q. Work of an "AI Hacker"?

[Reporter Hong Yeongjae: There have already been multiple reports overseas of hacking attacks suspected of using AI, and in South Korea as well, assessments are emerging that the threat of AI hacking has surfaced in earnest following this financial sector accident. There are several reasons why financial authorities suspect that AI tools were used in the hacking. While past attacks often involved infiltrating a specific company's server and plundering a database all at once to steal massive amounts of information, this time, multiple financial companies were attacked simultaneously, scraping information by finding relatively vulnerable points exposed externally at each company. The frequency and method of the attacks, as well as the traces left by the attacker—specifically the phrase indicating the AI tool Artex—are points that raise suspicions about the use of AI.]

Q. Resolved by "Easing Network Separation Regulations"?

[Reporter Hong Yeongjae: Currently, financial companies are subject to so-called network separation regulations, which isolate their internal computer networks from the internet. However, many recent AI security technologies can only be utilized when connected to external clouds or AI models. If network separation is too strict, it can restrict the adoption of security technologies where AI analyzes numerous attack attempts in real time to detect and block abnormal signs. Therefore, the government intends to ease network separation regulations so that AI security technologies can be utilized, but concerns are also being raised that loosening network separation could increase external connection points themselves, creating new attack channels.]

Q. Are My Information and Assets Safe?

[Reporter Hong Yeongjae: The government has stated that, up to this point, core financial services such as internet and mobile banking have not been directly breached by this accident, and there have been no cases of financial damage. However, sensitive personal information such as names and mobile phone numbers has been leaked, and since this information could be misused in secondary crimes like voice phishing or smishing, it is not a situation where we can feel at ease.]

(Photo: Yonhap News / Video: Kim Seung-tae | Video Editing: Lee So-young | Design: Lim Chan-hyeok)
※ Please note: This article was translated by AI and may contain errors.
Copyright Ⓒ SBS & SBSi. All rights reserved.
Copying, redistribution, and unauthorized use in AI training are strictly prohibited.

Most Read