News

AI Mock Hacking Test: Personal Info Stolen and Report Generated in Just 6 Minutes

[Anchor]

We conducted a hacking experiment using "Artex," an AI tool reportedly used in recent cyberattacks against the financial sector. It took the AI tool a mere 6 minutes to steal personal information and even produce a report.

Reporter Park Jaehyeon has the details.

[Reporter]

A virtual financial institution server was set up in an isolated environment without an internet connection.

Instructions were then entered into "Artex," an AI agent known as a cutting-edge financial hacking tool.

All that was typed was a request to "find vulnerabilities that allow access to the database without authentication."

Running on a high-spec personal PC, it took Artex just 6 minutes to locate the vulnerabilities.

One hundred pieces of virtual personal information hidden within the server were exposed as is.

[Ryu Seok-jun / Researcher, AI Safety Research Center at Soongsil University: It only takes 6 minutes to form a hypothesis, prove it, and even print out a report.]

As AI's ability and speed in finding security vulnerabilities improve, an international security consortium has projected that software vulnerabilities discovered this year will increase by nearly 50% compared to earlier expectations.

[Shane Huntley / CTO, Google Threat Intelligence Group: Attackers can explore every vulnerability at any time because they are not constrained by manpower. They are able to attempt every possible attack.]

It has now become inevitable to use AI for defense against surging AI-driven hacking.

We issued the same instructions to a cybersecurity AI agent in the same isolated environment used in the previous experiment.

It immediately identified the flaws and specifically detailed what needed to be patched and how.

This means that even smaller companies that struggle to make massive investments in security can use AI to preemptively find vulnerabilities and defend themselves.

[Choi Dae-sun / Director, AI Safety Research Center (Dean of Graduate School of AI) at Soongsil University: Just as attacking capabilities have become generalized, defensive capabilities can also be generalized as a technology or means accessible to anyone. Moving forward, we must actively utilize AI-driven defense....]

Arguments are also being raised that companies should more actively share and utilize discovered vulnerabilities externally to jointly enhance defensive capabilities.

(Camera: Kim Hyun-sang | Video Editing: Park Na-young | Design: Cho Su-in | Footage provided by: Ministry of Science and ICT)
※ Please note: This article was translated by AI and may contain errors.
Copyright Ⓒ SBS & SBSi. All rights reserved.
Copying, redistribution, and unauthorized use in AI training are strictly prohibited.

Most Read