News

AI Tools Used in Financial Sector Hacks Operating on Hundreds of Servers Worldwide

AI Tools Used in Financial Sector Hacks Operating on Hundreds of Servers Worldwide
▲ File image

It has been revealed that hundreds of servers equipped with the same open-source artificial intelligence (AI) penetration testing tools used in recent domestic financial sector hacks are currently operating worldwide.

As attackers bypass existing security networks by utilizing overseas relay servers and new internet protocol (IP) addresses, concerns are growing within the domestic financial sector over the potential secondary exploitation of leaked loan-related information and a security personnel structure heavily reliant on outsourcing and contract workers.

According to a threat intelligence report released on October 8 by security and data intelligence firm S2W, attempts to sell fake customer information on the dark web and Telegram, taking advantage of the recent financial sector hacking incident, have been detected, making responses to prevent secondary damage following personal data leaks critical.

According to the report, fraudulent sales posts claiming to "sell millions of customers from major domestic financial companies" are appearing back-to-back on the dark web and Telegram.

As a result of S2W acquiring and cross-verifying actual leak samples, it was confirmed to be fraudulently manipulated data filled exclusively with overseas emails and rare domestic surnames, while containing phone number identifiers consisting only of legacy prefixes such as '011', '016', and '019'.

This means that fraudulent transactions are thriving amidst the confusion immediately following a major security incident.

The real problem lies elsewhere.

According to financial authorities, core payment information such as account passwords or one-time passwords (OTPs) was not compromised, but loan inquiry history was leaked alongside names and contact information.

The report explained that such credit and loan information can be used as a powerful weapon for sophisticated, customized voice phishing that goes beyond typical indiscriminate smishing.

The analysis indicates a very high risk that secondary damage will materialize, with attackers grasping victims' actual loan statuses and approaching them by offering preferential loan conditions, or exploiting the news of the incident to send text messages guiding them to install malicious apps under the guise of "personal data leak confirmation notices."

The spread speed of the AI infrastructure weaponized in the attacks is also alarming.

According to S2W's analysis, hundreds of servers equipped with the same open-source AI penetration testing tools used in the attacks are currently observed operating worldwide.

Attackers neutralized traditional defense networks by cross-utilizing pre-established relay servers, overseas proxies, and domestic IPs.

Most of the IPs used in the attacks were new addresses not even registered in existing global threat reputation databases (DBs).

The explanation is that it is difficult to proactively block AI-based attacks with lowered entry barriers through reactive reviews focused merely on blocking simple IPs.

However, criticisms have been raised that the financial sector's response foundation to fend this off remains vulnerable.

Although government regulations are shifting from ex-ante regulation to corporate-led voluntary security, the security monitoring and computer emergency response team (CERT) personnel of the majority of financial companies are still filled primarily with outsourced or contract workers.

Critics point out that under poor environments where they must handle tens of thousands of abnormal events daily, a method of holding only individual working-level staff or chief information security officers (CISOs) accountable every time an accident breaks out cannot withstand exploding AI attacks.

The report emphasized, "Prior to engaging in disputes over inspection responsibilities, institutional support to internalize on-site professional personnel and secure independent AI inspection capabilities is urgent."

(File Photo: Yonhap News)
※ Please note: This article was translated by AI and may contain errors.
Copyright Ⓒ SBS & SBSi. All rights reserved.
Copying, redistribution, and unauthorized use in AI training are strictly prohibited.

Most Read