Video
Circumstances have been detected suggesting that an artificial intelligence agent may have been mobilized in the breach involving the personal information of approximately 25,000 Shinhan Bank customers.
Traces of a Chinese-language-based autonomous penetration testing tool, in which AI replaces humans to find vulnerabilities and plan attack paths, were found on a server presumed to have been used in the attack, though it has not yet been confirmed whether this tool was actually used in the attack.
According to the security industry, a Chinese-language string meaning "AI Autonomous Penetration Test Console" was identified in the HTML title of a web server utilized in credential stuffing—a technique involving random information input—presumed to have targeted Shinhan Bank.
The HTML title is the page title displayed on a web browser tab or at the top of a window. In simple terms, the Chinese phrase "AI Autonomous Penetration Test Console" was exposed as is in the page title of the web server used in the attack.
Credential stuffing is a hacking method in which an attacker indiscriminately inputs pre-secured ID and password combinations into multiple systems.
Typically, after illegally trading and collecting ID and password data used for specific sites on dark web information markets, attackers target the user habit of using the same IDs and passwords across multiple websites.
In the past, attackers had to repeat such inputs manually, but recently, tools that automate this process using AI are increasingly being mobilized.
Moon Jong-hyun, head of the Genians Security Center, stated, "Multiple threat analysts are reasonably suspecting that AI-based automated attack tools were utilized in this financial institution attack."
At the same time, he pointed out, "Although it is a tool developed surface-level for the purpose of supporting security audits and penetration testing, if malicious actors exploit it, there is a possibility that it could be repurposed as a means to enhance the automation and efficiency of actual cyberattacks."
Reported by Jung Da-eun | Video edited by Kim Min-ji | Designed by Yook Do-hyun | Produced by SBS Digital News