Releases "Guide to Analyzing and Responding to Breaches Targeting Shadow IT in the Era of AI-Automated Attacks"

SK shieldus released on October 8 a guide titled “Analyzing and Responding to Breaches Targeting Shadow IT in the Era of AI-Automated Attacks,” which examines security issues involving shadow IT and APIs (application programming interfaces), both of which have emerged as major threats in the era of AI-automated attacks.


Drawing on recent breach cases in the financial sector, the guide analyzes how AI-based attack tools are used and the actual paths taken in the breaches. It also outlines the security framework companies need to prepare for similar attacks.


Based on a comprehensive review of information about the incident made public to date, SK shieldus concluded that it was more likely a case of existing attacks being automated and made more sophisticated than one in which AI created a new attack technique. Rather than targeting core financial transaction systems, the attackers first went after internet-facing assets in blind spots in security management, such as loan agent systems, employee support services, and sales support platforms. AI was assessed to have helped them scan these assets more quickly and at greater scale.


SK shieldus noted that AI-based automated attack tools can scan internet-facing assets and APIs at multiple financial institutions simultaneously and rapidly expand their targets based on API call patterns and response data. The analysis warned that the threat could grow as AI can mimic normal call patterns to conduct large-scale scanning and gather information in environments where companies’ key business operations are connected through APIs.

SK shieldus: "AI Automates and Makes Existing Attacks More Sophisticated, Rather Than Creating New Vulnerabilities" View original image

In the guide, SK shieldus also explained how the AI-based penetration-testing tool ARTEX, which has been cited as a possible tool used in the attack, works and what risks it poses. In particular, EQST (Experts, Qualified Security Team), SK shieldus’s white-hat hacker group, directly analyzed ARTEX to identify how autonomous AI-based attacks operate and draw out their security implications.


Based on its findings, SK shieldus identified “shadow IT”—unmanaged external points of access—as the starting point of the AI attack. Shadow IT refers to systems, services, and APIs operating outside the security team’s inventory and control. It includes not only assets whose existence is unknown, but also assets that are known yet receive insufficient security reviews because they are low on the management priority list. The analysis found that in this incident, too, externally exposed business support systems and APIs were used as major attack paths, rather than core financial transaction systems.



Kim Byungmoo, vice president and head of the Cyber Business Division at SK shieldus, said, “AI does not create new vulnerabilities; it amplifies attacks. Companies therefore need to gain visibility into their assets and strengthen controls over externally exposed areas, including APIs. Since the fundamentals of security remain unchanged in the AI era, we will continue to support our customers in building practical security services and zero-trust-based security frameworks so they can respond effectively to the changing threat landscape.”


This content was produced with the assistance of AI translation services.

© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.

Today’s Briefing