Financial Security Institute Warned of AI Attack Two Weeks Before Series of Hacks
The Financial Security Institute shared cases of attacks using artificial intelligence (AI) with financial institutions ahead of a recent series of cyberattacks targeting the financial sector, and recommended that they continuously inspect systems exposed to the outside world.
According to documents submitted by the Financial Security Institute to Han Chang-min, a Social Democratic Party lawmaker on the National Assembly's Political Affairs Committee, the institute presented a case involving an AI agent attack targeting Financial Firm A in South Korea, along with recommended response measures, at the "Seminar on Responding to Financial AI Security Threats" on September 17. About 160 financial-sector security officials attended the seminar. Those in attendance reportedly included officials from KB Kookmin Bank, Hana Bank, Hyundai Capital, and Welcome Savings Bank, which have recently suffered cyber incidents.
According to the presentation materials, the attacker used a DeepSeek-based AI agent to scan servers exposed to the outside world, then exploited vulnerabilities in the server software to install a web shell, a type of malware. Financial Firm A detected and blocked the attack just before the attacker could scan internal servers and download additional malware.
Hot Picks Today
"Didn't Know This Trick?" 84-Sq.-M. Mixed-Use Unit Sells for 2.14 Billion Won... Indirect Buying Demand Spreads [One Year of Land Transaction Permit Zones Across Seoul]
- "The '20,000-Won Happiness' That Makes You Forget Short-Form Dopamine"... China's Gen Z and Millennials Hooked on Grandma's Hobby [China.zip]
- "Busan Is in Big Trouble"... One Cockroach Can Produce 350 Nymphs; Establishment Confirmed, Causing Alarm
- Ceiling Collapse at Daegu Commercial Building Injures Dozens of Older Adults... Police, National Forensic Service Begin Probe into Cause
- "I Hate Dog Meat and Skate, Love Pizza" ... "Let's Meet" Frenzy Over Beautiful 41-Year-Old Nurse, But There's a Twist
The institute stressed that "these threats cannot be caught through assessments conducted only once or twice a year" and that "continuous measurement and verification are necessary." Some have pointed out that the damage from the recent cyberattacks could have been reduced if financial institutions had inspected and addressed vulnerabilities in their external systems after the seminar.
© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.