Initializing portfolio

000

Aravind.
All articles
Cybersecurity3 min read

Suspected AI-Agent Hacks Spread From Korea's Big Banks to Savings Banks and Lenders

A wave of suspected AI-agent hacks has spread from Shinhan, KB Kookmin and Hana to Korean savings banks and lenders, exposing loan data and prompting an emergency FSC meeting.

AravindChief Technology Officer & Advisor · AI, Cloud & Cybersecurity
Suspected AI-Agent Hacks Spread From Korea's Big Banks to Savings Banks and Lenders

South Korea's Financial Services Commission held an emergency meeting with industry representatives on Sunday, October 4, after a wave of breaches moved from the country's largest commercial banks into smaller lenders. Regulators suspect AI agents were used in the attacks.

"We cannot rule out the possibility that AI was used," FSC Chairman Lee Eog-weon said, telling the sector to stay on the highest alert.

What has been disclosed so far

  • Shinhan Bank: 25,727 customers exposed. KB Kookmin: 119. Hana Bank: 89. BNK Busan Bank: 11 outsourced developers.
  • Yegaram Savings Bank: about 40,000 customers, the largest single-firm breach in this wave so far, disclosed on Friday.
  • Welcome Savings Bank: up to 2,200 corporate customer records, found in an internal review on Saturday.
  • Hyundai Capital: personal data of some of its 146 mortgage loan agents.
  • The Financial Supervisory Service has alerted about 500 financial firms to malicious IP addresses seen across multiple attacks. They must finish emergency checks by Thursday.

Detection was slow even at the biggest banks: 15 hours 26 minutes at Shinhan, 41 hours 44 minutes at Hana, 67 hours 41 minutes at KB Kookmin. Traces of a Chinese-language AI hacking tool called "Artex AI" were reportedly found in the bank attacks.

The data matters more than the count

The stolen records go beyond names and phone numbers. They include loan application details, calculated credit limits, decision codes and interest rates. That's what a voice-phishing caller needs to sound convincingly like the bank.

The banks point out that core transaction systems were not breached. The attackers went through internet-facing systems used by employees and loan agents. Regulators named weak authentication and excessive data retention and access as the gaps.

The lesson for Indian BFSI

Read that list of weaknesses again: weak authentication on external-facing staff and agent portals, too much data kept for too long, too many people able to reach it. None of those are AI problems. An AI agent just finds them faster and works through them at a scale a human crew couldn't.

Indian banks and NBFCs run large agent and DSA networks on similar portals. If I ran security at one of them, I'd be asking three questions this week. Which external systems give agents access to loan data? How long do we keep it? And how many hours would it take us to notice an automated tool pulling it out?

Source: Korea JoongAng Daily: From banks to lenders, suspected AI hacks expose cracks in Korea's financial defenses

#AI Security#Data Breach#BFSI#Korea

Comments

Checking you're human…

Keep reading

Get the next essay first

Checking you're human…

By subscribing you agree to our Privacy Policy. Unsubscribe anytime.