Saltar al contenido
ES EN

South Korea's bank breaches show AI is cutting the cost of finding holes

South Korea links AI to hacks that exposed customer data at seven financial firms, and the target was third-party systems, not core payment networks.

South Korea's president, Lee Jae Myung, said on Tuesday that recent hacks exposed user data at seven financial firms, with indications that AI was used in some of the incidents. The Financial Times reported his remarks, and PYMNTS picked up the story. No money has been reported stolen, but one official called it "a completely new kind of crisis".

Pay attention to where the attackers went. They seem to have skipped the banks' core payment networks and gone after weaker systems run by third parties. In one case, a hacker bypassed identity checks on a portal where loan brokers track customers' applications, exposing the details of roughly 25,000 Shinhan Bank customers. That is a very ordinary kind of hole, in a very ordinary kind of system.

Illustration of a bank building with a glowing digital padlock and a hooded figure probing a side entrance on a screen
The reported entry point was a third-party portal, not the bank's payment core.

Where does AI come in? Moon Jong-hyun of the Genians Security Center says the attacks appear to have used Artex, an open-source, Chinese-language tool that applies AI to spotting and testing vulnerabilities. He compared it to a kitchen knife: a chef's tool or a criminal's weapon, depending on the hand. We would add that a knife does not scan thousands of doors by itself. A tool that does is a different kind of object, even if the intent is the same.

The PYMNTS analysis that accompanies the news makes the sharpest point: AI is not inventing a new class of problem, it is industrializing an old one. Mapping an application, reading its documentation, tracing authentication flows and probing configurations used to take expensive human hours. Automation compresses that work. The same piece cites two security researchers, aged 16 and 19, who found flaws at Microsoft and the Department of Justice. The bugs were not exotic; the leverage was.

That asymmetry is the part defenders should lose sleep over. A company can spend millions hardening a sprawling estate while someone with the right tooling searches it for gaps at a fraction of the old cost. And the soft spots are rarely the crown jewels. They are the partner portals, the broker dashboards, the integrations nobody has audited since they were wired up.

Our take: be skeptical of the "AI hackers" framing and just as skeptical of anyone who waves it away. The evidence here is still partial, with talk of indications and a tool that seems to have been used. But the practical lesson holds either way. Your security is only as good as your least-watched third party, and attackers who can test everything cheaply will find it. Audit the boring perimeter first.

Original source: PYMNTS.com

Produced with AI support and reviewed by the newsroom

Byline

· Chief editor · English edition · London

“Call it an AI crisis if you like, but the door that opened was a loan broker portal with a broken identity check.”

Comentarios

Publicar un comentario