South Korea, Japan buffeted by hacks as AI lowers bar for cybercriminals
Nine South Korean banks and two mega-churches are probing cyberattacks that may have involved AI tools, while Japanese companies including Daiwa Securities, SoftBank Corp and the Lawson convenience store chain have been hit by a recent surge in cyber incidents.
South Korea and Japan are grappling with a surge of cyber attacks that experts claim are fueled by the accessibility of AI tools. Nine South Korean banks and two major religious institutions are investigating potential AI involvement in recent breaches, while Japanese companies like Daiwa Securities, SoftBank, and Lawson have also faced a spike in cyber incidents.
Authorities are still determining if AI played a role in many of these breaches, but cybersecurity experts say the technology is automating tasks like vulnerability scanning and phishing campaign creation, making cybercrime easier, cheaper, and harder to detect. AI doesn't tire and eliminates language barriers that once hindered foreign hackers, said cybersecurity expert Nobuo Miwa.
Japan recorded more cyber incidents in the first nine months of the year than in all of the previous year, with September incidents up 18% from the previous month. The rise suggests attackers have crossed a threshold in effort, motivation, and technical capability, and AI has largely removed linguistic barriers.
A suspected 26-year-old China-based attacker behind the South Korean bank attacks used AI tools, according to cybersecurity firm CrowdStrike. While the hacker's skills were not advanced, they were effective, said CrowdStrike senior vice president Adam Meyers.
AI-powered tools are making it harder for defenders to spot suspicious behavior, said Choi Kyoungjin, director of the Center for AI, Data, and Policy at Gachon University. With general-purpose AI models, even ordinary users with malicious intent can easily find vulnerabilities.
South Korea reported a 20% increase in cyber incidents in the first half of the year, with distributed denial-of-service (DDoS) and ransomware attacks rising 56.7% and 76.8%, respectively. The bank incidents highlight the need for stronger security controls and rigorous testing as AI evolves, Meyers said.
Regulators in both countries are responding to the threat. South Korea's Financial Services Commission has directed entities to complete a 12-point cybersecurity self-assessment, and Japan's digital transformation minister has convened a meeting of ministries and agencies to address the attacks. Experts warn that defenses need a breakthrough as the landscape changes.
Written by urgent.news from Economic Times Tech's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.