Safety2 min read

AI Attackers Try Every Side Door, Big Bank or Small Firm

By , Senior AI ConsultantPublished

A free AI agent broke into seven South Korean financial firms through loan-agent portals and staff apps, while the two big banks with no such open door lost nothing.

An open-source AI tool called ARTEX, built to help companies test their own security, was pointed at South Korean banks and lenders, and it found a way into at least seven of them. Korea's Financial Security Institute says a person directed it; the tool did the searching. What it found was never the banks' core systems. It found the web systems built around them for loan agents, staff phones and outside developers.

An agent does not choose targets the way a person does

A skilled human attacker has a limited number of weeks, so they study one bank and ignore its neighbors. An agent scans for weaknesses, adjusts to what it finds and moves on, so one more target costs almost nothing. That is why Yegaram Savings Bank, a small lender few people outside Korea know, lost records on about 40,000 customers, more than Shinhan did. A human crew would probably not have bothered with it.

Side doors are not new. In 2013, attackers stole about 40 million payment card numbers from the US retailer Target after getting in through its heating and air-conditioning contractor. Someone had to find that contractor first, which took skill and time. In Korea the finding was automated, and the loan agent's portal played the contractor's part, at every lender in range.

Security spending did not decide who was safe

The three banks that lost data spent about $92 million on information security last year, mostly guarding their core networks. Meanwhile they had cut branches and pushed sales to outside agents and mobile staff, and each new channel got its own app or portal, built for convenience. The Financial Security Institute named three recurring faults: lookup services that never checked who was asking, loose controls on staff phones, and known web flaws nobody had patched. None needs cleverness to fix. Each can be checked in an afternoon, and the two banks that held had already done the equivalent.

The stolen data is a script for phone scams

What leaked was names, phone numbers and, at some firms, income and loan limits. A caller who knows your loan limit sounds exactly like your bank, which is why Korean regulators warned that voice-phishing calls and scam texts could follow. Knowing your details proves nothing about the caller. If someone rings about a loan, hang up and call the number printed on your card.

What this means for a company of ordinary size

Take a regional distributor with a price-lookup page for sales reps, a portal where suppliers upload invoices, and an app for drivers. Each was built for convenience, each has a login, and nobody has ever looked at them together. Ten such pages is ten doors an agent tries in one night. It needs only one to open, for example with a password an employee reused from an old leak. Credential stuffing, one of the likely methods in Korea, is exactly that: automated tries with passwords already stolen elsewhere.

AI hacking tools were already within reach of small businesses, and the banks show the same tools working against companies with large security budgets. So the useful first step is a list of every login page your company has on the internet. It is usually longer than anyone expects. Remove the ones nobody needs, put a second check on the rest, and run a tool like ARTEX against your own pages, with permission, to see the list an attacker would see.

Share this

STAY INFORMED

Get AI intelligence like this delivered to your inbox.

Free forever · Unsubscribe anytime


You May Also Find Valuable