
The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.
Hackers used AI agents to launch widespread cyberattacks on South Korean banks, savings banks, and financial firms, resulting in data breaches affecting tens of thousands of customers. The attacks exposed limitations in existing security measures, prompting authorities to consider a comprehensive overhaul of financial sector cybersecurity.[AI generated]
Why's our monitor labelling this an incident or hazard?
The article explicitly mentions the use of AI agents by hackers to conduct attacks on multiple financial institutions, resulting in confirmed data breaches affecting tens of thousands of individuals. The AI system's use in the attack is a direct cause of harm, specifically violations of privacy and data security, which fall under violations of human rights and legal protections. The harm is materialized, not hypothetical, and involves multiple organizations and individuals. The event also discusses the failure of existing security measures to prevent these AI-driven attacks, reinforcing the classification as an AI Incident rather than a hazard or complementary information.[AI generated]