AI-Driven Cyberattacks Target South Korean Financial Institutions

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

Hackers used AI agents to launch widespread cyberattacks on South Korean banks, savings banks, and financial firms, resulting in data breaches affecting tens of thousands of customers. The attacks exposed limitations in existing security measures, prompting authorities to consider a comprehensive overhaul of financial sector cybersecurity.[AI generated]

Why's our monitor labelling this an incident or hazard?

The article explicitly mentions the use of AI agents by hackers to conduct attacks on multiple financial institutions, resulting in confirmed data breaches affecting tens of thousands of individuals. The AI system's use in the attack is a direct cause of harm, specifically violations of privacy and data security, which fall under violations of human rights and legal protections. The harm is materialized, not hypothetical, and involves multiple organizations and individuals. The event also discusses the failure of existing security measures to prevent these AI-driven attacks, reinforcing the classification as an AI Incident rather than a hazard or complementary information.[AI generated]
AI principles
Privacy & data governanceRobustness & digital security

Industries
Financial and insurance services

Affected stakeholders
ConsumersBusiness

Harm types
Human or fundamental rightsEconomic/Property

Business function:
ICT management and information security

AI system task:
Goal-driven organisation


Articles about this incident or hazard