AI-Driven Cyberattacks Surge in South Korea and Japan

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

Banks, businesses, and churches in South Korea and Japan have faced a surge in cyberattacks, with AI tools enabling criminals to automate vulnerability scans and phishing campaigns. The incidents have led to increased operational disruptions, financial risks, and heightened cybersecurity costs, prompting urgent defensive measures.[AI generated]

Why's our monitor labelling this an incident or hazard?

The article explicitly states that AI tools were used by cybercriminals to conduct attacks on banks and companies, leading to increased cyber incidents and investigations. The harms include disruption to organizations, potential financial losses, and risks to customers through phishing and smishing campaigns. The AI system's use in automating and enhancing attacks directly contributed to these harms. Although some financial losses have not yet materialized, the ongoing incidents and regulatory responses indicate realized harm and significant impact. Hence, this event meets the criteria for an AI Incident rather than a hazard or complementary information.[AI generated]
AI principles
Robustness & digital securitySafety

Industries
Financial and insurance servicesDigital security

Affected stakeholders
Business

Harm types
Economic/Property

AI system task:
Event/anomaly detectionContent generation


Articles about this incident or hazard