AI-driven cyberattacks put South Korea and Japan on high alert

0
122
AI-powered attacks put South Korea and Japan’s cyber defences to the test
AI-powered attacks put South Korea and Japan’s cyber defences to the test

A growing wave of cyber incidents across South Korea and Japan is raising concerns that artificial intelligence is making it easier for less-skilled criminals to launch effective attacks.

In South Korea, 9 banks and 2 mega-churches are investigating cyberattacks that may have involved AI tools. In Japan, companies including Daiwa Securities, SoftBank and convenience store chain Lawson have also faced a recent rise in cyber incidents.

Investigations are still underway to determine how AI was used in these cases. However, cybersecurity experts say attackers are using the technology to automate vulnerability scans and create phishing campaigns, making attacks faster, cheaper and more difficult to detect.

“AI doesn’t get tired… My view is that Japan ​is essentially being subjected to carpet bombing,” said Nobuo Miwa, president of Tokyo-based cybersecurity firm S&J Corp.

Japan recorded more cybersecurity incidents in the first 9 months of the year than during all of last year, according to data from TrendAI. Incidents reached 86 in September, up 18% from August and 37% from July.

CrowdStrike said a suspected 26-year-old attacker based in China, linked to the South Korean bank incidents, would probably not have been able to carry out the campaign without AI assistance. The individual allegedly used a Chinese-developed AI agent and Anthropic’s Claude Code for financial gain.

“While (the hacker’s) capabilities were not terribly sophisticated they were effective,” said Adam Meyers, CrowdStrike’s senior vice president of counter adversary operations.

South Korea reported 1,236 cyber incidents in the first half of the year, up 20% year-on-year. While server hacking cases declined, DDoS attacks increased 56.7% and ransomware incidents rose 76.8%.

Experts warn that stolen data could later be used for phishing and text-message “smishing” scams. Fitch analyst Karen Wu said the incidents could lead to regulatory penalties, customer compensation and higher cybersecurity spending.

Technology developers Google and Anthropic have also warned about the growing use of AI in cyberattacks. Google’s threat intelligence chief John Hultquist said, “At this point, we can assume ​that all threat actors ⁠are using AI in some capacity and their operations have benefited,”

South Korea’s Financial Services Commission has ordered financial industry groups, regulators and affected executives to complete a 12-point cybersecurity self-assessment. In Japan, digital transformation minister Toshiharu Furukawa convened a meeting of government agencies, while the National Cybersecurity Office plans to issue warnings to businesses.

Miwa expects attacks to remain elevated.

“The attackers have experienced a breakthrough that has rendered many of the old assumptions obsolete,”

“Our defences need their own breakthrough as well.”

Also read: Viksit Workforce for a Viksit Bharat

Do Follow: The Mainstream LinkedIn | The Mainstream Facebook | The Mainstream Youtube | The Mainstream Twitter

About us:

The Mainstream is a premier platform delivering the latest updates and informed perspectives across the technology business and cyber landscape. Built on research-driven, thought leadership and original intellectual property, The Mainstream also curates summits & conferences that convene decision makers to explore how technology reshapes industries and leadership. With a growing presence in India and globally across the Middle East, Africa, ASEAN, the USA, the UK and Australia, The Mainstream carries a vision to bring the latest happenings and insights to 8.2 billion people and to place technology at the centre of conversation for leaders navigating the future.