
AI-generated summary
Recently, personal information leakage incidents have continued to occur in banks, online platforms, general companies, and public institutions, and there are concerns in the security industry that the leaked information could be combined with generative artificial intelligence and used for precise targeted attacks.
Income, loans, workplace, and contact information are exposed everywhere... Combined with a precise personal profile
AI-based target selection and customized phishing... Analysis of stolen overseas mailboxes
(Seoul = Yonhap News) Reporter Shim Jae-hoon = "Customer, we have contacted you to confirm the credit loan you received last month."
Honestly, if the call comes from someone who knows my name, my workplace, and even the loan details from my bank, it's not easy to suspect phishing.
Recently, personal information leakage incidents continue to occur in commercial banks, online platforms, general companies, and public institutions. There are concerns in the security industry that leaked personal information could be combined with generative artificial intelligence (AI) and used for precision-targeted attacks.
Spear phishing, which involves throwing customized lures targeting specific people, is not a new method. However, in the past, attackers had to manually search through portal sites and social media (SNS) to select targets and refine phrases, but now AI is taking over that role.
Microsoft (MS) warned in a threat analysis released this year that attackers are using generative AI to create phishing phrases, target targets, and analyze stolen data.
◇ Income and loans for banks, contact information for platforms… Scattered personal information
Just by looking at the recent series of leaks in Korea, we can get an idea of how many places personal information is being distributed.
Shinhan Bank announced on the 1st that an external unauthorized person accessed some loan-related services by bypassing the authentication process. The number of affected customers was estimated to be around 25,000.
The first site the attacker penetrated was the mobile homepage service where loan originators check the status of customer loan applications. Customer names, phone numbers, annual income, calculated loan limits, etc. were missing. 66 resident registration numbers and 97 linked information (CI) were also included.
A security industry analysis also revealed that traces of AI infiltration tools were found on the server believed to have been used in the attack.
Moon Jong-hyun, head of the Genius [263860] Security Center, announced through LinkedIn that he had confirmed the Chinese phrase 'ARTEX-AI Autonomous Penetration Test Console' in the HTML title of the web server that appears to have been used in the attack. ARTEX is a Chinese-centric open source penetration testing tool based on the Large Language Model (LLM). It has not been officially confirmed by financial authorities or Shinhan Bank whether this tool was actually used in the attack.
At KB Kookmin Bank, the personal and credit information of 119 customers was leaked through an external intrusion. The bank explained that the breach was a mobile business support system for employees and had nothing to do with customer financial transactions. Names, phone numbers, addresses, and encrypted resident registration numbers were missing, and the items differ for each customer.
Hana Bank announced that the information of 89 customers was leaked due to external hacking forces abnormally accessing the Sales Support System (ODS). It included the resident registration number, name, address, email address, phone number, and even the name of the employer.
At BNK Busan Bank, the personal information of 11 outsourced development employees was exposed, but no customer information leaks were confirmed. Woori and NH Nonghyup Bank announced that although there was a hacking attempt, customer information was not stolen.
Personal information leaks are not limited to banks.
KEPCO announced in a statement distributed on the 4th that the names, affiliations, and phone numbers of approximately 24,000 KEPCO employees were exposed on an external web page.
Online video service (OTT) Tving had a large amount of member information leaked last June. Member ID, name, date of birth, gender, phone number, email, etc. were included, and the amount of damage was calculated to be 19.53 million. It is the fourth largest domestic leak, following Coupang (about 37.56 million people), Cyworld/Nate (about 35 million people), and SK Telecom [017670] (about 23.24 million people).
In this way, customers' income and loan details are stored in banks, and contact information and date of birth are stored in telecommunication companies and platforms. When viewed separately, the information is fragmentary, but when put together, a person's profile can be created precisely.
◇ AI-based target selection and customized bait… Phishing click-through rate 4.5 times higher
Targeted phishing using AI has already been reported several times overseas.
In this year's report, Microsoft said that attackers customize phishing messages based on the target's job title, affiliation, and recent activities, and that phishing is becoming more sophisticated, with AI even quickly changing phrases to match the target's native language and tone of voice.
Attackers used generative AI to create emails tailored to the target's business and used proposal requests, invoices, and manufacturing processes as materials. Afterwards, a method was used to first select financial managers and executives by automatically analyzing public profiles and in-house address books.
MS said that in phishing attacks incorporating AI, click-through rates reached up to 54%, which was 4.5 times higher than existing methods. However, MS analyzed that most attacks are still led by humans and that AI is not at the stage where it can attack on its own from start to finish.
The time it takes to attack is also decreasing. According to a report last month from the Google Threat Intelligence Group (GTIG), in the second quarter of last year, an attacker took control of cloud resources and mobilized AI agents to plan, create, and execute a large-scale credential theft operation in less than six hours.
◇ AI analyzes even stolen mailboxes… Choose your ‘next prey’
AI is also used to find the next target in breached accounts.
A representative example is 'EvilTokens,' a service-based phishing platform that Microsoft blocked last month. It is said to be sold for $500 per month to use the phishing function on Telegram.
The platform's method is to have victims click on a link, which leads them to an official Microsoft login page, where they are encouraged to enter a code. At that moment, the victim unknowingly transfers account access to the attacker.
From there, the attackers used AI to analyze mailboxes to find conversations involving money, then identify employees they could target and decide who to impersonate. Microsoft estimated that about 12,000 email inboxes from 10,000 organizations, including construction, finance, universities, and medical, were breached through this platform.
Security company Check Point believed that 'EvilTokens' were created with AI and that LLM was a commercial service directly connected to the attack execution process.
It is pointed out that once such an advanced function is created, any buyer can use it, greatly lowering the threshold for fraud using AI.
◇ Even if I know my information accurately, I have doubts… Confirm with official app/main number
Until now, awkward spelling or unusual requests have been key clues in detecting phishing. However, if the other person knows exactly my name, workplace, and even the most recent loan I received, and approaches me verbally, the story is different.
It has not yet been confirmed that information leaked from the domestic financial sector was combined with data leaked from other sources using AI and used to commit actual crimes.
However, overseas, cases of using AI to analyze stolen information and public data to select targets and create bait have already been revealed.
KB Kookmin Bank warned customers not to click on links in texts or emails from unknown sources, and not to respond when asked for personal or financial information. TVING also advised users to change their passwords for other services that use the same ID and password immediately after the incident.
First of all, if you receive a call from a financial institution or someone claiming to confirm a leak, it is best not to use the link or number in the message. It is basic to check directly with the official app or representative number. If you turn on multifactor authentication (MFA) and use different passwords for each site, you can prevent your account from being stolen.
Nowadays, we live in an era where we need to be suspicious if the other person knows too much about us.
AI outlook — possibilities, not facts
Targeted phishing attacks using generative AI are expected to increase in Korea as well.
Likely · Within months
Financial institutions and platform companies are expected to pursue additional investments and expansion of multifactor authentication (MFA) to protect personal information.
Very likely · Within weeks

Avery Ching, co-founder and CEO of Aptos Labs, predicted at a press conference in Seoul that future finance will become an on-chain blockchain economy, and said that Aptos viewed regulations as design requirements and built an infrastructure that prioritizes safety and security. He also emphasized the possibility of combining stablecoins and AI in the Korean market and said that he is planning to expand tokenization asset pilot projects through collaboration with institutions.

Google has revamped its AI Gemini plan to block access to the 'Pro' model for free and low-cost subscribers, and is seeking to attract subscribers to the high-priced plan ahead of the launch of its new top model, 'Gemini 4 Argon'.

US President Donald Trump named artificial intelligence (AI) 'super intelligence (SI)' and launched a White House task force dedicated to this. Director of National Intelligence Jay Clayton has been appointed AI czar, tasked with coordinating cooperation between the government and private companies and securing America's technological leadership.

State-run Korea Electric Power Corp. announced that personal data of roughly 24,000 employees was leaked on an external website. The exposed data includes names, titles, and phone numbers, though sensitive information remained safe.

The Ministry of Science and ICT has launched a 24-hour emergency response system with the Korea Internet & Security Agency (KISA) in relation to the recent financial hacking incident and has begun to prevent the spread of the virus to the private sector and further damage.

From January to August of this year, there were approximately 240,000 hacking attempts targeting the court computer network, significantly exceeding the number of hacking attempts for the entire year last year. In addition, cases of personal information leakage due to mistakes by internal employees or AI-related factors were found to have increased significantly compared to previous years.