
AI-generated summary
Recently, interest in personal security is increasing as large-scale account takeover attacks using artificial intelligence have shaken the defense networks of major domestic commercial banks such as Shinhan Bank, KB Kookmin Bank, and Hana Bank.
Replacing passwords leads to serial hijacking... Pay special attention to email accounts
Set up MFA and check for suspicious logins... Do not click on the ‘Leak Inquiry’ link
(Seoul = Yonhap News) Reporter Shim Jae-hoon = Recently, large-scale account takeover attacks using artificial intelligence (AI) have shaken the defense networks of major domestic commercial banks such as Shinhan Bank, KB Kookmin Bank, and Hana Bank, drawing attention to the personal security that users must take care of themselves.
Although individuals cannot prevent breaches that occur at companies, secondary damage from leaked account information spreading to other financial and shopping accounts can be significantly reduced depending on how users respond.
The security industry agrees that simply using a separate password for each site and turning on multi-factor authentication (MFA) significantly reduces the risk of account takeover.
◇ If the portal is breached, your bank account is also at risk... ‘Credential stuffing’ warning
The first threat that arises when a leak occurs is ‘credential stuffing.’
This is a method of putting a list of IDs and passwords extracted from one service into an automated tool and attempting to log in to banks, open markets, portals, social networking services (SNS), etc. It targets the fact that many users use the same account information on multiple sites because it is easy to memorize.
Recently, with the addition of generative AI and sophisticated automated scripts, the scale and precision of attacks have increased. Not only does it pour in a huge amount of login attempts in a short period of time, it also compiles scattered personal data to select attack targets.
The first defense that experts recommend is not to rewrite your password.
AhnLab [053800] recommended creating completely different passwords for each service. The explanation is that modifications such as adding a number or one or two special characters to the end of an existing password are something that attack tools can easily find, so it is best to avoid them if possible.
The place you need to pay the most attention to is your email account. Email is used as a way to verify identity and reset passwords in most web services. If one email goes through, a series of bank and shopping mall accounts tied to it can be breached.
If you receive a notification that your personal information has been leaked on a site, it is not enough to simply change the password for that site. You can prevent the spread of damage by finding all other sites that use the same password and changing them one by one.
The next line of defense after passwords is MFA, so-called two-step authentication.
Even if the ID and password fall into the hands of an attacker, the possibility of unauthorized access is greatly reduced as additional barriers such as biometric authentication or an authentication app (OTP) must be overcome. If you have never logged in and you receive a notification requesting authentication or approval on your smartphone, it is safe to never approve it and change your password right away.
◇ “Check if it has been leaked”… Phishing and smishing targeting immediately after an accident
We must also be wary of the flood of phishing and smishing texts following the personal information leak incident.
Attackers induce users to click on malicious links (URLs) with phrases such as ‘Confirm personal information leakage’, ‘Pay compensation for damages’, and ‘Apply for account protection’. In fact, it is easy to click on it without thinking as it is often disguised as an official information from a financial company with a leaked name or phone number.
Do not click on links in text messages or emails whose source you are not sure about. You need to get into the habit of running the financial company's official app directly or entering the address directly into the browser address bar.
It is also helpful to check your login history regularly.
If there is evidence of accessing from an unfamiliar area or from a device you have never seen before, or if you receive instructions to change your password that you did not request, click 'Log out from all devices' and set a new password. It is also necessary to check whether the account recovery phone number or secondary email has been changed to someone else's.
On a public PC shared by multiple people, do not use the browser's automatic login or password saving functions, and be sure to log out when you are finished using it.
Personal PCs and smartphones must also be periodically checked with antivirus and the operating system (OS) is kept up to date to prevent malware infection that steals account information stored in the browser.
◇ Corporate responsibility is also heavy… “API and internal network control must be strengthened”
No matter how careful an individual is, it is impossible to prevent all cyber crimes, so companies that directly handle customer data must pay attention to their security systems.
AhnLab pointed out that companies should make application program interface (API) authentication and access control more stringent, and have a surveillance system that can catch abnormal repeated calls or bulk inquiries in real time.
He said that the scope of surveillance should not be limited to customer webs and apps, but should also be expanded to include internal management networks and outsourcing and partner linkage systems. We also ordered data management principles that minimize the amount of customer personal information stored on a regular basis.
An AhnLab official emphasized, "Once account credentials are leaked, attackers use this as a stepping stone to launch serial attacks. Users must follow basic rules such as separating passwords for each site and applying multi-factor authentication, and companies must operate a three-dimensional defense network, such as upgrading the abnormal login detection system."
AI outlook — possibilities, not facts
Secondary account takeover damage due to the practice of password reuse will continue to increase.
Likely · Within months
Companies' API and internal network security controls will be strengthened.
Possible · Within months

A terminology debate is erupting in the United States after U.S. President Donald Trump signed an executive order requiring the use of 'super intelligence (SI)' instead of 'artificial intelligence (AI)' in federal government documents and external communications. This is interpreted as an intention to alleviate negative public opinion about AI and maintain an edge in technological competition with China.

The Wall Street Journal criticized AI companies for using cute characters to hide the risks of technology and build a friendly image. Open AI's 'Dots', Meta's 'Muse', and Antropic's 'Claude' were presented as examples, and experts were concerned that these strategies could attract children and adolescents.

During a hacking attack targeting major domestic banks such as Shinhan Bank, traces of 'ARTEX AI', a Chinese-based open source tool in which an artificial intelligence (AI) agent automatically performs the hacking process, were discovered, putting the entire financial sector on a security alert.

Following Shinhan, Kookmin, and Hana Bank, the personal information of 11 outsourced development employees was leaked at BNK Busan Bank through external hacking using an AI agent. Busan Bank immediately blocked the web page and reported it to the financial authorities, and announced that there was no leak of customer information.

Samcheok City in Gangwon-do was selected by the Ministry of Science and ICT for the '2027 Smart Village Supply and Expansion Project' and will invest 3 billion won by 2029 to build an AIoT-based maritime safety management system.

KB Kookmin Bank announced that about 100 pieces of customer information were leaked due to an external intrusion through the mobile work support system for employees. This is the second commercial bank hacking incident following Shinhan Bank, and financial authorities are discussing response measures considering the possibility of further spread of damage.