韩国7家主要金融机构上周遭遇网络攻击,导致约68000名客户的个人数据被窃取1。被泄露的信息包括姓名、电话号码、年收入和贷款额度,以及部分客户的国民身份证号码1。韩国政府随后发现,两家该国最大的教堂及韩国电力公司的在线系统也遭到非法入侵1。
韩国总理韩锡勋对此次事件表示,攻击据信利用了人工智能技术,强调如果AI被用于网络钓鱼攻击中,可能造成二次伤害1。调查发现,黑客使用了名为ARTEX的开源渗透测试工具,该工具由中国开发者构建1。美国网络安全公司CrowdStrike的初步报告显示攻击可能源自中国,韩国金融监督服务确认了来自美国、日本、德国和至少10个其他国家的28个IP地址参与了银行攻击1。
黑客利用了外部贷款招聘人员使用的门户、员工移动工具和销售支持系统中的弱认证协议实施入侵1。受影响最严重的金融机构包括新韩银行、KB国民银行和哈纳银行1。专家指出,生成式AI工具可以协助编写计算机代码、分析软件漏洞、处理大量信息并自动化网络运营的某些阶段1。
South Korea's government has raised alarms over a coordinated cyberattack targeting multiple financial institutions, warning that artificial intelligence played a key role in the breach. Seven major banks suffered compromised defenses last week, resulting in the theft of approximately 68,000 customers' personal data, including names, phone numbers, annual income, and loan amounts.1 The attack extended beyond the financial sector, with two of South Korea's largest churches and the Korea Electric Power Corporation confirming unauthorized access to their online systems.1
Prime Minister Han Seok-kyun emphasized the urgent need for preventive measures, noting that the incident was believed to have leveraged artificial intelligence technology.1 He specifically cautioned that if AI is employed in phishing attacks, it could inflict secondary damage on victims.1 Investigators identified the use of ARTEX, an open-source penetration testing tool developed by Chinese programmers, in executing the breach.1 IP addresses from at least 28 locations—including the United States, Japan, Germany, and more than ten other countries—were traced to the bank intrusions.1 The attackers exploited weak authentication protocols in systems used by external loan recruitment personnel, employee mobile tools, and sales support systems.1
Security researchers at U.S. firm CrowdStrike indicated the attack likely originated in China.1 Experts note that generative AI tools can assist in writing computer code, analyzing software vulnerabilities, processing large volumes of information, and automating certain stages of network operations,1 potentially lowering the technical barriers to cybercrimes and enabling more frequent and widespread attacks across diverse industries.
评论
还没有评论,欢迎留下第一条。