AI is bringing old vulnerabilities into the light of day
The recent Korean bank hacks show how AI is bringing existing cyber security weaknesses out of obscurity and into the light of day.
I was talking with the BBC in Singapore recently about the Korean bank hacks. There has been a lot of focus on the role of AI, but for me the bigger issue is how much easier it has become to find existing vulnerabilities. What was once hidden by obscurity is now in the light of day.
These were not necessarily new vulnerabilities or novel attacks. Reporting on the incidents points to AI automating and accelerating existing attack techniques.
AI has made existing vulnerabilities much easier to find. What was once hidden by obscurity is now in the light of day.
An old staff portal. A loan application service. A web page that nobody has reviewed for years. These things do not become secure just because they are out of sight. But finding and investigating them used to take more time and effort. AI is significantly reducing that effort.
The weakness was already there. It is now so much easier for someone who is using modern AI tools to find it and work out how to exploit it.
The basics still matter
American Banker reports that the attackers targeted supporting systems, including loan recruiter services and employee work-support applications. Reported weaknesses included inadequate session validation at BNK Busan Bank and a bypassed mobile-phone verification step at Shinhan Bank.
These are basic access-control issues. The involvement of AI does not change that.
We should be careful about saying the banks had no cyber protection. The issue is that protection was inadequate in some of the systems holding or providing access to sensitive information. Having security controls in one part of an organisation does not compensate for weaknesses elsewhere.
There is a tendency to focus security effort on core systems and treat everything else as less important. But a supporting application that exposes customer financial information is not a minor concern. The customer does not care whether their data was stolen from the core banking platform or an application used by a loan recruiter.
“We did not think anyone would find that” was never a security control.
They were not detecting the attacks quickly enough
The delays in detection are another important part of this story.
Reporting based on information submitted to South Korea’s National Assembly puts the detection time at approximately 68 hours for KB Kookmin, almost 42 hours for Hana, and around 15 hours for Shinhan. At KB Kookmin, the attack had reportedly ended approximately 25 hours before the bank detected it.
That raises questions about more than prevention. What was being monitored? Which activity would trigger an alert? Who was responsible for investigating it?
The available reporting does not tell us exactly which monitoring controls failed at each institution. But the delays matter. If attackers can find and exploit weaknesses faster, organisations cannot afford to discover the activity long after it has finished.
Management cannot rely on things staying hidden
For management, the question is not just whether the organisation is ready for AI-enabled attacks. It is whether the organisation has dealt with the weaknesses it already has.
Do we know which systems are exposed to the internet? Who owns them? What information can they access? Have their access controls actually been tested? Would we notice someone retrieving customer records they should not be able to see?
These are not new questions. AI makes leaving them unanswered more dangerous.
An overlooked system is still your system. The customer information it exposes is still your responsibility. Calling it peripheral does not make the consequences peripheral.
AI did not create these management responsibilities. It is making the gaps harder to hide.
Go check if your organisation has (at least) the basics in place!