By Kyu-seok Shim, Brenda Goh and Kentaro Okasaka
SEOUL/TOKYO, Oct 9 (Reuters) – South Korean and Japanese companies are racing to strengthen cyber defences after a wave of attacks that cybersecurity experts say are highlighting how AI may be lowering the bar for criminals with limited technical skills.
Nine South Korean banks and two mega-churches are probing cyberattacks that may have involved AI tools, while Japanese companies including Daiwa Securities, SoftBank Corp and the Lawson convenience store chain have been hit by a recent surge in cyber incidents.
Authorities are still investigating whether and how AI was used in many of the breaches. But cybersecurity specialists say the technology is helping attackers automate tasks from scanning for software vulnerabilities to crafting phishing campaigns, making cybercrime faster, cheaper and harder to detect.
“AI doesn’t get tired… My view is that Japan is essentially being subjected to carpet bombing,” said Nobuo Miwa, president of Tokyo-based cybersecurity firm S&J Corp.
Japan recorded more cybersecurity incidents in the first nine months of the year than in all of last year, according to data from TrendAI. Incidents rose to 86 in September, up about 18% from August and 37% from July.
The rise suggests attackers have crossed a threshold in “effort, motivation and technical capability,” while AI has largely erased language and other barriers that once hindered foreign hackers, Miwa said.
US cybersecurity company CrowdStrike said a suspected 26-year-old China-based attacker behind the South Korean bank incidents would probably not have been able to carry out the campaign without AI assistance.
The individual, whom CrowdStrike assessed was pursuing financial gain, used a Chinese-developed AI agent and Anthropic’s Claude Code, according to the company.
“While (the hacker’s) capabilities were not terribly sophisticated they were effective,” said Adam Meyers, CrowdStrike’s senior vice president of counter adversary operations.
HARD-TO-DETECT ATTACKS
AI-powered tools are also making it harder for defenders to spot suspicious behaviour, said Choi Kyoungjin, director of the Center for AI, Data and Policy at Gachon University near Seoul.
“With general-purpose AI models, even ordinary users with malicious intent can ask the system to look for vulnerabilities and it will do much of that work for them,” he said.
South Korea reported 1,236 cyber incidents in the first half of the year, up 20% from a year earlier. While server hacking cases fell, reports of distributed denial-of-service (DDoS) attacks and ransomware rose 56.7% and 76.8% respectively, according to government data.
The South Korean bank incidents underscored the need for stronger security controls and more rigorous testing as AI evolves, Meyers said. “The genie is out of the bottle, so to speak.”
Although the breaches have not yet resulted in material financial losses, risks could increase if stolen data is used in phishing or similar text-message “smishing” campaigns, Karen Wu, senior analyst at Fitch, wrote in a note.
“We expect the incidents to result in regulatory penalties, customer compensation costs, and a sector-wide increase in cybersecurity spending,” Wu said.
DEFENCES NEED THEIR OWN BREAKTHROUGH
Warnings about AI’s growing role in cybercrime are increasingly coming from the technology’s developers.
Alphabet’s Google and Anthropic have both warned that AI-assisted attacks are becoming more common globally.
“At this point, we can assume that all threat actors are using AI in some capacity and their operations have benefited,” John Hultquist, the chief analyst at Google’s Threat Intelligence Group, said last month.
Regulators in Japan and South Korea have begun responding.
South Korea’s Financial Services Commission has directed financial industry associations, regulators and affected executives to complete a 12-point cybersecurity self-assessment.
In Japan, digital transformation minister Toshiharu Furukawa convened a meeting of ministries and agencies on Thursday following the recent attacks. The National Cybersecurity Office plans to issue warnings to businesses.
S&J’s Miwa said he expected elevated levels of cyberattacks to persist.
“The attackers have experienced a breakthrough that has rendered many of the old assumptions obsolete,” he said.
“Our defences need their own breakthrough as well.”
(Additional reporting by Maggie Grether and Joyce Lee in Seoul, Chang-ran Kim in Tokyo and Raphael Satter in Washington; Writing by Brenda Goh; Editing by Sam Nussey, Miyoung Kim and Jamie Freed)



Comments