据韩联社报道,针对韩国新汉银行(Shinhan Bank)的网络攻击可能使用了先进的人工智能工具,导致约2.5万名客户的个人信息被泄露,这凸显了自动化黑客攻击对金融机构构成的威胁。
By Soobin Kim Advanced artificial intelligence tools may have been used in a cyberattack on South Korea’s Shinhan Bank Co. that exposed information on about 25,000 customers, Yonhap News reported, highlighting the risk of automated hacking against financial institutions.
韩联社援引网络安全专家的话指出,攻击者很可能利用了复杂的人工智能技术来探测系统漏洞,并非法访问了该银行用于贷款审批的相关系统。
Attackers probably used sophisticated AI agents to probe for vulnerabilities and gain unauthorized access to a service used by loan recruiters, Yonhap said, citing cybersecurity experts.
新汉银行(隶属于新汉金融集团)周四表示,有外部人员未经授权访问了该银行的某些系统并获取了客户信息。该行正在与相关部门及外部网络安全专家合作,调查事件的原因、影响范围及潜在后果。
Shinhan Bank, a unit of Shinhan Financial Group Co., said Thursday that an unauthorized external party accessed certain services and obtained customer information. The lender is investigating the cause, scope and potential impact with authorities and outside cybersecurity experts.
“目前,新汉银行尚无法准确评估此次事件对其财务状况、经营业绩或业务活动的具体影响,”该行在声明中称。被泄露的客户信息包括姓名、电话号码、年收入以及借款额度。
“At this time, Shinhan Bank is not in a position to reasonably quantify the specific impact of the incident, if any, on its financial condition, results of operations or business activities,” it said. Information exposed in the breach included customer names, phone numbers, annual income and borrowing limits, the bank said.
这一事件凸显了人工智能带来的新网络安全风险:黑客可以利用人工智能技术自动化地搜索大量系统中的安全漏洞。
The incident highlights an emerging cybersecurity risk as AI allows hackers to automate the search for security gaps across large numbers of systems.
韩国金融监管机构表示已启动紧急现场检查,以查明此次攻击的性质和范围。此前,另一家韩国银行也因数据安全问题而受到关注——KB国民银行(KB Kookmin Bank)周五宣布,有119名客户的个人信息因外部入侵而被泄露。
South Korea’s Financial Supervisory Service began an emergency on-site inspection to ascertain the nature and extent of the Shinhan breach, a spokesperson for the regulator said. It comes as another Korean lender faced scrutiny over data security. KB Kookmin Bank said Friday that personal information of 119 customers had been leaked due to an external intrusion.
韩国金融服务委员会计划于周五与当地银行召开会议,讨论这些数据泄露事件。
The Financial Services Commission is set to hold a meeting with local banks Friday to discuss the data breaches.
网络安全公司Genians的负责人Mun Chong-hyun指出,近期在韩国发生的多起攻击事件中都使用了这类原本用于防御目的的人工智能工具。然而,当这些工具被用于黑客攻击时,可能会成为“双刃剑”,反而助长犯罪行为。
Mun Chong-hyun, director at Genians, a cybersecurity firm, said several recent attacks in South Korea have featured such AI tools that have been developed and shared for defensive purposes. They can however be a “double-edged sword” when used in hacking attempts to facilitate crime.
“随着人工智能相关技术的不断发展,源代码被随意共享,并被用于恶意的网络攻击中,因此许多人需要提高警惕,”Mun补充道。
“As AI-related technologies advance, source codes are being shared indiscriminately and used for malicious AI hacking attempts, so many people need to take caution,” added Mun.
与韩国一些重大数据泄露事件相比,此次Shinhan银行的数据泄露事件影响的范围相对较小。
The number affected by the Shinhan breach is relatively small compared with some of South Korea’s biggest data breaches.
“这次事件尤其令人担忧,因为它泄露了用户的个人信息和财务数据,”NordVPN韩国分公司负责人Sungho Hwang表示。“生成式人工智能技术使得这类攻击变得更加难以察觉(即攻击看起来更加‘真实’、更难以被识别),”他补充道。
“This particular breach is worrying because it exposed both personal and financial information,” said Sungho Hwang, Korea country manager at NordVPN. “Generative AI has made these attacks even more convincing,” he added.
韩国此前曾遭遇过更为严重的数据泄露事件:例如Lotte Card公司的数据泄露事件导致近300万客户的个人信息被泄露;Coupang韩国分公司的黑客攻击影响了超过3300万个用户的账户。韩国的隐私监管机构因此对这家电子商务巨头处以了创纪录的罚款,以处罚其数据泄露行为及其他隐私违规行为。
South Korea has suffered far larger breaches, including one at Lotte Card Co. that exposed information belonging to nearly 3 million customers. A hack at Coupang Inc.’s South Korean unit hit more than 33 million accounts and the country’s privacy regulator imposed a record penalty on the e-commerce giant over the breach and other privacy violations.