South Korean and Japanese organizations are scrambling to harden their cyber defenses after a spate of attacks that experts say are being powered by artificial intelligence. Nine banks and two large churches in South Korea, along with Japanese companies including Daiwa Securities, SoftBank Corp. and the Lawson convenience‑store chain, are investigating breaches that may have employed AI tools.
AI Lowers the Barrier for Hackers
Cybersecurity specialists warn that AI is automating tasks that previously required deep technical skill, such as scanning for software flaws and generating convincing phishing messages. “AI doesn’t get tired… Japan is essentially being subjected to carpet bombing,” said Nobuo Miwa, president of Tokyo‑based S&J Corp.
Data from TrendAI shows Japan recorded 86 cybersecurity incidents in September, an 18% rise from August and a 37% increase from July, surpassing the total number of incidents recorded for the entire previous year.
International Actors and AI Tools
U.S. firm CrowdStrike linked a suspected 26‑year‑old China‑based attacker behind the South Korean bank incidents to the use of a Chinese‑developed AI agent and Anthropic’s Claude Code. “While the hacker’s capabilities were not terribly sophisticated, they were effective,” said Adam Meyers, CrowdStrike’s senior vice president of counter‑adversary operations.
Choi Kyoungjin of Gachon University warned that general‑purpose AI models now allow even ordinary users with malicious intent to ask the system to locate vulnerabilities, dramatically speeding up attack preparation.
Rising Threats and Economic Impact
South Korea reported 1,236 cyber incidents in the first half of the year, a 20% increase over the same period last year. While server‑hacking cases fell, distributed denial‑of‑service attacks rose 56.7% and ransomware incidents jumped 76.8%, according to government data.
Although no major financial losses have been confirmed yet, analysts caution that stolen data could fuel phishing and smishing campaigns. “We expect regulatory penalties, customer compensation costs, and a sector‑wide increase in cybersecurity spending,” wrote Karen Wu, senior analyst at Fitch.
Regulators Respond
Both countries are moving to tighten defenses. South Korea’s Financial Services Commission has ordered a 12‑point cybersecurity self‑assessment for financial institutions. In Japan, Digital Transformation Minister Toshiharu Furukawa convened a meeting of ministries and agencies, and the National Cybersecurity Office plans to issue new warnings to businesses.
Miwa of S&J predicts that elevated attack levels will continue, stating, “The attackers have experienced a breakthrough that has rendered many of the old assumptions obsolete. Our defenses need their own breakthrough as well.”
Original reporting: Appleton, WI News Feed (HLL/CB) — read the source article.