Banks an unusual target in AI-assisted hacking
Hackers used a Chinese artificial-intelligence agent to attack South Korea’s biggest banks and steal the personal information of 68,000 people, the Wall Street Journal’s CIO Journal reported Monday in its “Morning Download” newsletter.
The breach marks one of the first AI-powered intrusions into the global financial system, according to the Journal. Earlier AI-assisted attacks have primarily struck governments and nonfinancial corporations; banks falling to attackers wielding AI tools is unusual, the newspaper reported.
The case illustrates a challenge AI introduces: identifying who — or what — is behind an attack. “The biggest set of changes are coming with AI agents because agents’ identity can change. Human identity doesn’t change,” Jay Chaudhry, founder and chief executive of the cybersecurity company Zscaler, told the Journal.
Chaudhry spoke to the Journal on Monday during an event with the WSJ Leadership Institute. Zscaler is scheduled to hold its Investor Day on Tuesday in New York.
The CEO said his company has experienced firsthand how AI can disrupt cyber defenses. Zscaler participated from the start in a program called Project Glasswing, which tested a preview of an AI system Chaudhry referred to as Mythos. “When Mythos preview came out, we were part of Project Glasswing from day one,” Chaudhry said. “And as we tested it, we found that it is pretty damn powerful.”
In response, Zscaler shifted the priorities of its engineering team for about three months, with a focus on fixing critical and high-level vulnerabilities rather than delivering new functionality, Chaudhry said. “Every company is going through the same exercise,” he said.
Chaudhry described the broader challenge this way: “Fixing software vulnerabilities is what Mythos brought to the limelight. Every CIO I talk to is working on it, but is very worried because software always has vulnerabilities. There’s so many unfixed vulnerabilities and there’s not enough time and resources,” he said.
The Journal asked readers how their companies are coping with the need to patch and update software as AI makes it easier to find vulnerabilities.