SEOUL/TOKYO: South Korean and Japanese companies are racing to strengthen cyber defences after a wave of attacks that cybersecurity experts say are highlighting how AI may be lowering the bar for criminals with limited technical skills.
Nine South Korean banks and two mega-churches are probing cyberattacks that may have involved AI tools, while Japanese companies including Daiwa Securities, SoftBank and the Lawson convenience store chain have been hit by a recent surge in cyber incidents.
Authorities are still investigating whether and how AI was used in many of the breaches. But cybersecurity specialists say the technology is helping attackers automate tasks from scanning for software vulnerabilities to crafting phishing campaigns, making cybercrime faster, cheaper and harder to detect.
„AI doesn’t get tired … My view is that Japan is essentially being subjected to carpet bombing,“ said Nobuo Miwa, president of Tokyo-based cybersecurity firm S&J Corp.
Japan recorded more cybersecurity incidents in the first nine months of the year than in all of last year, according to data from TrendAI. Incidents rose to 86 in September, up about 18 per cent from August and 37 per cent from July.
The rise suggests attackers have crossed a threshold in „effort, motivation and technical capability“, while AI has largely erased language and other barriers that once hindered foreign hackers, Miwa said.
US cybersecurity company CrowdStrike said a suspected 26-year-old China-based attacker behind the South Korean bank incidents would probably not have been able to carry out the campaign without AI assistance.
The individual, whom CrowdStrike assessed was pursuing financial gain, used a Chinese-developed AI agent and Anthropic’s Claude Code, according to the company.
„While (the hacker’s) capabilities were not terribly sophisticated they were effective,“ said Adam Meyers, CrowdStrike’s senior vice president of counter adversary operations.