How to protect your accounts from AI-powered attacks如何保护您的帐户免受人工智能攻击
A wave of account takeover attacks involving artificial intelligence (AI) against major banks is testing their defenses and putting personal cybers...

AI-powered account takeover attacks are testing major banks’ defenses and putting personal cybersecurity in the spotlight. Shinhan Bank disclosed that information on about 25,000 people was leaked, while KB Kookmin Bank and Hana Bank confirmed breaches affecting 119 and 89 people. Woori Bank and NH NongHyup Bank also reported suspected hacking attempts. Security experts say unique passwords and multifactor authentication can reduce the risk of further account compromise.
The article says credential stuffing is a key danger after a leak, using stolen usernames and passwords from one platform to try other services.
AhnLab advises choosing a completely different password for each service and prioritizing email account security because inbox access can expose linked banking and shopping accounts.
Users who receive a breach notification should change reused passwords on every account where they were previously used.
Multifactor authentication can block unauthorized access by requiring verification beyond a username and password, including biometric authentication or a one-time code from an authenticator app.
Fraudulent emails and text messages may use stolen personal details such as a name or phone number to appear like legitimate bank communications and can direct recipients to malicious websites.
Published Oct 3, 2026 12:41 pm KST
Updated Oct 3, 2026 1:01 pm KST
A wave of account takeover attacks involving artificial intelligence (AI) against major banks is testing their defenses and putting personal cybersecurity in the spotlight.
Shinhan Bank disclosed Thursday that the information of about 25,000 people had been leaked. A day later, KB Kookmin Bank and Hana Bank confirmed breaches affecting 119 and 89 people, respectively. Woori Bank and NH NongHyup Bank also reported suspected hacking attempts. The incidents have raised suspicions that AI was used to automate the attacks.
Consumers have little control over breaches within companies. But the steps they take afterward can go a long way toward preventing exposed login details from putting their other financial and shopping accounts at risk.
Security experts say two measures can substantially reduce the risk of account compromise — using a unique password for each service and enabling multifactor authentication.
A key danger following a leak is credential stuffing. This involves using automated software to test usernames and passwords stolen from one platform across numerous others, from banking and retail websites to web portals and social networks. Attackers count on people using the same login details across multiple accounts for convenience.
Generative AI and more advanced scripts have made these campaigns larger and more targeted. Criminals can make vast numbers of login attempts in a short period while piecing together personal information from different sources to select potential victims.
Against this backdrop, security specialists urge users to stop reusing passwords. AhnLab, a cybersecurity company, advises choosing a completely different password for each service.
Securing email accounts should be a priority. Most websites rely on email for identity checks and password recovery, meaning that losing control of an inbox can leave linked banking and shopping accounts vulnerable.
Anyone who receives a breach notification should look beyond the service involved. Those who have used the exposed password elsewhere should change it on every account where it was reused to prevent further breaches.
MFA adds another layer of protection by requiring verification beyond a username and password. Biometric authentication or a one-time code from an authenticator app can help prevent unauthorized access even when login details have been stolen.
Another threat comes from fraudulent emails and text messages sent in the wake of a breach.
Messages offering to check whether personal information has been leaked, provide compensation or secure an account may direct recipients to malicious websites. By incorporating stolen details such as a person’s name or phone number, scammers can make these messages look like legitimate communications from a bank.
Rather than following links from unfamiliar or unverified senders, users should open their bank’s official app or type its website address directly into their browser.
“Stolen login details can open the door to a series of further attacks,” an AhnLab official said. “Users need to adopt basic precautions, such as separate passwords for each service and multifactor authentication, while businesses must build stronger defenses, including better detection of abnormal login activity.”
BOK faces scrutiny over cybersecurity after staff data breach
Nearly 100,000 cyberattacks hit foreign ministry, affiliates in 6 months
Telecoms step up cybersecurity spending after breaches
人工智能驱动的账户盗用攻击正在考验各大银行的防御能力,并将个人网络安全推向风口浪尖。新韩银行披露约2.5万人的信息遭到泄露,而KB国民银行和韩亚银行则证实分别有119人和89人受到影响。友利银行和NH农协银行也报告了疑似黑客攻击事件。安全专家表示,使用唯一密码和多因素身份验证可以降低账户进一步被盗用的风险。
文章指出,凭证填充攻击是数据泄露后的主要危险,即利用从一个平台窃取的用户名和密码来尝试其他服务。
AhnLab 建议为每个服务选择完全不同的密码,并优先考虑电子邮件帐户安全,因为访问收件箱可能会泄露关联的银行和购物帐户。
收到安全漏洞通知的用户应更改之前使用过该密码的所有帐户上的重复密码。
多因素身份验证可以通过要求除用户名和密码之外的验证来阻止未经授权的访问,包括生物识别身份验证或来自身份验证器应用程序的一次性代码。
欺诈性电子邮件和短信可能会使用窃取的个人信息,例如姓名或电话号码,伪装成合法的银行通信,并可能将收件人引导至恶意网站。
发布于2026年10月3日下午12:41(韩国标准时间)
更新于2026年10月3日下午1:01(韩国标准时间)
一波利用人工智能 (AI) 对各大银行进行账户盗用攻击的浪潮正在考验它们的防御能力,并将个人网络安全推到了风口浪尖。
新韩银行周四披露,约2.5万人的信息遭到泄露。一天后,KB国民银行和韩亚银行分别证实,有119人和89人受到影响。友利银行和NH农协银行也报告了疑似黑客攻击事件。这些事件引发了人们的怀疑,认为人工智能被用于自动化攻击。
消费者对公司内部的数据泄露事件几乎没有控制权。但他们事后采取的措施却能有效防止泄露的登录信息危及其他金融账户和购物账户的安全。
安全专家表示,两项措施可以大幅降低账户被盗用的风险——为每个服务使用唯一的密码并启用多因素身份验证。
信息泄露后的一个主要风险是撞库攻击。这种攻击方式利用自动化软件,将从一个平台窃取的用户名和密码尝试登录到众多其他平台,包括银行和零售网站、门户网站以及社交网络。攻击者正是利用了人们为了方便而在多个账户中使用相同登录信息的心理。
生成式人工智能和更高级的脚本使得这些攻击活动规模更大、目标更精准。犯罪分子可以在短时间内进行大量的登录尝试,同时从不同来源拼凑个人信息,从而锁定潜在的受害者。
在此背景下,安全专家敦促用户停止重复使用密码。网络安全公司AhnLab建议为每个服务选择完全不同的密码。
保护电子邮件账户安全至关重要。大多数网站都依赖电子邮件进行身份验证和密码找回,这意味着一旦失去对收件箱的控制,关联的银行和购物账户就可能面临风险。
收到数据泄露通知的人应该关注的不仅仅是涉事服务本身。曾在其他地方使用过泄露密码的人应该更改所有使用该密码的账户上的密码,以防止进一步的数据泄露。
多因素身份验证 (MFA) 除了用户名和密码之外,还需要进行其他验证,从而增加了一层额外的安全保护。即使登录信息被盗,生物识别认证或来自身份验证器应用程序的一次性代码也能帮助防止未经授权的访问。
另一种威胁来自数据泄露事件发生后发送的欺诈性电子邮件和短信。
声称可以查询个人信息是否泄露、提供赔偿或保护账户的信息,可能会将收件人引导至恶意网站。诈骗分子通过植入窃取的个人信息,例如姓名或电话号码,使这些信息看起来像是来自银行的合法通知。
用户不应点击来自陌生或未经核实的发送者的链接,而应打开银行的官方应用程序或直接在浏览器中输入银行的网址。
“被盗的登录信息可能会引发一系列后续攻击,”安实验室的一位官员表示。“用户需要采取一些基本的防范措施,例如为每个服务设置不同的密码并启用多因素身份验证,而企业则必须构建更强大的防御体系,包括更好地检测异常登录活动。”
BOK因员工数据泄露事件面临网络安全审查
近10万起网络攻击在6个月内袭击了外交部及其附属机构。
电信公司在数据泄露事件后加大网络安全投入