Signal

A slew of cyberattacks hit Japanese companies in September, exposing the data of millions and prompting calls for security checks, as AI lowers hacking barriers

First reported by Bloomberg ·

The signal ●●●○ Compiled by AI from Bloomberg, Techmeme, Reuters, Associated Press and Seoul Economic Daily
Why you might care

Cyberattack capabilities are rapidly improving for less skilled actors, increasing the risk of breaches for all organizations.

What happened

A significant increase in cyberattacks targeting Japanese and South Korean companies occurred in September, exposing millions of individuals' data and prompting urgent calls for enhanced security measures. Cybersecurity experts suggest that artificial intelligence (AI) tools are increasingly being used to lower the barrier to entry for cybercriminals, even those with limited technical expertise. Companies like Daiwa Securities, SoftBank, and the Lawson convenience store chain in Japan, along with nine South Korean banks and two mega-churches, are investigating breaches. While the direct use of AI in every incident is still under investigation, specialists note that AI can automate vulnerability scanning and phishing campaign creation, making attacks faster and harder to detect. Japan, in particular, has seen a substantial rise in reported cybersecurity incidents, surpassing last year's total within the first nine months. A China-based attacker suspected in the South Korean bank incidents reportedly used AI agents and models, highlighting the technology's role in enabling less sophisticated actors to conduct effective campaigns. The trend indicates a need for stronger security controls and more rigorous testing as AI capabilities evolve.

What it means

The recent surge in cyberattacks, particularly in Japan and South Korea, signals a critical inflection point where AI is democratizing sophisticated hacking techniques. Previously, complex attacks required significant technical skill and resources, but AI-powered tools now automate key stages, enabling individuals with limited expertise to identify vulnerabilities and launch campaigns effectively. This shift suggests a future where the sheer volume and evolving nature of threats will overwhelm traditional, reactive cybersecurity measures, forcing a fundamental rethinking of defensive strategies. The trend indicates that companies can no longer rely solely on the technical proficiency of their security teams; proactive, AI-assisted defense mechanisms will become essential.

This wave of attacks underscores a growing market readiness for AI-driven cybersecurity solutions and a corresponding increase in the perceived value of robust security. Companies will likely face greater pressure from regulators and customers to demonstrate advanced protection, potentially leading to increased investment in AI-powered threat detection and response systems. The incidents also highlight the evolving landscape of cybercrime, where the use of AI by adversaries necessitates an equivalent advancement in defensive AI, creating a competitive arms race. Organizations that fail to adapt to this new paradigm risk not only financial losses and regulatory penalties but also significant damage to their reputation and customer trust.

AI-written summary. May contain errors.