How to protect your accounts from AI-powered attacks

gettyimagesbank

gettyimagesbank

A wave of account takeover attacks involving artificial intelligence (AI) against major banks is testing their defenses and putting personal cybersecurity in the spotlight.

Shinhan Bank disclosed Thursday that the information of about 25,000 people had been leaked. A day later, KB Kookmin Bank and Hana Bank confirmed breaches affecting 119 and 89 people, respectively. Woori Bank and NH NongHyup Bank also reported suspected hacking attempts. The incidents have raised suspicions that AI was used to automate the attacks.

Consumers have little control over breaches within companies. But the steps they take afterward can go a long way toward preventing exposed login details from putting their other financial and shopping accounts at risk.

Security experts say two measures can substantially reduce the risk of account compromise — using a unique password for each service and enabling multifactor authentication.

A key danger following a leak is credential stuffing. This involves using automated software to test usernames and passwords stolen from one platform across numerous others, from banking and retail websites to web portals and social networks. Attackers count on people using the same login details across multiple accounts for convenience.

Generative AI and more advanced scripts have made these campaigns larger and more targeted. Criminals can make vast numbers of login attempts in a short period while piecing together personal information from different sources to select potential victims.

Against this backdrop, security specialists urge users to stop reusing passwords. AhnLab, a cybersecurity company, advises choosing a completely different password for each service.

Securing email accounts should be a priority. Most websites rely on email for identity checks and password recovery, meaning that losing control of an inbox can leave linked banking and shopping accounts vulnerable.

Anyone who receives a breach notification should look beyond the service involved. Those who have used the exposed password elsewhere should change it on every account where it was reused to prevent further breaches.

MFA adds another layer of protection by requiring verification beyond a username and password. Biometric authentication or a one-time code from an authenticator app can help prevent unauthorized access even when login details have been stolen.

Another threat comes from fraudulent emails and text messages sent in the wake of a breach.

Messages offering to check whether personal information has been leaked, provide compensation or secure an account may direct recipients to malicious websites. By incorporating stolen details such as a person’s name or phone number, scammers can make these messages look like legitimate communications from a bank.

Rather than following links from unfamiliar or unverified senders, users should open their bank’s official app or type its website address directly into their browser.

“Stolen login details can open the door to a series of further attacks,” an AhnLab official said. “Users need to adopt basic precautions, such as separate passwords for each service and multifactor authentication, while businesses must build stronger defenses, including better detection of abnormal login activity.”


Interesting contents

Taboola 후원링크

Recommended Contents For You

Taboola 후원링크