Businesses and institutions in Japan and South Korea are investigating a string of cyberattacks that exposed, or may have exposed, data tied to millions of accounts. The incidents span different systems and organizations, and authorities have not established that they are connected.
Japan counts a widening series of breaches
In Japan, companies including Daiwa Securities, GMO Research, Rakuten Drive, Nikkei and restaurant operator Monogatari disclosed unauthorized access or possible data leaks this week, The Japan Times reported.
The largest disclosures involved account records rather than confirmed numbers of unique people. Monogatari said data tied to about 10 million Yakiniku King accounts was exposed. Park24, which operates Times rental-car and car-sharing services, previously reported a breach affecting 6.6 million accounts. GMO Research said unauthorized access to its infoQ survey site affected as many as 948,498 users, while Rakuten Drive said three incidents between January and September may have affected more than 16,000 users.
Chief Cabinet Secretary Minoru Kihara said it was not yet clear whether the Japanese incidents were related. He said the government was collecting information and analyzing the attackers’ methods. Officials also urged people to avoid reusing passwords, turn on multifactor authentication and be cautious with links.
South Korea probes banks and churches
South Korean authorities are investigating a separate set of attacks on financial institutions. President Lee Jae Myung said data was exposed at seven firms and that there were signs AI models had been used in some of the attacks, the Financial Times reported.
The breaches appear to have focused on less-secure systems run by third parties rather than core payment networks. About 25,000 Shinhan Bank customers, 40,000 Yegaram Savings Bank customers and 2,200 corporate clients of Welcome Savings Bank had data exposed, according to the FT. Smaller breaches also affected KB Kookmin Bank and Hana Bank, while BNK Busan Bank and Hyundai Capital reported leaks involving contractors or loan brokers. No funds had been reported stolen.
Two Seoul megachurches are also examining suspected attacks. Yoido Full Gospel Church said an initial review found that data relating to about 850,000 members may have been compromised. Cybersecurity firm Oasis Security said a flaw in a church membership system could have exposed data associated with as many as 89,580 registered SaRang Church accounts, Reuters reported.
Oasis said attack records contained references to “sub-agents” and extensive reports that appeared automated, which suggested AI tools may have played a role. Other researchers said a Chinese-language, open-source tool called Artex may have been used to identify and test vulnerabilities in some bank attacks.
Those signs do not prove that AI powered every intrusion. Nikkei Asia noted that AI can assist in the preparatory stages of an attack, while evidence that it was used during an attack remains difficult to trace. Investigations in both countries are continuing.