Skip to content

Topic

AI-Enabled Cyberattacks

Cyberattacks that use AI systems, such as language models or autonomous agents, to automate exploitation, malware control, or other offensive tasks.

Current stories

security15 publishersConfirmed

South Korea suspects AI agents in bank breaches that leaked data on at least 25,000 Shinhan customers

President Lee Jae Myung says AI appears to have been used in hacks on South Korean banks that leaked data on at least 25,000 Shinhan customers. If his claim that AI removes the need for specialized skills holds up, banks should plan for many more attackers.

Perspective Coverage

15 publishers
Builder
Builder 27%
Operator
Operator 56%
Investor
Investor 17%

Reality

Evidence68
Adoption35
Hype gap+25
Incentives45
Confidence62
leadership4 publishersConfirmed

CrowdStrike traces AI-assisted attacks on South Korean banks to one possible suspect in Guangdong

CrowdStrike tied AI-assisted South Korean bank attacks, run on an open-source pentest tool and DeepSeek, to a possible 26-year-old suspect in Guangdong. The reported breaches involved systems banks run for brokers and staff, so the exposure to manage sits at the bank's edge, whoever the attacker proves to be.

Reality

Evidence45
Adoption
Insufficient
Hype gap+20
Incentives40
Confidence50
security6 publishersConfirmed

A ShinyHunters credential pipeline scanned 1.8 million Android APKs on ten rented EC2 workers

Anthropic says an alleged ShinyHunters member decompiled apps pulled from multiple stores and routed verified TruffleHog hits into a Telegram channel sorted by service, and those credentials opened most of his confirmed breaches.

Perspective Coverage

6 publishers
Builder
Builder 21%
Operator
Operator 57%
Investor
Investor 22%

Reality

Evidence55
Adoption
Insufficient
Hype gap+20
Incentives55
Confidence60
invest1 publisherOne report

Hackers took data on 25,000 Shinhan customers through a site built for loan recruiters

South Korea's financial regulator gave lenders until Thursday to check every internet-facing system after hackers breached at least seven banks. Attackers entered through tools built for loan recruiters and staff, so the repair falls on how much credit data banks let outsiders see.

Reality

Evidence60
Adoption
Insufficient
Hype gap+20
Incentives
Insufficient
Confidence55
invest2 publishersConfirmed

Korean police need a financial regulator's ruling to decide who investigates the Shinhan Bank hack

Korea's National Police Agency booked the AI-driven attack on Shinhan Bank as a criminal case and assigned 28 cyberterrorism investigators to it. Whether the case moves to the new Serious Crimes Investigation Agency turns on how the Financial Services Commission classifies the bank's system.

Reality

Evidence60
Adoption
Insufficient
Hype gap+20
Incentives
Insufficient
Confidence55
invest2 publishersConfirmed

FSC chief Lee Eok-won promises strict accountability for whichever Korean lender is breached next

FSC chairman Lee Eok-won told Korean financial firms they will be held strictly accountable under law if the hacks that hit six lenders happen again. The threat covers future breaches, so for the firms already hit the cost so far is five requests, including security checks and customer compensation.

Reality

Evidence58
Adoption
Insufficient
Hype gap+25
Incentives
Insufficient
Confidence55
product5 publishersConfirmed

CrowdStrike and Fortinet co-sign a letter that dates the security tooling they sell

More than 100 companies signed a call for collective action on cyber defence whose first principle is that status quo security will not be enough, a sentence co-signed by five of the vendors who supply that status quo.

Perspective Coverage

5 publishers
Builder
Builder 33%
Operator
Operator 42%
Investor
Investor 25%

Reality

Evidence70
Adoption20
Hype gap+35
Incentives80
Confidence65
security5 publishersConfirmed

Check Point co-signs a cyber defense letter whose only named product belongs to OpenAI

A vendor coalition has formed around OpenAI's call for a surge in cyber defense. What an underfunded defender can actually requisition from it today is one subsidized model tier, on terms the letter does not state.

Perspective Coverage

5 publishers
Builder
Builder 25%
Operator
Operator 48%
Investor
Investor 27%

Reality

Evidence55
Adoption15
Hype gap+40
Incentives72
Confidence62
security6 publishersConfirmed

Hundreds of AI agents drove one IP into 440 PaperCut servers across 48 countries

GreyNoise and Blackpoint Cyber trace the new PaperCut auth-bypass chain to one scanning address running AI agents against schools, which turns an unpatched print server from a maintenance ticket into a credential incident.

Perspective Coverage

6 publishers
Builder
Builder 31%
Operator
Operator 57%
Investor
Investor 12%

Reality

Evidence62
Adoption38
Hype gap+20
Incentives40
Confidence66
build5 publishersConfirmed

Anthropic widened its dual-use biology block on lost certainty about the old threshold

Anthropic's third misuse report says its 2025 Claude models sat well below the level that could help a sophisticated user with dangerous biology, and that for current models it can no longer make that assurance.

Perspective Coverage

5 publishers
Builder
Builder 28%
Operator
Operator 52%
Investor
Investor 20%

Reality

Evidence50
Adoption
Insufficient
Hype gap+20
Incentives65
Confidence55

Earlier coverage

  1. Researchers built every sandbox this year's rogue AI agents got out of

    Science · September 17, 2026 · 1 publisherOne report

  2. AI lowers the skill floor for the 30-line attack that wrecked a 27-ton generator

    Leadership · September 17, 2026 · 1 publisherOne report

  3. Four of the six stages in AEPD's agent-breach report happen after a successful login

    Build · September 15, 2026 · 1 publisherOne report

  4. IBM prices the AI-assisted breach at a million dollars more than the rest

    Invest · September 14, 2026 · 1 publisherOne report

  5. OpenAI, Anthropic and 100+ others urge governments to fund defenses against AI-enabled cyberattacks

    Invest · August 30, 2026 · 8 publishersConfirmed

  6. ShinyHunters affiliates escalated one stolen token to full cloud admin in about three hours

    Product · September 10, 2026 · 1 publisherOne report

  7. OpenAI test found agents breaching Hugging Face; CrowdStrike touts new tools to police shadow AI

    Product · September 10, 2026 · 1 publisherOne report

  8. FBI's cyber division tells operators quarterly patching is finished

    Security · September 9, 2026 · 1 publisherOne report

  9. Foster's H.R.10230 would put credit union and Home Loan Bank tech vendors under federal oversight

    Security · September 4, 2026 · 1 publisherOne report

  10. The UAE says attack attempts quadrupled to 800,000 a day. The number that matters is hours.

    Product · August 24, 2026 · 1 publisherOne report

  11. OpenAI says the attacker is months behind. That makes defense a rental, not a purchase.

    Invest · August 23, 2026 · 1 publisherOne report