I should add that this was described to me as an AI based attack, which I don’t think was mentioned in this article.
AI attack probably caused by AI generated code.
“AI based attack” is a very buzzy term that doesn’t really mean anything.
It could mean autonomous AI agents got loose and attacked the bank (like the HuggingFace attack). This is a truly terrifying development that the creators of agents should be held accountable for.
But more than likely it just means that an attacker used AI tools during their attack on the bank.
In a traditional attack, the bad guys would find a toehold into the network of the bank by misconfigured firewall settings or someone revealing a password or someone clicking a bad link or downloading a bad attachment. Then the bad guys would manually run hacking tools to find other toeholds (configuration issues, unpatched software, vulnerabilities, etc..) to pivot their way through the network to escalate privileges and take control.
The most basic attacks could be performed by what are derisively called “script kiddies” who don’t really know what they are doing but know how to run the pre-configured scripts to try to find exploitable “toeholds” in the network. The more sophisticated attacks could be performed by highly skilled hackers who know exactly what they are doing, have more sophisticated tools and know what the next pivot should be immediately.
This could be a very time consuming process that could potentially take hours/days/weeks and would have the potential to be detected and stopped if the appropriate monitoring and notification systems were in place.
With AI, these hacking tools can be leveraged in real time by multiple AI agents (who are all “highly skilled hackers”) and with lightning speed. This could allow the attacker to outrun the monitoring and detection put in place to stop them.
Another “AI based attack” could involve using AI to help in the social engineering of the employees. For example, the “CEO” could call a user and tell them to go to a website, enter their Windows/Microsoft credentials and download a file. But the “CEO” could be an AI clone of the CEO’s voice being used by a bad guy. From there, they would do what I described above.
At least these are some of the things the bad guys have been up to lately. It’s really just bad guys using AI to more effectively and efficiently run the same scams they have been running for years.