Reusing passwords invites chain account takeovers
Enable two-factor authentication and monitor suspicious logins
A series of AI-powered hacking attacks targeting major South Korean banks has prompted growing concern over personal account security.
Experts advise that avoiding password reuse across multiple sites and enabling multi-factor authentication (MFA) can significantly reduce the risk of falling victim.
Large-scale account takeover attacks using AI have struck major domestic banks including Shinhan Bank, KB Kookmin Bank and Hana Bank in recent months, according to Yonhap, raising alarm over personal data protection.
One attack method that warrants particular attention is "credential stuffing" — a technique in which login credentials leaked from one site are used to attempt mass logins at banks, portals, online shopping platforms, SNS and other services.
The threat has grown sharper as generative AI combines with automation tools, boosting both the scale and precision of attacks. Hackers can now attempt large volumes of logins in a short time and piece together personal data scattered across multiple sources to identify and target specific individuals.
To guard against such attacks, using a different password for each site is essential. Experts also caution against simply swapping out a digit or special character from an existing password, as such minor variations offer little real protection.
Email accounts deserve particular care. Because email is widely used for identity verification and password resets on other platforms, a compromised email account can trigger a chain reaction that exposes financial and shopping accounts as well.
Setting up MFA adds another layer of defense. Even if a username and password are leaked, an attacker would still need to clear an additional verification step — such as biometric authentication or a one-time password (OTP) — making unauthorized access far less likely.
Users should also be on guard against phishing and smishing attacks that exploit data breach incidents. Attackers may lure victims into clicking malicious links using messages about "confirming a personal data leak," "receiving breach compensation" or "applying for account protection."
Rather than clicking links in texts or emails of uncertain origin, it is safer to open a financial institution's official app directly to check any alerts.
Login histories should also be reviewed regularly. If access from an unfamiliar location or device is detected, users should log out of all devices, change their password, and verify that account recovery phone numbers and email addresses have not been altered.
"Once account credentials are leaked, attackers use them as a foothold to launch a chain of follow-on attacks," an official at AhnLab told Yonhap. "Users must follow basic rules such as using separate passwords for each site and enabling multi-factor authentication, while companies need to upgrade their abnormal login detection systems and build a multilayered defense."
kido@heraldcorp.com
