INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Financial Sector Hacked by AI-Operated Global Network of Servers

| 2026-10-08 11:10 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
A recent report by S2W has revealed that hundreds of servers running the same open-source AI intrusion tool used in recent domestic banking hacks are operating worldwide, targeting the finance industry. The attackers have been using a combination of pre-set proxy servers and overseas proxies to bypass security systems, with the majority of IP addresses not registered in the existing global threat rating database. This approach has raised concerns that leaked customer information could be used for phishing and other secondary crimes, including data breaches. Hackers are selling fake personal information exploited from a data breach, specifically phone numbers composed only of the 011-016-019 identifier, with rare surnames and overseas email addresses.
Technical Mitigations AI-generated
• Patch the open-source AI intrusion tool used in recent domestic banking hacks, specifically the 'DarkMatter' version. • Implement a more robust proxy server detection system to identify and block pre-set proxy servers and overseas proxies used by attackers. • Use IP address geolocation techniques to detect unknown IP addresses not registered in existing global threat rating databases.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
Global Scope financefinance
Incident Timeline
‎2026/10/08
Threat actors sold hundreds of thousands of customer information records, primarily composed of phone numbers and surnames from Korea, on Darkweb and Telegram.
organisation IP
organisation OTP
organisation Telegram