Site navigation

How AI Helped Thwart a Cyberattack at the Tokyo Olympics

Michael Behr

,

AI cyberattack
Digital operations are becoming more complicated – cybersecurity staff need AI to keep cyberattacks under control.

An attempted cyberattack during the Tokyo Olympics was thwarted thanks to the assistance of a cybersecurity AI.

According to research from cybersecurity experts Darktrace, the group discovered an attempted attack a week before the games began. Criminals connected a Raspberry Pi device to a national sporting body’s network with the aim of stealing sensitive data.

Not only would the subsequent data breach have had had a negative impact on the body’s reputation, but it could also have potentially threatened the safety of its athletes.

The group noted that threat actors frequently exploit moments of high pressure and stress to launch their attacks on an organisation. This takes advantage of a time when employees are distracted, tired or have little time to react to an attack.

By using AI, Darktrace was able to recognise the malicious activity and act at machine speed to interrupt the threat. This gave the human personnel time to neutralise the attack.

To hide their activity, the criminals named their Raspberry Pi to mimic the groups naming conventions. As a small device, it was also relatively easy to physically conceal.

However, Darktrace’s AI Antigena recognised the device and its connection as deviating from the ‘pattern of life’ for new devices, the typical modes of behaviour and operation the AI expects to see.

As the device attempted to scan the sporting body’s servers, the AI recognised the activity as suspicious and stopped it from connecting.

Towards the end of the attack, the device attempted to make external connections to exfiltrate any stolen data. The AI blocked these connections before they were made, ensuring that no data was exfiltrated.

The entire attack took place over less than 12 hours. The AI was able to keep the attack under control, giving human cybersecurity staff the time to respond to the threat, quarantine the digital activity and find the physical location of the Raspberry Pi and remove it.


Recommended


AI has emerged as one of the key transformative tools available to organisations across every sector. As cybersecurity becomes more important, the pressure put on security staff increases.

Furthermore, the digital pivot has seen more and more activity move online, facilitated by the increase of cloud operations. As such, networks have become more complicated, making it difficult for human personnel to monitor and react to activity.

As such, AI provides a vital tool for cybersecurity staff if they want to stay ahead of cybercriminals.

Unfortunately, the power of AI can also be leveraged by cybercriminals.

The ability to parse large amounts of information, such as databases of contacts or lists of passwords, allows criminals to tailor and target their attacks. AI lets them scale-up brute force attacks.

In addition, AI also enables deepfake attacks, allowing criminals to create vocal or even visual duplicates in order to win their targets trust.

Michael Behr

Senior Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data