S2W: Most Attack IPs in Financial Hack Missing From Threat Databases
S2W said AI penetration tooling appeared on one shared attack server, but it did not investigate the affected financial institutions directly.
S2W disclosed on October 8, 2026, the results of its analysis of attack information tied to a recent financial-sector breach incident. According to the company, most of the IP addresses used in the campaign had little to no report history in global threat reputation databases.
S2W said the attackers alternated between overseas rented servers and commercial proxies to change their access IPs. The company also confirmed records showing that an AI penetration tool's management interface and a relay program for AI model connections were operated together on one of the shared attack IPs.
S2W stated the server had been running since early September and is presumed to have been withdrawn after media reports. The company added that it did not directly conduct the incident investigation for the affected financial institutions.
According to S2W's analysis reported by etnews.com, further investigation is needed to determine whether the AI tool was used as far as the actual data exfiltration stage.
Quick answers
What did S2W find on the attack server?
S2W confirmed records showing an AI penetration tool's management interface and a relay program for AI model connections were operated together on one of the shared attack IPs.
Did S2W investigate the affected financial institutions?
No. S2W stated it did not directly conduct the incident investigation for the affected financial institutions.
Was the AI tool used to steal data?
S2W said further investigation is needed to determine whether the AI tool was used as far as the actual data exfiltration stage.