IBM, COBOL and AI, OH My

So, in recent cyber news several security and IT companies were hit hard on the stock market!  For the purpose of this blog post I want to look closely at the hit IBM took.  A review showed that IBM shares fell 13% after Claude AI blogged about how Claude code could help reduce the cost of COBOL systems used by many systems.  A loss of 13% is a heavy hit, even though IBM shrugged it off, many other financial platforms called it “tanking.”  Below is a visual presentation of the IBM stock performance year to date.

Well, what do we make of this?  First of all, COBOL known as “Common Business Oriented Language.”  It originated way back in the 1960s and is designed for high-volume business data processing on mainframes.  It is a crucial programming language because it supports “250 billion lines of code” in many businesses, such as banking and government! 

It is used in mainframe applications, such as financial services, insurance, retail business and even government entities for “batch processing.”  It is heavily involved in the insurance industry as well and at least 90% of Fortune 500 companies still utilize it!  Read that figure again my friends!  It is nearly everywhere, behind many of the systems that support most of modern life! 

Now, the problem with Cobol is that kind of like Latin, it has nearly become a dead language.  Most of the original users and programmers who crafted the code have retired or died.  Yet it still runs large facets of our industrial and government bases. 

Now, with AI and especially Anthropic making the claim via a “blog post” that their tool-set can now review and update COBOL panic set in amongst investors!  Remember, and here is another number for you, 95% of ATM transactions are handled by COBOL!  95%!!  What happens if suddenly an attacker can interfere with that process?  Mass panic and who knows what else.

As one example of real-world events involving COBOL.  A small local business called me because they had been infected with ransomware.  The event involved every one of their 3 locations and hundreds of systems!  Their email server was encrypted, their workstations were encrypted and they were facing substantial loss of income.  As we began the recovery process, I learned that their central shipping system was a COBOL based IBM system, one which the attackers did find and yet ignored! 

But why would attackers, who had already gained complete access to their environment, suddenly choose to ignore such a vital system?  Well, because they didn’t understand COBOL!  They could see the system, but because it was so old, the hackers didn’t understand the language, nor did they have an adequate attack method for it!  It was “security through obscurity!”  It worked then, but now? 

Well, with AI beginning to explore such older coding entities, the entire scenario could be much different!  The attackers could have used an AI tool to enhance their understanding of such an antiquated system and thus attack it successfully.  Which in this instance would have completely shut down the business.  A danger to be addressed for certain in future security briefings.

Now, granted, much has been written as well stating that this was all a big misunderstanding.  That other AI tools already were translating COBOL and addressing its inherent issues, but given that IBM took such a hit, it is important to explore, to acknowledge the fact that AI is impacting much of the IT world in ways no one would have expected! 

Leave a Reply

Discover more from Dave Does Cyber Security

Subscribe now to keep reading and get access to the full archive.

Continue reading