Science & Tech · South Korea
South Korea probes possible AI role in attacks on banks
Authorities are examining whether artificial-intelligence tools assisted cyberattacks that exposed customer information at several South Korean banks. Regulators have ordered broader security checks while police investigate the incidents.
South Korea is examining possible AI involvement in bank cyberattacks that exposed customer information. Regulators have ordered sector-wide checks, but the tools and full scale remain unknown.
- Shinhan reported a leak affecting about 25,000 customers.
- KB Kookmin and Hana also reported customer-data exposure.
- Regulators linked 28 IP addresses to recent hacking attempts.
- Police and financial watchdogs are investigating possible AI involvement.
- Woori and NH Nonghyup reportedly blocked similar attacks.
What's new
- President Lee Jae Myung called for a rapid investigation into possible AI use.
- Regulators linked 28 IP addresses to recent attacks and shared them with financial firms.
- Woori Bank and NH Nonghyup Bank blocked attempts without reported data leaks.
South Korea was investigating on Oct 6 whether artificial-intelligence models were used in recent cyberattacks on banks, after customer information was exposed at several institutions. President Lee Jae Myung said signs of AI use had appeared in some incidents and called for the circumstances to be established quickly, while police and financial regulators pursued separate inquiries.134
Customer information exposed
Shinhan Bank said an outside party gained unauthorised access to certain services and obtained information belonging to about 25,000 customers. The compromised data included names, telephone numbers and annual income. According to reporting cited by The Straits Times, attackers may have used advanced AI agents to test for weaknesses and enter a service used by loan recruiters.23
KB Kookmin Bank reported that an external intrusion exposed personal information relating to 119 customers, while 89 Hana Bank customers were affected by another attack. According to Yonhap, Woori and NH Nonghyup also faced attempted attacks, but each prevented the intrusions and neither reported a customer-data leak.23
On Oct 5, The Korea Times said data breaches reported by seven financial firms had affected over 67,000 individuals. It said the incidents exposed both personal and financial information, while investigators had identified traces associated with ARTEX AI on infrastructure believed to have been involved in the campaign.7
Evidence under examination
The Financial Supervisory Service and the Financial Security Institute identified 28 distinct IP addresses associated with recent hacking attempts and distributed the information to the financial sector. Yonhap reported that the watchdog believed the shortlisted addresses had been used in hacking supported by AI agents. Investigators linked the IP addresses to the US, Japan and a further 10 countries, while being unable to establish the origin of some.13
That assessment has not established publicly which AI systems, if any, were deployed. Authorities have not disclosed the specific tools or the complete scale of the breaches. The Korea Times report about ARTEX AI described traces found on suspected infrastructure, rather than establishing publicly that the technology carried out the intrusions.17
President Lee said the indications of AI use had generated concern and instructed officials to determine what happened and limit the damage. He also called for cybersecurity approaches suited to an era in which AI can be used in attacks. The president’s comments did not identify a particular model or developer.123
Regulatory and police response
The Financial Services Commission convened an emergency meeting on Oct 2 with regulators, major banks, card companies and industry associations. It ordered financial companies to examine every system accessible from outside, regardless of the service type, and to check that authentication and access controls protecting internal information were adequate. The commission also directed institutions to share attacker addresses, methods and intrusion records rapidly.5
Following reports of the attacks, the Financial Supervisory Service launched an urgent field inspection at Shinhan, and the Financial Services Commission, the FSS and the Financial Security Institute opened inquiries. The Kyunghyang Shinmun reported that police initially opened a pre-case inquiry involving several banks; subsequent reports said police had begun a full investigation.256
Why it matters
For European readers, the investigation illustrates how potentially reusable AI tools and attack infrastructure spread across several countries can complicate the attribution and containment of financial cyberattacks. The case also raises questions about technologies developed and shared for defensive purposes that, according to The Straits Times, featured in recent attacks.23
Videos
Related stories
Version history
- version 1 ·

