South Korea declares AI-assisted bank breaches a national security priority

South Korean President Lee Jae Myung warned that AI models were likely used in a recent wave of cyberattacks against seven financial institutions, exposing customer data but not stealing funds. Authorities suspect attackers targeted less secure third-party portals rather than core banking systems, with evidence pointing to the use of the open-source AI tool Artex. The government has launched a full-scale police investigation and a 24-hour emergency response, urging the sector to develop AI-based defensive measures to counter this 'completely new kind of crisis.'
Key points
- President Lee Jae Myung stated that signs of AI usage in recent bank hacks have caused considerable public anxiety, calling for swift clarification of circumstances and concentrated resources to minimize damage.
- The breaches affected seven financial firms, including Shinhan Bank, KB Kookmin Bank, Hana Bank, Woori Bank, Yegaram Savings Bank, Welcome Savings Bank, and BNK Busan Bank, with Hyundai Capital also reporting leaks involving contractors.
- Specific data exposures included details of approximately 25,000 Shinhan Bank customers, 40,000 Yegaram Savings Bank customers, and 2,200 corporate clients at Welcome Savings Bank, though no funds were reported stolen.
- Moon Jong-hyun, head of Genians Security Center, indicated that Artex, a Chinese-language open-source AI vulnerability testing tool, was likely used in some attacks, comparing it to a kitchen knife that can be wielded as a weapon.
- The Financial Services Commission chair Lee Eog-weon called for the 'highest level of vigilance' and urged the financial sector to build systems that 'defend against AI attacks with AI,' while the science ministry and cyber security agency initiated a 24-hour emergency response.
- Police have opened a full investigation, and the Financial Supervisory Service shared data on 28 unique IP addresses linked to the hacking attempts with the financial sector, with identical IP addresses suggesting a single attacker may be responsible for some incidents.
Background
This incident follows a series of major cyber breaches in South Korea over the past year, including incidents at ecommerce company Coupang, streaming service TVing, financing platform LotteCard, and communications group KT, which affected millions of customer accounts. The current wave of AI-assisted attacks intensifies scrutiny of cybersecurity in a country already sensitive to such failures. Globally, similar concerns have emerged, such as Anthropic's report in 2025 that suspected Chinese state-backed hackers used Claude code to target about 30 organizations worldwide, including financial institutions, and a February 2026 incident where fraudsters used AI-powered impersonation to trick Italian private bank Fideuram out of €95 million. Additionally, in September 2026, Australia reported that an OpenAI agent breached a government health data portal, marking a potential first instance of an AI agent hacking a government website, while Canada reported failed AI hacking attempts against its government sites.
How outlets are covering it
The Financial Times emphasizes the public anxiety and the 'completely new kind of crisis' described by officials, highlighting the use of Artex and the targeting of third-party portals. NBC News focuses on the presidential response and the call for AI-era cybersecurity methods, noting that authorities have not yet disclosed the full scale of the breaches or the specific AI tools used. Both sources agree on the involvement of AI and the emergency government response, but the Financial Times provides more specific details on the affected institutions and the Artex tool, while NBC News highlights the broader context of AI hacking attempts in Australia and Canada. The Financial Times also notes the lack of stolen funds, whereas NBC News does not explicitly mention this detail.
Why it matters
The use of AI in cyberattacks against financial institutions marks a significant shift in the threat landscape, indicating that traditional cybersecurity measures may be insufficient against AI-driven vulnerabilities. This incident underscores the need for governments and financial sectors to develop AI-based defensive strategies and to address the growing risk of AI tools being weaponized for cybercrime. The public anxiety and emergency response in South Korea reflect the broader global concern over AI's potential to exacerbate cyber threats, particularly in critical infrastructure like banking. This event may accelerate regulatory and technological responses to AI-driven cyber risks, influencing future cybersecurity policies and practices worldwide.
What to watch
Authorities are expected to continue their full-scale investigation into the AI-assisted bank hacks, with a focus on identifying the specific AI tools used and the full scale of the breaches. The financial sector is likely to implement AI-based defensive measures as urged by the Financial Services Commission, while the government may introduce new cybersecurity regulations or guidelines to address AI-driven threats. International cooperation on AI cybersecurity may increase, given the global nature of AI hacking attempts, as seen in Australia and Canada. The incident may also lead to heightened scrutiny of open-source AI tools like Artex and calls for stricter controls on their use in malicious activities.
- AI models used in bank cyber attacks, warns South Korea’s president Financial Times
- South Korea's Lee says AI appears to have been used in bank hacks Reuters
- The Morning Risk Report: Hackers Use Chinese AI Tool to Hit South Korean Banks, Exposing New Risk WSJ
- South Korea Investigates Possible Use of A.I. in Hackings on Its Banks The New York Times
- South Korea’s Lee says AI appears to have been used in bank hacks NBC News
Want the full story? Read the original reporting
Read on Financial Times