South Korea declares AI-driven bank hacks a national crisis

South Korean President Lee Jae Myung declared that artificial intelligence tools were likely used in a recent wave of cyberattacks against major commercial banks, prompting a full-scale police investigation and emergency government response. The breaches exposed customer data at seven financial institutions, including Shinhan Bank and KB Kookmin Bank, but no funds were reported stolen. Authorities suspect attackers targeted less secure third-party portals rather than core banking systems, using AI to identify vulnerabilities. The incident has triggered a 24-hour emergency response from the science ministry and calls for AI-based defensive measures.
Key points
- President Lee Jae Myung stated that signs of AI usage in the hacks have caused considerable public anxiety and ordered a swift investigation to minimize damage.
- Police launched a full-scale investigation after cyberattacks breached customer personal information at seven financial firms, including Shinhan, KB Kookmin, Hana, and Woori Banks.
- The Financial Services Commission reported that attackers targeted less secure third-party systems, such as loan broker portals, rather than core payment networks.
- Approximately 25,000 Shinhan Bank customers, 40,000 Yegaram Savings Bank customers, and 2,200 Welcome Savings Bank corporate clients had data exposed.
- The Financial Supervisory Service shared data on 28 unique IP addresses linked to the attacks with the financial sector to aid in tracking the intruders.
- No funds were reported stolen in the incidents, though the breaches have heightened concerns about the security of the financial sector.
Background
This incident follows a period of heightened cybersecurity scrutiny in South Korea, where major breaches at companies like Coupang and KT affected millions of users in the past year. The country has also been investing heavily in AI infrastructure, with a record 2027 budget allocated to boost AI capability and chip prowess. Additionally, recent global incidents, such as an OpenAI agent breaching an Australian government portal and AI-assisted fraud in Italy, have raised international concerns about the risks of AI in cybersecurity.
How outlets are covering it
While both NBC News and the Financial Times confirm the use of AI in the attacks and the involvement of President Lee Jae Myung, they differ in the level of detail provided. NBC News focuses on the official government response and the launch of a full-scale police investigation, noting that authorities have not yet disclosed the specific AI tools used. In contrast, the Financial Times provides more granular details, citing a security official who identified 'Artex,' a Chinese-language open-source AI tool, as a likely culprit. The Financial Times also emphasizes that the attacks targeted third-party portals rather than core banking systems and highlights the broader context of AI-driven cyber threats globally, including incidents in Australia and Italy. Both outlets agree on the scale of the data breaches and the emergency measures taken by the Financial Services Commission.
Why it matters
The use of AI in cyberattacks against major financial institutions marks a significant shift in the cybersecurity landscape, highlighting the growing threat of AI-powered vulnerabilities. This incident underscores the need for governments and financial institutions to develop AI-based defensive measures and strengthen the security of third-party systems. It also raises concerns about the potential for AI to be used as a weapon by criminals, as noted by security experts, and could lead to increased scrutiny of AI regulations and cybersecurity standards in South Korea and globally.
What to watch
The South Korean police are expected to continue their full-scale investigation to identify the attackers and determine the full scope of the breaches. The Financial Services Commission and the Financial Supervisory Service will likely implement stricter security measures for third-party systems and require financial institutions to adopt AI-based defensive technologies. The science ministry and cyber security agency may continue their 24-hour emergency response and collaborate with cloud providers to block suspicious IP addresses. Additionally, the incident may prompt further discussions on AI regulations and cybersecurity standards in South Korea and internationally.
- South Korea’s Lee says AI appears to have been used in bank hacks NBC News
- South Korea's Lee says AI appears to have been used in bank hacks Reuters
- The Morning Risk Report: Hackers Use Chinese AI Tool to Hit South Korean Banks, Exposing New Risk WSJ
- South Korea Investigates Possible Use of A.I. in Hackings on Its Banks The New York Times
- AI models used in bank cyber attacks, warns South Korea’s president Financial Times
Want the full story? Read the original reporting
Read on NBC News