South Korean President Lee Jae Myung directed officials on Sunday to fully investigate a wave of cyberattacks on the country’s financial industry, as regulators warned that the hackers may have used artificial intelligence tools to break into systems at several major banks.
Lee told officials to take the breaches seriously and to spare no effort in developing countermeasures, presidential spokesperson Kang Yu-jung said, according to The Korea Herald. The order covers recent leaks of personal data at banks, finance companies and public agencies, Reuters reported.
Also on Sunday, Lee Eog-weon, chairman of the Financial Services Commission, called industry associations, fellow regulators and executives of the affected companies to an emergency meeting. The session had been planned for Oct. 7 but was moved up after more breaches surfaced at smaller lenders, Reuters reported, citing Korean media. “We cannot rule out the possibility that AI was used in the attacks,” the chairman said, as quoted by the Korea JoongAng Daily.
Leaks spread beyond big banks
Shinhan Bank, one of the country’s largest lenders, disclosed Oct. 1 that personal information belonging to about 25,000 customers had leaked, including names, phone numbers and annual income. Hana Bank, BNK Busan Bank and KB Kookmin Bank reported incidents the next day, according to The Korea Times, which said some customers’ resident registration numbers, South Korea’s national ID numbers, were also exposed.
Smaller lenders were hit as well. Yegaram Savings Bank reported a leak involving about 40,000 customers, the largest so far at a single firm, and Hyundai Capital said personal data tied to some of its housing loan agents was exposed, the JoongAng Daily reported. Welcome Savings Bank told authorities that up to 2,200 corporate customer records had leaked. Some of the stolen bank data included loan application details and calculated credit limits, according to the paper.
The attackers went after internet-facing systems that employees and loan agents rely on, not the internal networks that track account balances and process transactions, the JoongAng Daily reported. A source at a financial regulator told the paper that passwords and card security codes were not directly exposed, making immediate unauthorized transactions unlikely. The FSC chairman warned, however, that the stolen data could still fuel voice phishing and other scams, The Korea Herald reported.
Signs of an AI tool
Police have opened an investigation into the attacks on major banks, The Korea Times reported. The paper said a server thought to have been used against Shinhan carried traces of a Chinese-language AI tool for penetration testing, and text on the server suggested it may be connected to ARTEX AI, an open-source system built on a large language model that can probe networks for weaknesses on its own.
Regulators believe the attackers may have scanned many financial companies for weak spots rather than singling out one institution, Reuters reported, citing the Yonhap news agency. Yonhap, citing bank data submitted to lawmakers, said the attack traffic came from internet addresses in several countries, including Britain, Japan, Singapore, the United States and Vietnam.
In an editorial, the Korea JoongAng Daily said an AI agent given a target can work out its own method of attack and exploit small weaknesses to find a way in.
The main opposition People Power Party has urged authorities to also examine whether North Korea played a role, pointing to past attacks on South Korean financial institutions that were blamed on Pyongyang, Reuters reported.
What’s next
The Financial Supervisory Service sent about 500 financial firms a list of malicious IP addresses tied to the attacks and ordered them to complete emergency security checks and submit the results by Thursday, the JoongAng Daily reported. Regulators also told companies to tighten access controls, limit outside access to their systems and strengthen consumer protections, and said details on attack methods would be shared across the industry, according to Reuters.
The FSC chairman called for an approach of “AI attacks defended by AI,” Reuters reported. Authorities also identified weak login security and the excessive storage of customer data as key gaps in the industry’s defenses, and warned that firms with similar failures would face stern penalties, according to the JoongAng Daily.




