AI Frontier Post
AI News

AI may be hacking South Korea's banks: Lee orders a full investigation after 68,000 customers hit

President Lee Jae-myung said on Tuesday there are signs AI was used in recent bank hacks that exposed customer data across more than seven institutions, and ordered police and regulators into a full-scale investigation.

South Korean President Lee Jae-myung said on Tuesday that AI models are believed to have been used in a string of recent hacking incidents against the country's banks, and ordered a full-scale investigation. HK Businesswire reported that police announced the probe at Lee's urging, as more than seven financial institutions reported customer data breaches over the past week.

"There are signs that artificial intelligence was used in some hacking attacks, causing considerable concern and anxiety among the public," Lee told a cabinet meeting, according to Reuters. "We have now reached a point where AI can make [hacking] easy for even those without special skills."

68,000 customers and counting

The scale is already substantial. According to the Financial Services Commission, more than 68,000 people have been affected. Shinhan Bank, where the investigation began, said information attached to loan applications for about 25,000 customers — including names, phone numbers and annual income — had been leaked. KB Kookmin Bank, Hana Bank and BNK Busan Bank later reported their own breaches, and the trouble has spread beyond commercial banks: Yegaram Savings Bank reported a breach involving around 40,000 customers, while Hyundai Capital said personal information belonging to 146 housing-loan agents was exposed, GBHackers reported.

A monitor glowing in a dark room, showing blurred penetration-testing terminal windows — AI-assisted intrusion tools are suspected in the Korean bank breaches.
Investigators are examining whether AI-based attack automation played a role, especially in the Shinhan Bank breach. Image: AI Frontier Post (AI-generated).

The "AI autonomous penetration testing console" clue

The AI angle has one concrete thread. Security researchers found a Chinese-language string translated as "AI autonomous penetration testing console" in the HTML title of infrastructure believed to be linked to the Shinhan intrusion. The string has been linked to ARTEX AI, an open-source, large language model-based penetration testing framework designed to automate reconnaissance, vulnerability discovery, attack-path planning and tool execution. But GBHackers cautions that the presence of the string does not prove the framework was used in the attacks or that AI autonomously conducted the intrusions — the tool is publicly available, and attribution is still under investigation. Reports from Korea Times have also connected the Shinhan incident to credential stuffing, where attackers automate login attempts with previously compromised credentials; AI-assisted orchestration could make such campaigns quicker and harder to distinguish from legitimate traffic.

Seoul's answer: AI fighting AI

The regulatory response has been swift. Financial Supervisory Service (FSS) data — 28 unique IP addresses and some country information linked to the hacking attempts — was shared with the financial sector on Tuesday. On Sunday, FSC Chairman Lee Eog-weon convened an emergency meeting with financial industry associations, regulators and executives from the affected institutions, Reuters reported, warning that the sector must respond with the highest level of vigilance. "With advances in AI technology, hacking methods are becoming increasingly sophisticated, while the scope of the damage is spreading across all areas on a scale that is difficult to compare with the past," Lee said. "The government, companies and our society as a whole need to recognise the seriousness of the current situation and remain particularly vigilant." Regulators are now pushing "AI attacks responding with AI" initiatives — AI security testing and AI-driven detection models, phishing-resistant multifactor authentication, and monitoring for credential stuffing.

A security analyst monitoring rows of servers in a bank data center — Korean regulators are pushing AI-driven detection in response to the breaches.
The Financial Security Institute notes attackers rotate IP addresses across locations, making attribution hard. Image: AI Frontier Post (AI-generated).

Part of a bigger, faster pattern

The Korean case lands amid a run of AI-involved intrusions. Last month, Australia disclosed that an OpenAI agent had breached a government health data portal in June — what could be the first known instance of an AI agent hacking a government website — as we covered here. An AI research firm also said last week that AI agents had tried to hack into a Canadian government website, in what Ottawa described as a failed attempt. The through line is Lee's warning: AI is compressing the skill barrier for offensive operations, so defenders can no longer assume attackers are skilled humans. Meanwhile Seoul is pushing hard on both sides of the AI ledger — the government just added a $3.5B frontier AI program to its sovereign-model drive the same day the bank-hack investigation began.

What to watch

Two questions now decide how big this story gets. First, attribution: whether investigators can confirm AI-automated attack tooling — and which tools — were actually used, versus opportunistic attackers borrowing the hype. Second, containment: authorities have found no leaked payment credentials or evidence of unauthorized transactions yet, but they warn the stolen profiles could fuel targeted voice phishing and social-engineering fraud. With IP-based attribution acknowledged as nearly useless when attackers hop across addresses, the FSS's AI-detection push may be the more durable outcome of this episode than any arrests.