Skip to content

AI·News & analysis

South Korea's president says AI was likely used in a wave of bank hacks

Shinhan, KB Kookmin, Hana and four other lenders reported breaches in a week. President Lee Jae Myung says there are signs AI was involved, and investigators found traces of an AI hacking tool.

By Dan Kost aka Poseidan9 min read
Street view of a KB Kookmin Bank branch in Gunpo, South Korea, with its yellow and black sign above the entrance
Photo: LandAndTree / Wikimedia Commons, CC0

Tide

Wave

Sci-fi

3/10

Reality

Shipping

The hacker never sleeps, because the hacker is software.How we rate

The Squeeze

South Korean President Lee Jae Myung says AI was likely used in hacks that hit seven Korean financial firms in about a week, a rare public claim from a head of state.

The attackers went through side systems used by employees and loan agents, not online banking, and took names, phone numbers, incomes and some national ID numbers. If AI tools let attackers scan a whole industry for weak spots at once, every bank's least-watched system becomes a target.

What to know

  1. South Korean President Lee Jae Myung said on Tuesday that there are signs AI was used in some of the recent hacks against the country's banks.
  2. Seven financial firms reported breaches since the start of October, including Shinhan Bank, KB Kookmin Bank, Hana Bank and BNK Busan Bank. Shinhan's breach alone hit about 25,000 customers.
  3. A server believed to be used in the Shinhan attack carried a Chinese-language title meaning 'AI autonomous penetration testing console', which local media linked to the open-source tool ARTEX AI. Officials haven't confirmed it.
  4. Police have opened an investigation, regulators traced about 30 IP addresses in a dozen countries, and the rest of the financial sector is checking its systems.

South Korea's president says artificial intelligence was probably used to hack the country's banks.

"In some hacking incidents, signs have emerged of AI being used, causing considerable public concern and anxiety," President Lee Jae Myung said at a cabinet meeting on Tuesday, Reuters reports. "Please establish the circumstances swiftly and clearly, and concentrate personnel and resources on minimizing the damage."

It follows a week in which seven financial firms reported breaches, including three of the country's largest banks. Police are investigating, and the rest of the financial sector is checking its systems for weak spots.

What happened?

The breaches came fast, starting at the beginning of October during an extended holiday period.

Shinhan Bank went first. On Thursday, it said personal information on about 25,000 customers had leaked. An unauthorized party bypassed authentication to reach a service that loan agents use to check the status of applications, The Korea Times reports. Exposed data included names, phone numbers, annual income and borrowing limits, along with other information submitted for loans.

KB Kookmin Bank followed on Friday. It said data on 119 customers leaked after abnormal external access to a mobile system used by employees. Depending on the customer, it included names, phone numbers, addresses and resident registration numbers, Korea's national ID numbers, in encrypted form.

Hana Bank said the same day that data on 89 customers was exposed after an external hacking agent tried to get into its sales support system. It included resident registration numbers, names, addresses, emails, phone numbers and workplace details.

BNK Busan Bank said information on 11 outsourced workers leaked. Woori Bank and NH NongHyup Bank said they were attacked too, but no data was exposed.

It spread beyond the big banks

The attacks didn't stop at commercial lenders.

Yegaram Savings Bank reported a leak involving about 40,000 customers, and Hyundai Capital said personal data on 146 housing loan agents was exposed, The Korea Times reports. Welcome Savings Bank is also on the list of seven firms that have reported breaches since the start of the month.

Regulators and industry officials now suspect the attackers scanned a broad range of companies for weaknesses instead of going after one target. They warn more cases may surface, since smaller firms have fewer security staff and the attacks were timed during October's long holiday.

Brokerages, insurers and card issuers say they haven't found leaks so far. Some security teams at brokerages reportedly worked through the holiday weekend on internal reviews.

Why do officials suspect AI?

Two reasons: the evidence on one server, and the pattern.

The server: Yonhap reported that a server believed to be used in the Shinhan attack had an HTML page title in Chinese meaning "AI autonomous penetration testing console." That suggests a possible link to ARTEX AI, an open-source autonomous penetration-testing system built on a large language model, The Korea Times reports.

The server is suspected of being used in a credential stuffing attack, where stolen usernames and passwords are tried automatically across many logins.

What the tool does: ARTEX AI uses agents to automate information gathering, vulnerability discovery, attack-path planning, running security tools and verifying flaws, BleepingComputer reports.

Not confirmed: neither the bank nor financial authorities have confirmed the tool was used. The Chinese-language string also doesn't link the attacks to any particular group, BleepingComputer notes.

The pattern: instead of hitting banks' core networks, the attackers repeatedly probed systems used by employees and for sales support. That pattern raised suspicions that the attacks were automated with AI, The Korea Times reports.

Moon Jong-hyun, head of the Genian Security Center, wrote on LinkedIn that several threat analysts believe the breaches involved AI-based attack automation tools, according to BleepingComputer.

Where did the attacks come from?

Nobody knows yet.

The digital risk team at the Financial Supervisory Service, South Korea's financial watchdog, has identified about 30 IP addresses tied to the attacks, The Korea Times reports. They span the US, Japan, Hong Kong, Singapore, Vietnam, Thailand, Malaysia, Spain, Latvia, Sweden, Germany and Korea.

The attacker may have used addresses in many places to hide their trail. Authorities stress that an IP address's location alone doesn't establish the attacker's nationality or the real source of an attack.

Industry officials quoted by The Korea Times said the hackers behind the Shinhan attack are suspected of being based overseas.

How is the government responding?

The president: on Sunday, Lee ordered a thorough investigation after a briefing on the breaches. "The president ordered officials to conduct a thorough investigation and make every effort to devise measures, with a grave awareness of the seriousness of the matter," presidential spokesperson Kang Yu-jung said, according to The Korea Times.

The regulators: the same day, Financial Services Commission chairman Lee Eog-weon and Financial Supervisory Service governor Lee Chan-jin held an emergency meeting with banks, brokerages, insurers, card companies, savings banks and fintech firms.

"We are seeing multiple data breaches across the financial sector in a short period of time," the FSC chairman said. "The entire industry must take the situation seriously and remain on the highest alert."

He also said authorities couldn't rule out that AI was used, and regulators urged firms to adopt AI-based security and join government AI security testing.

Orders to firms: companies must inspect every externally accessible system, including ones that don't face customers, reduce unnecessary data exposure, check for weak authentication and access controls, share threat information quickly and submit their inspection results, BleepingComputer reports.

The police: the Korean National Police Agency's cyber terror unit began a preliminary inquiry into Shinhan, KB Kookmin, Hana and BNK Busan last week, The Korea Times reports. Yonhap reported on Tuesday that police have now launched a full-scale investigation, according to Reuters.

Was any money taken?

Not that anyone has found.

Authorities say there's no sign that information usable for unauthorized payments leaked. KB Kookmin and Hana said the breached systems were separate from their internet and mobile banking, that no transaction data leaked and that they'll fully compensate any losses.

The bigger risk is what comes next. Officials warned the stolen data could fuel voice phishing and other fraud, since scammers can sound convincing when they already know your name, income and loan limit.

Part of a bigger pattern

South Korea isn't the only government dealing with AI agents in hacking.

In September, Australia said an OpenAI agent breached a government health data portal in June, getting unauthorized access to files, Reuters reports. Last week, an AI research firm said agents tried to hack a Canadian government website, which it described as a failed attempt. Canada said there was no sign its systems were compromised.

Security experts told The Korea Times that AI is lowering the technical barrier to attacks, with agents able to combine scattered information, find vulnerabilities, launch attacks and adjust based on the results.

What it means for you

  • If you bank with an affected firm in South Korea: expect a notice if your data was involved, and be wary of calls or texts that cite your loan, income or ID details.
  • If you run security anywhere: the attackers went after side systems such as loan-agent lookups and employee apps, not the main banking platform. Check your least-watched logins first.
  • Everyone else: automated attacks can hit many companies in days, so leaks from places you've never heard of may still include your data.

The bottom line

A wave of breaches hit seven South Korean financial firms in about a week, and the country's president now says AI was likely involved. Investigators found traces of an AI hacking tool on one server but haven't confirmed its use or who's behind it. No payment data appears to have leaked, but the stolen personal details leave customers exposed to scams.

Key facts

Firms breached
7 since early October
Largest breach
Shinhan Bank, about 25,000 customers
Suspected tool
ARTEX AI traces on one server (unconfirmed)
Attack IPs
About 30, across a dozen countries and territories
Payment data leaked
None found so far, regulators say

Got questions?

Quick answers, plain words

What did President Lee Jae Myung say?

At a cabinet meeting on Tuesday, he said: 'In some hacking incidents, signs have emerged of AI being used, causing considerable public concern and anxiety.' He told officials to establish the facts quickly and focus resources on limiting the damage, Reuters reports.

Which banks were hit?

Shinhan Bank, KB Kookmin Bank, Hana Bank and BNK Busan Bank confirmed leaks, along with Yegaram Savings Bank, Welcome Savings Bank and Hyundai Capital, according to The Korea Times. Woori Bank and NH NongHyup Bank said they were targeted but no data was exposed.

How many people were affected?

Shinhan reported about 25,000 customers, Yegaram Savings Bank about 40,000, KB Kookmin 119 and Hana 89. BNK Busan said data on 11 outsourced workers leaked, and Hyundai Capital said data on 146 housing loan agents was exposed, The Korea Times reports.

What information leaked?

It varied by firm. Leaked data included names, phone numbers, addresses, annual income and loan limits, and for some customers resident registration numbers, Korea's national ID numbers.

Was money stolen or online banking hacked?

Regulators say they have found no sign that information usable for unauthorized payments leaked. KB Kookmin and Hana said the breached systems were separate from their internet and mobile banking platforms.

What evidence points to AI?

Yonhap reported that a server believed to be used in the Shinhan attack had a page title in Chinese meaning 'AI autonomous penetration testing console', suggesting a link to ARTEX AI, an open-source hacking tool built on a large language model. Neither the bank nor regulators have confirmed it was used.

What is ARTEX AI?

An open-source penetration-testing system that uses AI agents to automate information gathering, finding vulnerabilities, planning attack paths, running security tools and verifying flaws, according to BleepingComputer. Penetration testers use such tools to find weaknesses before attackers do.

Who is behind the attacks?

Unknown. Regulators traced about 30 IP addresses in places including the US, Japan, Hong Kong and Germany, but say an IP address's location doesn't reveal the attacker's nationality. The Chinese-language string also doesn't tie the attacks to any specific group, BleepingComputer notes.

What should customers of these banks watch for?

Authorities warn the leaked data could be used for voice phishing and other scams. Treat unexpected calls or texts that mention your loan, income or account details with suspicion, and contact your bank through its official number.

Has AI been linked to hacking elsewhere?

Yes. In September, Australia said an OpenAI agent breached a government health data portal in June, and an AI research firm said last week that AI agents tried to hack a Canadian government website. Canada said there were no signs its systems were compromised, Reuters reports.

SourcesThe Korea Times
Topics and tagsAI agents, Cybersecurity, AI policy, south korea

The daily newsletter

Tech news you'll actually get.

One short email a day. Five minutes. Plain words. Free, every morning.

Free. One email a day. Unsubscribe anytime.

More in brief