AI-generated conceptual South Korean bank cyberattack scene representing suspected AI-assisted hacking Business Security Technology

South Korea Says AI Was Used in Bank Cyberattacks — Is AI-Powered Hacking Becoming the New Normal?

Share:

South Korean authorities say artificial intelligence appears to have been used in a wave of cyberattacks against financial institutions, raising a difficult question for banks around the world: is AI-assisted hacking moving from a theoretical risk into routine criminal practice?

South Korean President Lee Jae Myung said the attacks showed signs of AI use and ordered authorities to mobilise resources quickly. Police and financial regulators are investigating a series of incidents that affected banks, savings banks and other financial firms.

AI-generated conceptual South Korean bank cyberattack scene representing suspected AI-assisted hacking
AI-generated image created for NextNews.

What has happened in South Korea?

South Korea’s financial sector has been dealing with a cluster of attacks that exposed customer information at several institutions and triggered an industry-wide security response.

Reuters reported that President Lee said AI appeared to have been used in the attacks, while the Financial Supervisory Service and Financial Services Commission moved to coordinate countermeasures across the sector.

Authorities have identified 33 IP addresses associated with the incidents, or 28 unique addresses after duplicates were removed, spanning 12 countries.

The addresses are indicators used by investigators and banks to block or monitor suspicious activity. They do not by themselves identify the attackers or prove where the attacks originated.

Sources: Reuters and Yonhap News Agency.

Which financial institutions were affected?

Reports have linked recent incidents to major banks and other financial firms including Shinhan Bank, KB Kookmin Bank, Hana Bank, BNK Busan Bank, Yegaram Savings Bank, Welcome Savings Bank and Hyundai Capital.

Shinhan Bank said personal information belonging to around 25,000 customers had been exposed, including names, phone numbers and annual income.

Hana Bank reported information relating to 89 customers had been leaked.

Other banks, including Woori Bank and NH Nonghyup Bank, were reportedly targeted but blocked unauthorised access without reporting customer-data leakage from those attempts.

South Korean regulators have also stressed that some online claims about the incidents are unverified. The Financial Services Commission said it had not confirmed claims that bank account information had been exfiltrated to China.

What does “AI was used” actually mean?

This is the most important unresolved question.

Authorities have not publicly disclosed the exact AI models, tools or workflows used in every attack.

“AI-assisted hacking” could mean several different things:

  • using an AI model to scan websites or applications for vulnerabilities;
  • automating reconnaissance across large numbers of internet-facing systems;
  • generating or modifying exploit code;
  • analysing stolen credentials and identifying likely access paths;
  • automating phishing, social engineering or credential attacks; or
  • using an autonomous agent to chain several steps together without constant human direction.

Those are materially different capabilities. Until investigators release more technical evidence, it would be premature to describe the incidents as fully autonomous AI attacks.

Why AI changes the economics of hacking

The biggest cyber impact of AI may not be a completely autonomous “robot hacker”.

It may be the ability to make ordinary attackers faster and more productive.

Tasks that once required hours of manual work — reading unfamiliar code, searching documentation, testing input patterns, translating error messages or generating tailored scripts — can increasingly be accelerated by AI.

That means smaller teams can investigate more targets and iterate faster.

For defenders, the same capability is useful. AI can triage alerts, analyse code and help identify vulnerabilities. That is why cybersecurity is becoming one of the clearest examples of AI’s dual-use nature.

Banks are particularly attractive targets

Financial institutions hold valuable personal information, credentials and transaction data while operating complex networks of customer portals, third-party software, APIs and legacy systems.

The weakest point is not always the core banking platform.

Attackers may target internet-facing applications, contractors, smaller subsidiaries or poorly maintained systems connected to a larger institution.

This is why the South Korean incidents have prompted brokerages, insurers and card issuers — not just banks — to run additional checks.

Regulators have launched a special response

South Korean authorities have ordered financial firms to identify exposed IT infrastructure, assess vulnerabilities, apply corrective measures and block suspicious addresses connected to the attacks.

A month-long special response period has been launched to reduce the risk of secondary fraud using stolen personal information.

Regulators have warned consumers about possible follow-up scams in which criminals impersonate bank employees, loan advisers or compensation services.

As of the latest reporting, authorities said they had not confirmed subsequent financial losses caused by misuse of the exposed data.

Is AI-powered hacking becoming the new normal?

AI-assisted hacking is likely to become more common, but the phrase should be used carefully.

AI does not eliminate the need for vulnerabilities, credentials or weak security controls. It cannot magically break a well-designed and well-maintained system simply because it is an AI model.

What it can do is reduce the time and expertise required for some parts of an attack.

That shifts the threat landscape in three ways:

  1. More reconnaissance: attackers can examine more systems in less time.
  2. Faster exploitation: models can help interpret code and vulnerability information.
  3. More convincing social engineering: AI can generate personalised messages, voice content and multilingual scams at scale.

The result may be more frequent attacks by moderately skilled actors rather than an immediate wave of fully autonomous cyber warfare.

Defenders are using the same technology

The defensive side is advancing just as quickly.

Anthropic recently expanded access to powerful Claude models for verified cybersecurity teams, while other frontier AI developers are building security-specific tools for vulnerability research, incident response and threat analysis.

That creates an accelerating contest in which attackers use AI to find weaknesses while defenders use AI to identify and patch them faster.

Related NextNews coverage: Anthropic expands powerful Claude models to cybersecurity teams.

Australia should pay attention

The South Korean incidents are particularly relevant to Australia because the country is already examining the consequences of AI agents interacting with government systems.

OpenAI’s Medicare-related incident exposed the difficulty of detecting and reporting unauthorised AI activity, while the federal government is reviewing whether Australia’s cyber governance is ready for AI-driven incidents.

That means the policy issue is no longer limited to hypothetical future risks. Governments and banks now need operational processes for investigating activity in which AI may be acting as an attacker, an assistant or an accidental source of harm.

The bottom line

South Korea’s bank breaches do not yet prove that fully autonomous AI hacking has become routine.

They do show something more immediate: investigators increasingly expect AI to be part of real-world cyberattack toolkits.

The distinction matters. AI is likely to make attackers faster before it makes them fully autonomous.

For banks, governments and other high-value organisations, that means vulnerability management, authentication, third-party security and incident response need to operate at a pace closer to the machines now helping both sides.

Important disclaimer

This article is provided for general news and informational purposes only. It does not constitute cybersecurity, legal, financial, privacy, compliance or technical advice and should not be relied upon as advice tailored to your circumstances.

The South Korean investigation is continuing and technical details about the AI systems allegedly used remain incomplete. Organisations should obtain independent advice from appropriately qualified cybersecurity, legal, privacy, risk and compliance professionals before changing security controls or incident-response procedures.

See the NextNews disclaimer.

Disclaimer


NextNews strives for accurate news, but use it with caution—content changes often, external links may be iffy, and technical glitches happen. See the full disclaimer for details.

Leave a Reply

Your email address will not be published. Required fields are marked *


The reCAPTCHA verification period has expired. Please reload the page.