South Korea Investigates Possible AI Use in Cyberattacks on Banks

South Korean authorities have launched a major investigation into a series of cyberattacks targeting banks and other financial companies, amid growing evidence that artificial intelligence may have played a role in the attacks.

President Lee Jae Myung said on October 6 that investigators had identified signs of AI being used in some of the incidents. He ordered authorities to establish what happened as quickly as possible and dedicate the necessary resources to limiting the damage.

The attacks affected several major financial institutions, including Shinhan Bank, KB Kookmin Bank and Hana Bank. Other affected companies included BNK Busan Bank, Yegaram Savings Bank, Welcome Savings Bank and Hyundai Capital.

More than 67,000 people are believed to have been affected by the breaches, with exposed information reportedly including names, telephone numbers, annual income, loan limits and, in some cases, resident registration numbers.

Police have created a 28-member investigation team to examine the incidents and determine whether criminal laws were violated. Authorities are also considering whether the investigation should be transferred to a newly established agency responsible for serious cybercrime involving critical infrastructure and electronic financial systems.

AI Suspected of Helping Hackers Find Weaknesses

One of the most important aspects of the investigation is the suspected use of AI-powered cybersecurity tools by attackers.

Investigators reportedly found traces associated with ARTEX AI, an open-source autonomous penetration-testing system, on a server believed to have been involved in one of the attacks. The technology was originally designed to help organizations identify vulnerabilities, but authorities suspect it may have been repurposed for malicious activities.

AI agents can potentially automate parts of the process that previously required considerable technical expertise. They can search for weaknesses, analyze systems and adapt their approach based on what they discover.

This has raised concerns among South Korean officials that artificial intelligence could lower the technical barrier for cybercriminals.

Attackers Appeared to Target Weaker Entry Points

Rather than directly attacking the core banking systems, the hackers appear to have focused on less-protected systems connected to employees, contractors, loan agents and other external partners.

In one reported case involving Shinhan Bank, attackers gained access to a portal used by loan brokers, exposing information connected to approximately 25,000 customers.

The strategy demonstrates why cybersecurity cannot focus only on a bank's main infrastructure. Third-party systems and external platforms can also become potential entry points for attackers.

No Evidence of Direct Theft of Funds So Far

Although significant amounts of personal information were exposed, South Korean financial authorities said there was no current indication that information directly usable for unauthorized payments had been stolen.

However, regulators warned that the leaked information could potentially be used in secondary crimes, including highly targeted voice phishing and smishing attacks.

Authorities are therefore treating the situation as a serious cybersecurity threat even though no major theft of money has been confirmed.

South Korea Wants AI to Fight AI

The attacks have also prompted calls for financial institutions to improve their defensive technologies.

Financial regulators have urged companies to accelerate the development of AI-based security systems capable of detecting and responding to increasingly automated attacks.

The broader concern is that traditional cybersecurity defenses may struggle to keep pace if criminals begin using AI to scan large numbers of systems and identify vulnerabilities more quickly.

A New Challenge for Financial Security

The investigation in South Korea comes as governments and cybersecurity researchers around the world examine how AI could change the nature of cybercrime.

Authorities have not yet publicly established exactly how much autonomy AI had in the South Korean attacks, nor have they released all details about the tools allegedly involved.

For now, investigators are working to determine who was behind the attacks, how the systems were compromised and what role artificial intelligence played.

The case could become an important test for financial cybersecurity as AI-powered tools become increasingly capable. If confirmed, the incidents would demonstrate how technologies originally developed to improve digital security can also be adapted by criminals to automate parts of sophisticated cyberattacks.