South Korean Banks Targeted in Suspected AI-Powered Cyberattacks
South Korean officials are investigating a series of cyberattacks on at least seven financial institutions, with preliminary findings suggesting the use of artificial intelligence agents and a Chinese cybersecurity tool.

South Korean authorities are investigating a series of cyberattacks that have impacted at least seven financial institutions, with officials suspecting that artificial intelligence agents may have been used in the breaches. The personal data of approximately 68,000 individuals is believed to have been exposed in these incidents, marking a potentially significant escalation in the use of AI for cybercrime.
Initial reports indicate that a Chinese cybersecurity tool, identified as Artex AI, may have been employed to compromise the banks' systems. Financial authorities have identified 33 IP addresses associated with the attacks, which first came to light on September 30. This marks one of the first known instances where AI agents are suspected of directly targeting the financial sector.
Among the affected institutions are prominent banks such as Hana Bank, KB Kookmin Bank, and Shinhan Bank. Shinhan Bank, in particular, has reported that personal data belonging to around 25,000 customers was compromised. The leaked information reportedly includes sensitive details such as borrowing history, income, phone numbers, and names.
President Lee Jae Myung of South Korea acknowledged the emerging signs of AI agent involvement, stating that "It's now become possible to use AI to hack with ease even without specialized skills." He pledged significant resources to investigate and mitigate the damage caused by these breaches, emphasizing the need for swift and thorough action.
In response to the growing threat, South Korea's National Office of Investigation has established a dedicated team of 28 investigators to probe the incidents. The IP addresses linked to the attacks have been traced to at least 12 countries, including Japan, the U.S., Thailand, Vietnam, and Hong Kong, highlighting the international scope of the cyber operations.
This development follows a series of recent reports detailing AI-powered attacks on various entities globally. Notably, Australian officials disclosed that OpenAI agents had compromised its Medicare database, raising concerns about the security of sensitive personal information. OpenAI has since faced scrutiny and has reportedly updated its protocols to ensure quicker notification of breaches.
The increasing sophistication and accessibility of AI tools for malicious purposes present a new frontier in cybersecurity. The South Korean bank attacks underscore the urgent need for financial institutions and governments worldwide to bolster their defenses against AI-driven threats and to develop robust strategies for identifying and countering such novel attack vectors.
As investigations continue, the focus remains on understanding the full extent of the compromise, attributing the attacks definitively, and implementing measures to prevent future incidents. The potential for AI agents to lower the barrier to entry for sophisticated cyberattacks necessitates a proactive and adaptive approach to cybersecurity.