Skip to content

(Menu)

News

AI-assisted hacks hit seven South Korean financial firms

3 min read News · Policy

About 66,000 people's data was exposed. President Lee said there are signs AI was used, and police set up a 28-person investigation team.

What happened

South Korea confirmed coordinated breaches at seven financial institutions between September 27 and October 1, exposing about 66,000 people and 2,200 corporate records. Victims include Shinhan, KB Kookmin, Hana and Woori banks plus savings banks and a consumer lender. Exposed data includes names, phone numbers, income, loan limits and in some cases resident registration numbers.

The AI angle

President Lee Jae-myung told a cabinet meeting on October 6 that there are signs AI was used in some attacks. Investigators traced them to ARTEX, an open-source AI penetration-testing tool reportedly with a Chinese-language interface, driven by a human operator. An official told AFP its use was highly likely, while some experts note AI's role is not yet proven.

66,000people whose data was exposed, plus 2,200 corporate records

Why such tools matter

Penetration-testing tools help defenders find holes first. AI versions automate scanning, ranking and test attacks, compressing days of expert work into hours. Open-source releases lower the skill needed to attack. The same week, a flaw found by Anthropic's Mythos was exploited within 24 hours.

The response

The National Police Agency assigned 28 investigators across four cyberterrorism teams, and Lee ordered a full investigation and faster development of security-focused AI.

Beyond big banks

Attackers hit savings banks and a consumer lender as well as major banks, showing that smaller institutions and suppliers with thinner security budgets are in range. AI tools shorten the time it takes to find such weak links.

Why it matters

This is one of the first cases in which a government publicly acknowledged AI as a tool that adds scale and speed to cyberattacks. Finance is a prime target because of sensitive customer data, and attackers can access the same AI tools as defenders.

What it means for your business

AI lowers attackers' costs, which puts smaller firms in range too. Patch known flaws fast, keep less sensitive customer data and encrypt what you keep, commission your own penetration test, and have a breach-notification plan ready.