October 8, 2026

South Korean President Lee Jae Myung didn’t waste time. On October 4 he ordered a full investigation into a sudden wave of cyberattacks that hit the country’s financial sector. The breaches exposed personal and credit data belonging to tens of thousands of customers. Banks scrambled. Regulators convened emergency meetings. And questions mounted about whether artificial intelligence had lowered the bar for sophisticated intrusions.

The incidents began quietly enough. Shinhan Bank reported unauthorized access on September 30. Roughly 25,000 customers saw their names, phone numbers, annual incomes, loan limits and in some cases resident registration numbers compromised. TechRepublic laid out the numbers early. Similar problems surfaced at KB Kookmin Bank, affecting 119 customers and 20 staff members. Hana Bank reported 89 affected individuals. BNK Busan Bank acknowledged a breach involving 11 outsourced developers. Then came the secondary lenders. Yegaram Savings Bank lost data on about 40,000 customers. Hyundai Capital saw information on 146 housing loan agents exposed. Welcome Savings Bank added corporate client records for as many as 2,200 entities. The total climbed past 65,000 people.

But the scale told only part of the story. Attack traffic traced back to 28 or 30 distinct IP addresses scattered across a dozen countries. The United States. Japan. Singapore. Vietnam. Britain. Hong Kong. Even Latvia and Sweden. Reuters reported the geographic spread, noting that investigators viewed the pattern as a broad scan rather than a laser-focused campaign against any single target. The attacks didn’t appear to penetrate core banking platforms that handle deposits or payments. Instead they hit peripheral systems. Loan inquiry services used by brokers. Mobile work-support tools for employees. Sales support platforms.

That choice of targets mattered. These auxiliary systems often receive less rigorous protection than the crown jewels. Authentication flaws surfaced. Session management weaknesses appeared. External access controls proved porous. Financial Services Commission Chairman Lee Eog-weon called for the highest level of vigilance. He convened an emergency meeting on October 4 that brought together regulators, industry associations and executives from the affected firms. The directive was clear. Conduct comprehensive security inspections. Tighten access controls. Minimize external system linkages. Strengthen consumer safeguards. Share threat intelligence without delay.

President Lee received a briefing on the breaches and the initial responses. Presidential spokesperson Kang Yu-jung relayed his instructions. “Take the matter with the utmost seriousness and make every effort to conduct a thorough investigation and draw up countermeasures.” The president later addressed the issue in a cabinet meeting. He pointed to emerging signs that AI models had played a role. “Signs have emerged that AI models had been used in some of the cyberattacks, causing considerable public concern and anxiety,” he said. Lee warned that rapid advances in machine learning now allow individuals without deep technical expertise to execute complex operations. The barrier had dropped.

Evidence accumulated quickly. Traces of automated tools surfaced in the Shinhan incident. A Chinese-language AI agent reportedly identified vulnerabilities and mapped attack routes. On October 8 The Korea Herald detailed findings from cybersecurity firm CrowdStrike. The attacker likely spoke Chinese and operated with financial motives. The group employed ARTEX, an open-source AI-powered penetration testing framework developed in China. They supplemented it with large language models including DeepSeek v4.1-flash, GLM-5.3, Grok 4.6 and sessions through Claude. Two servers played central roles. One in Hong Kong served as primary infrastructure. Another hosted the ARTEX tool. The intruder even queried Claude about marketplaces for stolen South Korean data and Telegram channels that trade such information. The financial motive looked plain.

Financial Supervisory Service officials could not rule out AI involvement. They advocated an approach that pairs artificial intelligence defenses with artificial intelligence attacks. Broader upgrades to the sector’s cybersecurity posture now sit on the agenda. Yet the government also moved to protect citizens directly. Regulators issued a consumer alert at the caution level. They launched a monthlong special response period aimed at preventing fraud that might exploit the stolen data. Banks must report suspected scams immediately. They share indicators through an AI-powered voice-phishing monitoring platform. Suspicious payment accounts face swift suspension. Authorities stress that no evidence has emerged of payment credentials or login details being taken. Still, the combination of names, contact information, income figures and resident registration numbers offers rich material for phishing campaigns and identity theft.

The breaches arrive against a backdrop of heightened cyber activity across South Korea. The Bank of Korea and the Export-Import Bank recorded sharp increases in probing attempts this year. One law firm in Seoul’s Seocho district began recruiting Shinhan customers for a potential damages lawsuit, charging a 10,000 won participation fee plus 10 percent contingency. Public anxiety spread beyond finance. Leaks hit an online training platform run by the Anti-Corruption and Civil Rights Commission and even touched two major churches. The pattern suggests attackers probe for easy entry points wherever they appear.

So far investigators have stopped short of attributing the campaign to a specific nation-state actor. CrowdStrike assessed the perpetrator as likely a Chinese speaker driven by profit rather than espionage. The use of open-source tools and commercial large language models fits a profile of opportunistic cybercriminals who harness readily available technology. But the speed and coordination across multiple institutions raise concerns about how easily such methods can scale. One bank discovered an intrusion that lasted nearly two hours only days later. Detection clearly lagged in places.

President Lee’s response reflects both immediate pressure and longer-term worry. South Korea has endured massive data incidents before, including the 2025 Coupang breach that exposed records for more than 33 million users. That episode drew heavy fines and calls for stricter penalties on corporate negligence. The current financial sector events echo those frustrations. Banks issued apologies. Shinhan Bank’s CEO Jung Sang-hyuk pledged full compensation for any customer losses. Yet trust has taken a hit. Customers wonder how their loan applications and credit profiles ended up in unauthorized hands.

Regulators now push institutions to stop storing unnecessary personal information on externally accessible systems. They want loan solicitors and brokers to operate with tighter boundaries. On-site inspections continue. The Financial Supervisory Service identified the cluster of IP addresses and continues tracing them. Some remain masked or unresolved. The work will take time. And the findings could reshape how South Korean financial firms approach third-party access, cloud services and employee mobile tools.

The episode also highlights a larger shift. Artificial intelligence doesn’t just power new services. It arms attackers who once needed custom malware or rare skills. Automated vulnerability scanning, natural language prompts to coding assistants, self-improving exploit paths. These capabilities compress the time between reconnaissance and execution. Defenders face an adversary that iterates faster than traditional rule-based security can match. FSC leaders speak of “AI attacks defended by AI.” The phrase may sound like a slogan today. It could become standard operating procedure tomorrow.

For now the priority remains containment and accountability. President Lee wants facts uncovered swiftly and clearly. He has mobilized specialized personnel and technical resources. Industry executives sat in the same room with regulators on a Sunday afternoon. That urgency signals recognition that the problem extends beyond any single bank. The attacks exploited common weaknesses. Their success across institutions points to systemic gaps. Closing those gaps will demand more than patches. It will require cultural changes in how data is handled, how access is granted and how threats are monitored in real time.

Customers received notifications. Monitoring services rolled out. But the deeper reckoning lies ahead. If a financially motivated actor using off-the-shelf AI tools can harvest credit profiles from multiple major banks in a matter of days, then the assumptions that underpinned previous cybersecurity strategies need revision. South Korea’s regulators and its president appear to understand the stakes. The investigation continues. The countermeasures are only beginning.

South Korea’s Banks Under AI-Assisted Assault: President Lee Demands Answers first appeared on Web and IT News.

Leave a Reply

Your email address will not be published. Required fields are marked *