South Korea’s Lee Orders Swift Bank-Hack Probe as Signs Point to AI Use
Customer information was exposed at seven financial firms. Investigators are examining reported AI traces, while regulators target missing identity checks, weak access controls and known software flaws.
A 28-member police team is investigating breaches at seven financial firms after authorities found customer-information leaks in employee and loan-solicitation systems; they reported no monetary losses or disruption to customer-facing banking. The attacks appear to have exploited missing identity checks, weak staff-service controls and known website vulnerabilities. Officials found possible ARTEX AI traces, but have not confirmed the tool’s role or attacker attribution. President Lee ordered resources for the response and urged faster development of cybersecurity-focused AI.
01
The seven firms named by authorities include Hana Bank, KB Kookmin Bank, Shinhan Bank, BNK Busan Bank, Yegaram Savings Bank, Welcome Savings Bank and Hyundai Capital.
02
The Financial Supervisory Service and Financial Security Institute shared 28 unique attacker IP addresses; authorities had earlier circulated addresses and guidance to about 500 financial companies.
03
Banks and card companies faced an October 6 inspection deadline, while securities firms, insurers and other providers had until October 8 to complete a 12-item security checklist.
South Korean President Lee Jae Myung ordered a swift investigation on October 6, 2026, after hackers exposed customer information at seven financial firms. He said signs pointed to possible AI use in some attacks and called for stronger defenses. Police have assembled a 28-member team, bringing a national response to breaches affecting major banks.
AI traces, not a settled attribution
The warning follows an October 4 Yonhap report that financial authorities found shared attacker IP addresses—network addresses used to connect online—across affected firms. Addresses used against commercial banks differed from those used against savings banks and a capital company, but the attack methods were similar. Attackers also changed addresses as they continued their attempts.
Authorities suspected AI tools had enabled large volumes of automated attacks against multiple financial firms, Yonhap reported. That was an assessment of how the attacks may have operated, not a confirmed account of AI’s role.
A financial-security official told Yonhap that traces of ARTEX AI had been found on addresses used to attack banks. The outlet described ARTEX AI as an open-source, language-model-based system for autonomously testing security weaknesses. Police were investigating those traces; the tool’s role remained unconfirmed.
Yonhap also cautioned that the tool’s worldwide availability and widely distributed addresses made attribution to a particular country difficult. As of October 6, authorities had not publicly confirmed which AI tools were involved or disclosed the full scale of the breaches.
The entry points were familiar security gaps
The suspected AI component sits alongside concrete failures in basic safeguards. Financial authorities divided the incidents into three categories and prescribed different repairs, according to Yonhap’s October 4 account:
Information-query services allowed access to loan-application details or company representatives’ information without identity verification. Firms were told to correct the missing checks or block the services.
Staff-support services lacked mobile-device access controls or left web weaknesses unresolved. Authorities called for access only from registered devices and immediate repairs to vulnerable services.
Website attackers exploited known vulnerabilities, installed malicious software and stole logs containing customer information. Regulators directed firms to fix those weaknesses or block affected services.
Authorities said other financial firms also faced intrusion attempts. Whether attackers succeeded depended on multiple authentication checks and advance fixes to vulnerabilities. The October 4 assessment found information leaks from systems for employees and loan solicitors, but no monetary losses or impact on customer-facing internet and mobile banking.
We must have the security capabilities to detect and block attacks in advance.
President Lee Jae Myung, at the October 6 Cabinet meeting, as quoted by Yonhap
Immediate inspections, longer-term AI defenses
Lee urged faster development and adoption of AI tools tailored to cybersecurity. His instructions paired that goal with dedicating personnel and resources to limiting damage from the current attacks. The seven firms with exposed customer information included Hana Bank, KB Kookmin Bank and Shinhan Bank.
The affected institutions extend beyond those major commercial banks. Financial authorities’ October 4 list also named BNK Busan Bank, Yegaram Savings Bank, Welcome Savings Bank and Hyundai Capital. Together with Hana, KB Kookmin and Shinhan, those institutions made up the seven firms identified in that assessment.
Regulators’ immediate response extended across the sector. The Financial Supervisory Service said on October 6 that it and the Financial Security Institute had shared 28 unique IP addresses and associated country information. Earlier, authorities had circulated attack addresses and security guidance to roughly 500 financial companies.
Banks and card companies were given an October 6 inspection deadline; securities firms, insurers, savings banks and electronic-finance providers had until October 8. The 12-item checklist covered blocking attacker addresses, investigating damage and securing externally exposed systems. Firms were instructed to remedy shortcomings immediately.
Authorities also planned on-site inspections of affected companies and sector-wide sharing of weaknesses and successful fixes. A broader effort to have firms correct basic IT controls runs through November. Regulators warned of strict action if inadequate checks lead to major IT failures or security incidents.
Editorial illustration for South Korea’s Lee Orders Swift Bank-Hack Probe as Signs Point to AI Use.
Sources
yna.co.kr"금융사 해킹사고, 동일 공격 IP 여러 곳 발견…AI활용 추정"(종합) | 연합뉴스
en.yna.co.kr(LEAD) Lee orders dedication of personnel, resources to handling hacking attacks | Yonhap News Agency
japantimes.co.jpSouth Korea’s Lee says AI appears to have been used in bank hacks
Reader comments
Newest comments first. Replies stay oldest first.