Ai-Linked Cyberattacks Hit Seven South Korean Financial Firms
South Korean authorities have launched an emergency cybersecurity investigation after a series of cyberattacks hit seven financial companies, exposing the personal information of tens of thousands of customers.
The attacks have raised concerns over the growing use of artificial intelligence in cybercrime, with investigators examining whether a single attacker or coordinated group used AI tools to identify vulnerabilities and target multiple financial institutions.
The affected companies include Shinhan Bank, KB Kookmin Bank, Hana Bank, BNK Busan Bank, Yegaram Savings Bank, Welcome Savings Bank and Hyundai Capital. More than 67,000 people are believed to have been affected, although the scale of the breaches varied significantly between institutions.
The largest reported breaches involved Yegaram Savings Bank, where information involving about 40,000 people was exposed, and Shinhan Bank, which reported a breach affecting around 25,000 customers.
At Shinhan Bank, leaked loan application information included customers’ names, phone numbers, annual income and calculated borrowing limits. Other breaches involved personal identification and contact information.
Authorities said there were no indications that information directly usable for unauthorised payments had been stolen. However, officials warned that exposed personal information could potentially be used for voice phishing, fraudulent text messages and other scams.
Investigators found similarities in the attacks, including the use of the same internet protocol address across several affected companies. They also discovered traces associated with ARTEX AI, an open-source autonomous security-testing tool capable of identifying vulnerabilities and attempting intrusions.
Officials stressed that the presence of the tool does not establish who was behind the attacks or where the attackers were located. Investigators are continuing to examine the attack routes and possible perpetrators.
The attacks appear to have focused in some cases on less-protected systems outside banks’ core networks, including platforms used by employees, loan agents and other external personnel.
South Korea's Financial Services Commission has ordered financial companies to strengthen their defences and restrict external access to systems unless it is essential for business operations.
The Financial Supervisory Service has also shared information about malicious IP addresses and attack methods with around 500 financial institutions. Banks and card companies have been ordered to complete emergency security checks by October 6, while other financial businesses have been given additional time.
Financial Services Commission Chairman Lee Eog-weon said authorities could not rule out the possibility that AI was involved and called for the financial sector to maintain the highest level of vigilance.
South Korean President Lee Jae-myung has ordered a thorough investigation and called for measures to prevent further breaches.
The incident has also prompted financial companies beyond the affected banks to strengthen their defences. Securities firms have begun blocking identified malicious IP addresses, reviewing their systems and increasing monitoring for further intrusion attempts.
The attacks highlight a growing cybersecurity challenge for financial institutions: the same AI technology being developed to improve security can potentially be used by criminals to automate the search for weaknesses and launch attacks at greater speed.
Related Posts
