World & Technology
South Korea Investigates Possible AI Use in Bank Cyberattacks
Authorities are examining attacks affecting customer information at major banks while urging institutions to strengthen defenses.
A national investigation
South Korean President Lee Jae Myung said Tuesday that artificial intelligence appears to have been used in recent cyberattacks on commercial banks. Reuters reported that police, the Financial Services Commission and the Financial Supervisory Service are investigating. Authorities have not yet disclosed the specific tools, attackers or complete scope. Describing AI involvement as an initial assessment rather than a proven technical finding is important while forensic work continues.
Major institutions affected
The reported incidents involved customer information at Shinhan Bank, KB Kookmin Bank, Hana Bank and Woori Bank. The supervisory service shared technical information, including 28 unique internet addresses, to help institutions respond. An address can be an investigative clue without identifying the person controlling it, because attackers use compromised servers, proxies and cloud services. Banks need to preserve logs and coordinate before drawing attribution conclusions.
How AI may change attacks
Artificial intelligence can help criminals write convincing messages, adapt malicious code, search stolen data and automate reconnaissance. It can increase speed and scale without creating a completely new category of vulnerability. Attackers still often rely on stolen credentials, unpatched software or weak access controls. Defenders should focus on those entry points while developing tools that recognize faster, more variable behavior.
Financial-sector concentration
Banks connect payment systems, identity records, mobile applications and outside vendors, making them valuable targets. A disruption can damage individual customers and confidence in the wider economy. Regulators therefore require incident reporting, continuity plans and capital for operational risk. The current investigation should examine whether a common vendor, shared software or coordinated campaign links the affected institutions rather than assuming separate breaches.
Using AI for defense
Defensive models can analyze large volumes of network and transaction data for unusual patterns, but they also produce false alarms and may be manipulated. Human review, tested response procedures and secure model access remain necessary. Banks should not purchase an AI security product as a substitute for asset inventories, patching, multifactor authentication and backups. Technology works best when it strengthens a disciplined security program.
Cross-border lessons
The South Korean cases follow international concern about automated systems reaching government and commercial networks. Cyberattacks rarely respect national borders, and financial institutions depend on common global software. Governments can share indicators and defensive guidance while protecting customer data. Attribution and sanctions require a higher standard of evidence than an early operational warning, especially when geopolitical consequences may follow.
What the final report should answer
Authorities should explain how AI use was identified, which systems were affected, what information left the banks and whether customers face fraud risk. They should also publish remediation deadlines and lessons that other institutions can apply. If the AI conclusion changes, that correction should be explicit. Accurate technical reporting builds more confidence than dramatic labels that outrun the evidence. Customers should receive practical guidance on password changes, account monitoring and reimbursement rights rather than vague warnings. Regulators should also say whether the institutions met existing notification deadlines and whether additional enforcement is warranted.
Reporting note: This article draws on public records and verified reporting; material claims are attributed in the text.
