
최근 신한은행 등 7개 금융사와 PFCT, 모우다 등에서 AI를 활용한 해킹 사고가 발생했으며, 고객 개인정보가 유출됐다. 전문가들은 AI가 취약점을 자동 탐색하는 데 악용되고 있다며, 금융권을 넘어 공공기관의 AI 보안 점검을 강화해야 한다고 경고했다.
AI-generated summary
AI 기술 발전으로 생활이 편리해졌지만, AI가 해서는 안 되는 일을 실행하는 문제가 대두되고 있다. 최근 금융권과 온투업 회사에서 해킹 사고가 발생했으며, 금융당국은 지난 7월 AI 보안 위협 대응 가이드라인을 발표했으나 피해가 발생했다.
가장 강한 성벽보다 취약한 구멍 하나 문제되기 십상
금융권 넘어 공공기관 AI 보안 점검도 대폭 강화해야
(서울=연합뉴스) 한승호 선임기자 = 인공지능(AI) 시대가 열리면서 사람들의 생활이 바뀌고 있다. 어렵게 느껴지던 일이나 시간이 너무 걸려 엄두를 내지 못하던 일도 할 수 있게 됐다. 문제는 AI가 해서는 안 되는 일을 시켜도 마다하지 않고 실행한다는 점이다.
최근 신한·KB국민·하나·BNK부산은행과 예가람·웰컴저축은행, 현대캐피탈 등 7개사에서 해킹 침해 사고가 발생했다. 온라인투자금융업(온투업) 회사인 피에프씨테크놀로지스(PFCT)와 모우다도 침해됐다.
보안시스템이 다른 업종에 비해 우수하다고 정평이 나 있는 은행의 일부 업무체계가 뚫렸다는 점에서 심각성이 있다. 더욱이 금융당국이 지난 7월 '프런티어 AI 보안 위협 금융분야 대응 요령' 가이드라인을 통해 사전 경고를 했는데도 피해가 발생했다.
AI가 금융회사 보안 공격 포인트를 빠르게 탐색할 수 있는 점을 들어 자산과 공급망에 대한 정확한 식별과 관리를 수행해야 한다는 점을 강조했는데도 막지 못했다. 해커는 대출모집인용 조회 서비스, 직원용 모바일 업무지원 시스템, 영업지원 시스템 등 보안 취약 지점을 노렸다.
현재까지 공개된 유출 정보는 고객명, 생년월일, 연락처, 주민등록번호 등으로 파악됐다. 이들 정보로 금융기관에서 부정 결제를 곧바로 할 수 있을 정도는 아니라고 하지만, 서로 다른 곳에서 유출된 개인정보 조각을 결합할 경우 맞춤형 피싱 등 2차 피해로 이어질 가능성은 남아 있다.
이번 해킹 공격에서 우려했던 대로 금융기관의 허점을 찾아내는데 AI가 활용된 것으로 보인다는 점을 주목할 필요가 있다. AI 도구를 활용해 취약점을 자동으로 탐색하고 공격을 반복했을 가능성이 제기되고 있다.
AI가 범죄를 저지르는 데도 도움을 주는 부정적 기능이 드러나고 있는 셈이다. AI가 단순한 업무를 보조하는 모델 수준을 넘어 소프트웨어의 방호벽을 무력하게 만드는 단계로 진입할 수 있다는 우려가 현실이 되고 있다.
날로 고도화 하는 AI로 무장한 해킹 범죄가 노리는 다음 타깃은 어디일까? 개인정보가 집중된 공공기관일 수도 있고, 의료·통신·에너지·교통처럼 한 번 마비되면 국민 일상 자체가 흔들리는 핵심 인프라일 수 있다고 전문가들이 경고하고 있다.
해외에서는 이미 공공기관 해킹 피해 사례가 나왔다. 지난 8월 프랑스 세무당국인 공공재정총국(DGFiP)이 해킹 피해를 보면서 수십만명의 개인과 기업관련 데이터를 탈취당했다. 부동산 지적정보 데이터베이스도 별도로 공격을 받았다고 외신이 전했다.
보안시스템은 아무리 견고하게 만들어도 관리 소홀로 인한 빈틈이 생기면 전체 보안체계의 취약점이 드러날 수 있다. 가장 강한 성벽보다 가장 취약한 구멍 하나가 문제를 일으키기 십상이다. 피해 대상이 국민 다수가 될 수 있는 공공기관 보안은 아무리 강조해도 지나치지 않다.
AI가 범죄적 공격에 이용되고 있는 만큼 AI를 활용한 방어 체계를 마련해야 한다. AI가 찾을 수 있는 공격 포인트에 대한 끊임없는 방어 시뮬레이션이 필요하다. 금융권을 넘어 공공기관의 AI 보안체계 점검도 대폭 강화해야 치명적인 피해를 막을 수 있다.
AI outlook — possibilities, not facts
공공기관을 대상으로 한 AI 활용 해킹 시도가 증가할 것이다.
Likely · Within months
금융당국은 AI 보안 점검 기준을 강화하고 정기 점검을 의무화할 것이다.
Possible · Within months
![[AI Prism] Domestic AI companies “toward an open ecosystem”... Lisa Su “Let’s go together” (Comprehensive 2nd edition)](/api/img?u=https%3A%2F%2Fimg.yna.co.kr%2Fphoto%2Fyna%2FYH%2F2026%2F10%2F07%2FPYH2026100704790001300_P2.jpg&w=320&q=72&f=webp)
AMD Chairman Lisa Su announced that she will cooperate with 13 domestic AI semiconductor companies to build a heterogeneous AI infrastructure that combines CPU/GPU and domestic AI semiconductors, develop it into a global reference model, and support the establishment of an AI research base in Korea and participation in the ROCm ecosystem.

Bloomberg reported that Chinese AI company DeepSeek is expected to secure close to 100 billion yuan (about 20 trillion won) in funding in its ongoing investment round. CATL and Tencent participated as major investors, and Deepseek's corporate value is expected to reach at least 500 billion yuan (about 100 trillion won).
![[AI Pick] Lisa Su “Betting on Korea’s AI ecosystem”… Recruiting hundreds of researchers](/api/img?u=https%3A%2F%2Fimg.yna.co.kr%2Fetc%2Finner%2FKR%2F2026%2F10%2F07%2FAKR20261007049900017_01_i_P2.jpg&w=320&q=72&f=webp)
AMD CEO Lisa Su visited Korea and announced plans to establish an AI research base (CoE) in Korea, promising to hire hundreds of researchers and expand infrastructure and industry-academic cooperation with domestic companies and universities. Cooperation discussions with 14 companies, including Rebellion, Furiosa AI, and Mango Boost, are also scheduled.

Finland's Licensing Supervisory Authority ordered Google to stop work on data center site development in the Muhos and Kayani regions until an environmental impact assessment is completed. Google planned to invest at least 13 billion euros in Finland over the next two years, but there are concerns that this measure will delay the project.

Antropic has expanded 'Project Glasswing', which supports the use of the AI model 'Claude Mythos' for cybersecurity, and introduced a three-level access authority system of defense access, red team access, and special access. Existing participating organizations will automatically be converted to special access, and new organizations will be verified and qualified in cooperation with the U.S. government. Antropic said that it discovered more than 129,000 software vulnerabilities through the program between April and July, of which 33,000 were classified as critical or high risk. However, JP Morgan Chase CEO Jamie Dimon voiced concerns, warning that Antropic's Mythos model has increased global cybersecurity risks tenfold.

Apple is collaborating with LG Electronics to jointly develop smart home devices, which will be manufactured and sold under the LG brand, while Apple will participate in design and function development. The product will be linked to Apple's new smart home hub, which is interpreted as a strategy to challenge Amazon's Ring and Google's Nest.