Breaking
TRBreaking news... Response from the Ministry of Justice to Özgür Özel's allegations: It is a baseless slanderRUIn Podolsk, a drone damaged the glazing of a houseRUMirra Andreeva reached the semi-finals of the “thousandth” in BeijingJPHanshin's Teruaki Sato becomes the 9th Triple Crown winner in history, the first in 4 years since Munetaka Murakami - professional baseballUSLast call to volunteer at TechCrunch Founder Summit 2026INDemonstrations against Gyanesh Kumar from Delhi to Patna and BengaluruUSChina’s Manus raises over $500M in first funding round since split with MetaRUWhat is known about the failure of RunetRUThe EU extended individual sanctions against Russians for a yearRUEstonia threatened with possible closure of the Baltic Sea to RussiaTRBreaking news... Response from the Ministry of Justice to Özgür Özel's allegations: It is a baseless slanderRUIn Podolsk, a drone damaged the glazing of a houseRUMirra Andreeva reached the semi-finals of the “thousandth” in BeijingJPHanshin's Teruaki Sato becomes the 9th Triple Crown winner in history, the first in 4 years since Munetaka Murakami - professional baseballUSLast call to volunteer at TechCrunch Founder Summit 2026INDemonstrations against Gyanesh Kumar from Delhi to Patna and BengaluruUSChina’s Manus raises over $500M in first funding round since split with MetaRUWhat is known about the failure of RunetRUThe EU extended individual sanctions against Russians for a yearRUEstonia threatened with possible closure of the Baltic Sea to Russia
BackS. Korea warns of AI-aided hacking after bank data breaches
S. Korea warns of AI-aided hacking after bank data breaches
Developing
Deutsche Welle1 hour agoTech4 min read

S. Korea warns of AI-aided hacking after bank data breaches

Financial institutions, churches, and energy providers hit by cyberattacks potentially utilizing AI-assisted tools

Quick Look

  • South Korea is mandating a security overhaul after hackers breached seven major banks and other institutions, stealing data from 68,000 customers.
  • Officials warn that AI-driven phishing and vulnerabilities in auxiliary systems pose a growing national threat.

AI-generated summary

Why It Matters

South Korean financial institutions and public entities suffered a series of cyberattacks involving the theft of personal data from 68,000 customers. The attacks exploited weak authentication protocols in auxiliary systems.

Font size

The South Korean government has demanded a comprehensive overhaul of safeguards against hackers after seven of the nation's major financial institutions' cyber defenses were breached last week and the private data of thousands of customers was leaked.

The data breaches go beyond the financial sector, with two of the largest churches in the country and Korea Electric Power Corp. on Wednesday confirming that their online systems had been illegally accessed, although it is not clear whether the same perpetrator was responsible for all the attacks.

On Tuesday, Prime Minister Han Seong-sook called for measures to be taken swiftly to halt any further leaks.

"This is a serious situation because this incident is believed to have taken advantage of artificial intelligence, and if AI is used in phishing attacks, it could lead to secondary damage," Yonhap News quoted Han as saying at a Cabinet meeting.

"It is also a serious situation in that similar hacking methods could spread beyond the financial sector to industries, as well as government and public sectors."

Threats to other sectors

Han said government agencies, public institutions, the financial sector and private enterprises all need to "remain vigilant."

Early reports from the US-based cybersecurity firm CrowdStrike suggest that the attack may have originated in China, although South Korea's Financial Supervisory Service (FSS) said it had identified 28 internet protocol addresses in the United States, Japan, Germany and at least 10 other countries that were involved in the bank breaches.

"South Korea officials are being careful about how they are framing their findings," said Aditya Das, an analyst at cryptocurrency research firm Brave New Coin in Auckland, New Zealand.

In the bank logs, investigators found traces of a tool called ARTEX, an open-source "autonomous penetration-testing" agent built by a Chinese developer, he said.

"It is freely available on the internet and officials have said explicitly that a Chinese-built tool doesn't mean Chinese attackers," Das told DW, adding that the use of multiple IP addresses is likely to be "a ploy by the hackers to hide their tracks."

It appears that the hackers exploited weak authentication protocols in portals used by external loan recruiters, employees' mobile tools and sales-support systems.

Data on thousands of customers lost

According to South Korean media reports, data belonging to as many as 68,000 customers was taken, with Shinhan Bank, KB Kookmin Bank and Hana Bank among the worst affected. Names, phone numbers, annual income figures, loan limits and their loan products were accessed, along with a small number of national identification numbers.

Das pointed out that if a scammer has a person's name, phone number, income figure and is aware that the individual has recently applied for a loan, a fake "bank security" call can be very convincing to the unwary. Once a victim has transferred funds to an account specified by the scammer, it is very difficult to get it back.

Hyobin Lee, a professor at Sogang University in Seoul, says the seriousness of the incident goes far beyond the simple exposure of personal information.

"If criminals obtain such information, they may be able to carry out sophisticated financial fraud, identity theft, or highly targeted phishing attacks," she said.

"Another concern is that stolen personal information can be reused or combined with other leaked databases, potentially creating security risks that persist long after the original attack," Lee underlined.

"More broadly, such incidents can undermine public confidence in financial institutions and raise concerns about the security of the financial system as a whole."

While major financial institutions have invested heavily in protecting their core systems, such as internet banking and mobile banking platforms, Lee said they have overlooked other elements of their networks.

"Some auxiliary systems, such as loan agent information portals and internal mobile applications used by employees, appear to have received less security attention," she said, adding that the application of AI by the hackers is another concerning element.

AI makes hacking easier?

"In the past, identifying security vulnerabilities, developing malicious code and conducting attacks against financial institutions required substantial technical expertise and considerable time," Lee pointed out. "Today, generative AI tools can assist with writing computer code, analyzing software vulnerabilities, processing large amounts of information and automating certain stages of cyber operations."

AI is "lowering the technical barriers to cybercrime" and making it accessible to more bad actors. At the same time, the technology is ramping up the speed and scale of attacks to overwhelm cyber defenses.

Given those developments, Lee fears that AI-assisted cyberattacks are only going to become more frequent.

"And the risks will not be limited to financial institutions," she said. "Hospitals, government agencies, energy infrastructure, telecommunications networks and other organizations holding sensitive information may also become increasingly attractive targets."

What to Watch

AI outlook — possibilities, not facts

  • Government-mandated security audit for all major financial institutions.

    Very likely · Within months

Open Questions

  • Are the attacks on banks and churches linked to the same perpetrator?
  • Will the government impose specific fines on the affected banks?

Related Topics

This article was originally published by Deutsche Welle.

Related Stories

More on this topiccybersecurity