Join a community of professionals and get:
on all CeFPro events.
unlock speaker decks and audience polls.
Full library access the moment you sign up.
Digital Content

- Unlimited access to peer-contribution articles and insights
- Global research and market intelligence reports
- Discover Connect Magazine, a monthly publication
- Panel discussion and presentation recordings
- South Korea is investigating suspected AI-assisted cyberattacks against major banks
- President Lee Jae Myung has called for cybersecurity defenses designed for the AI era
- Attackers targeted peripheral systems rather than banks' heavily protected core platforms
- Shinhan Bank confirmed data relating to around 25,000 customers was exposed
- Regulators have told financial firms to review externally accessible systems and security controls
- Insurers, brokerages and card companies are also strengthening defenses
- Experts warn AI could dramatically increase the speed and scale of cyberattacks
South Korea is scrambling to strengthen financial-sector cybersecurity after artificial intelligence was suspected of being used in a series of attacks against major banks, raising fresh concerns about the ability of increasingly autonomous tools to exploit vulnerabilities at speed.
President Lee Jae Myung said Tuesday that investigators had identified indications of AI involvement in recent hacking incidents and called for cybersecurity defenses designed specifically for the AI era.
"In some hacking incidents, signs have emerged of AI being used, causing considerable public concern and anxiety," Lee told a cabinet meeting.
"Please establish the circumstances swiftly and clearly, and concentrate personnel and resources on minimising the damage," he added.
The warning follows attacks involving Shinhan Bank, KB Kookmin Bank and Hana Bank, while Woori Bank and NH Nonghyup Bank have also reported suspected hacking attempts.
South Korean police have launched a full-scale investigation, while financial regulators are coordinating their response across the industry.
The incidents appear particularly significant because attackers targeted systems around the edges of banks' heavily protected core infrastructure.
Employee, loan-recruiter and sales-support services were among those affected, highlighting how attackers can potentially circumvent hardened banking platforms by identifying weaker entry points elsewhere in an institution's technology estate.
Shinhan Bank confirmed that information relating to approximately 25,000 customers was exposed.
Hana Bank reported that 89 customers' personal information had been compromised through abnormal access to a sales-support system, while KB Kookmin Bank identified a breach involving 119 customers.
The banks said financial transaction data was not affected in those incidents.
The concerns have now spread beyond banking. Brokerages, insurers and card issuers are reviewing their defenses, although no related data leaks had been confirmed in those sectors as of Tuesday this week.
South Korea's Financial Supervisory Service has identified around 30 IP addresses associated with the attacks and instructed financial companies to examine externally accessible IT infrastructure, authentication controls and potential vulnerabilities.
The incidents provide an early indication of how AI could change the economics of cybercrime.
Automated agents potentially allow attackers to scan systems, identify vulnerabilities and repeatedly test potential entry points at a scale and speed difficult to achieve manually.
Kim Hwan-guk, professor at Kookmin University's Department of Information Security and Cryptography, warned that the threat is likely to grow.
"Attempts to attack vulnerable sites using AI will increase in the future," Kim said, arguing that financial institutions need to shift toward AI-based defensive systems.
The South Korean attacks also follow recent international incidents involving AI agents targeting government systems, adding to concern that autonomous cyber capabilities are moving beyond controlled security testing and into real-world attacks.
For banks, the emerging risk extends beyond defending core infrastructure.
The attacks demonstrate that AI-enabled hackers may search continuously across peripheral systems for the weakest route into an institution – potentially forcing cybersecurity teams to defend an expanding attack surface against adversaries capable of operating at machine speed.