South Korea Says AI May Have Been Used To Hack Banks As Cyber Threat Enters New Era

South Korea Investigates Signs AI Was Used In Attacks On Major Banks

South Korean Banks Hit By Cyberattacks As Officials Investigate Possible AI Role

AI Enters The Banking Cyberwar

South Korean authorities are investigating a wave of attacks on financial institutions after President Lee Jae Myung said signs had emerged that artificial intelligence was used in some of the hacking.

The warning raises a much bigger question than one series of breaches.

If AI is now helping attackers probe banks, analyse weaknesses and accelerate parts of an intrusion, cybersecurity may be entering a period where the speed of attack becomes as important as the sophistication of the hacker.

South Korean authorities have not yet disclosed exactly which artificial intelligence systems were used or how much of the attacks they performed.

That distinction matters. There is no evidence that an autonomous AI independently chose a bank and hacked it without human direction.

But AI does not have to become an autonomous hacker to change cybercrime.

It only has to make human hackers faster.

What Happened To South Korea’s Banks?

South Korea’s Financial Services Commission began an emergency response after a data leak involving Shinhan Bank on 30 September was followed by attacks affecting KB Kookmin Bank and other financial companies.

Several major institutions have been caught up in the wider series of incidents, with personal information belonging to customers exposed in some cases.

The regulator ordered financial institutions to inspect internet-facing systems, strengthen authentication and access controls, block unnecessary exposure of information and increase the sharing of suspicious internet addresses and other threat data.

President Lee then escalated the issue on 6 October.

He said signs had emerged that AI was being used in some hacking incidents and called for a rapid investigation alongside cybersecurity measures designed for what he described as the AI era.

Police are investigating.

The technical details that matter most have not yet been made public. Authorities still need to establish exactly what role artificial intelligence played, whether the same attackers were responsible for multiple incidents and whether AI materially enabled breaches that would otherwise have been more difficult.

How Could AI Help Someone Hack A Bank?

The popular image of AI hacking is a machine breaking into a network by itself.

The more realistic threat is less dramatic but potentially more useful to criminals.

Cyberattacks involve large amounts of repetitive technical work.

An attacker may need to search for exposed services, study software, identify known vulnerabilities, analyse error messages, write scripts, examine stolen information and adjust an attack when the first method fails.

Artificial intelligence can accelerate many of those tasks.

A capable model can analyse pieces of code, explain technical errors, summarise documentation and help produce or modify scripts.

That can reduce the time required to perform work that previously demanded more manual effort.

As explained in how AI is changing cybersecurity for hackers and defenders, the immediate danger is not necessarily that artificial intelligence invents an entirely new form of cyberattack.

The bigger change may be that it makes familiar techniques cheaper, faster and easier to repeat.

That is where scale becomes important.

AI Does Not Need To Become An Autonomous Hacker

Imagine an attacker trying to compromise an exposed computer system.

A human can still decide what the target is and what they want to achieve.

AI can then help analyse the system, identify possible weaknesses, explain unexpected responses and generate code for the attacker to test.

The person remains in control.

More advanced AI agents could potentially perform longer sequences of actions with less human intervention, but that is different from claiming the machine independently planned an entire cyberattack.

This distinction is essential when assessing the South Korean incidents.

The evidence currently supports possible AI-assisted hacking, not the arrival of a fully autonomous digital criminal.

Yet AI assistance alone could be consequential.

If technology allows one skilled attacker to perform work that once required several people, or allows a less experienced attacker to accomplish tasks previously beyond their ability, the number of credible threats increases.

Why Banks Are Such Valuable Targets

Banks hold something cybercriminals value almost as much as money: identity.

Names, telephone numbers, account information and other personal details can be useful long after an attacker has left the original system.

Stolen information can make phishing attempts more convincing.

A criminal who already knows which organisation someone uses can construct a message that appears more credible than a generic scam.

The same information can potentially be combined with data stolen elsewhere to build a more detailed profile of a victim.

South Korean authorities have warned that exposed personal information could be used for voice-phishing and text-message scams.

That means the damage from a breach does not necessarily end when a vulnerability is closed.

The stolen information can continue circulating.

Banks therefore have to defend two fronts at once: the original intrusion and the fraud that may follow it.

The Bigger AI Cyber Threat Is Scale

Cybersecurity has always contained a fundamental imbalance.

A defender may need to protect thousands of employees, accounts, servers, applications, suppliers and connections.

An attacker may need to find one vulnerable route inside.

Artificial intelligence could widen that imbalance if it allows attackers to inspect more potential targets in less time.

A vulnerability that once required hours of research might be analysed more quickly.

Scripts can be adapted faster.

Technical documentation can be searched and interpreted almost instantly.

Reconnaissance can become more automated.

An attacker does not need AI to be perfect.

They need it to save time often enough to increase the number of attacks they can attempt.

That is why the history of cyber warfare is increasingly becoming a story about automation and AI.

The danger comes from volume as much as intelligence.

Banks Can Use AI Too

The same technology is available to defenders.

Financial institutions can use artificial intelligence to analyse security logs, detect unusual behaviour, identify suspicious transactions and prioritise vulnerabilities.

A defensive system capable of examining millions of events could identify patterns that would be difficult for a human team to spot manually.

AI can also help security specialists examine code, investigate alerts and decide which vulnerabilities require immediate attention.

The result is not a simple story in which attackers gain AI and banks do not.

It is an arms race.

Attackers can use automation to search for weaknesses.

Defenders can use automation to detect them.

The question is which side turns the technology into reliable action faster.

The Defender Has A Different Problem

Attackers and banks do not operate under the same conditions.

An attacker can take risks.

A bank cannot simply shut down a payment system because an algorithm says something looks suspicious.

Banks have customers, regulators, old software, external suppliers and services that must continue operating.

That makes defensive automation more complicated.

A security system might identify an unusual account, for example, but disabling it automatically could interrupt an important business process.

Someone still has to understand what the system does and what the consequences of blocking it might be.

This is one reason AI does not eliminate the need for experienced cybersecurity teams.

Speed matters.

Judgement still matters too.

AI Systems Can Also Become A Security Weakness

There is another side to the problem.

As financial institutions adopt artificial intelligence themselves, those systems can create new routes to sensitive information.

An AI assistant connected to company email, internal documents, customer records or software tools becomes part of the organisation’s security perimeter.

Its permissions matter.

Its connections matter.

The information supplied to it matters.

An organisation that uses AI carelessly can expose itself even without an outside hacker defeating traditional security.

That risk has already appeared elsewhere when sensitive information has been placed into public AI systems, a problem examined in the security dangers created when confidential material is uploaded to public AI tools.

Banks therefore face an uncomfortable balance.

They need AI to help defend increasingly complex networks while ensuring those same systems do not create additional weaknesses.

South Korea Was Already Preparing For This

The latest attacks have arrived while South Korea is expanding its broader use of artificial intelligence.

That makes the investigation particularly significant.

The country is simultaneously trying to become more advanced in AI development while dealing with the security consequences that more capable systems can create.

Financial regulators have already been pushing institutions to strengthen cybersecurity and develop more advanced defensive tools.

The recent incidents could accelerate that work.

If investigators eventually establish that AI played a substantial role in these attacks, banks may have to rethink how quickly threats can develop.

Traditional security processes built around human-speed attacks could struggle when parts of reconnaissance, vulnerability analysis and exploitation become automated.

What Investigators Still Need To Discover

The unanswered technical questions will determine how important the South Korean case becomes.

Investigators need to establish what artificial intelligence actually did.

Did it help write code?

Did it scan systems for vulnerabilities?

Did it analyse the responses from targeted servers?

Did it automate reconnaissance?

Did an AI agent interact directly with banking systems?

Did humans approve every important step?

And was the AI genuinely necessary to the attacks, or simply another tool used during an otherwise conventional intrusion?

Those differences matter.

Calling every incident involving an AI tool an “AI cyberattack” would risk exaggerating what happened.

But ignoring the role of artificial intelligence simply because a human was still involved would miss the larger technological shift.

Cybercrime has rarely depended on one revolutionary invention.

It evolves as attackers gain tools that remove friction from existing methods.

AI could remove a great deal of friction.

The Race Between Attack And Defence

Every major technological change in cybersecurity alters the balance between attackers and defenders.

Automation made large-scale scanning easier.

Cheap computing increased the volume of attacks.

Cryptocurrency transformed ransomware economics.

Large databases of stolen information made targeted fraud easier.

Artificial intelligence may become the next acceleration.

It can lower the cost of technical analysis, help people understand unfamiliar software and allow repetitive digital tasks to be performed at machine speed.

More powerful systems could eventually connect many of those capabilities together.

That possibility is why warnings about increasingly capable AI cyber systems matter far beyond the technology industry.

Banks, hospitals, governments, energy companies and transport networks all depend on software.

An attacker does not need to defeat every defence protecting those systems.

They need to find the weakness that was missed.

AI may help them search faster.

The South Korean investigation has not yet established exactly how far that capability has advanced.

What it has done is move the question from theory towards a real financial-sector investigation.

If AI played only a minor role, the incidents will still offer cybersecurity teams useful evidence about how attackers are adopting new tools.

If it played a substantial role, the implications are larger.

Banks may be approaching a world where

Previous
Previous

McDonald’s Sued Over Alleged AI Price-Fixing As Big Mac Pricing System Faces Antitrust Test

Next
Next

OpenAI Is Watermarking ChatGPT Text In The EU — Here’s What It Means For Ordinary People