AI agents are now suspected of orchestrating cyberattacks against major South Korean financial institutions, raising urgent questions about the security of banking infrastructure. This incident marks a shift in threat landscape where automated tools enable breaches without requiring deep technical expertise from the attackers. Financial customers face direct risks as personal data is exposed through these automated exploits.
Automated tools enable breaches without specialized skills
The attacks targeted three major banks: Hana Bank, KB Kookmin Bank, and Shinhan Bank. The breaches resulted in significant data leaks, with approximately 25,000 Shinhan Bank customers having their personal credit information compromised. KB Kookmin Bank reported that 99 customers and 20 employees were affected, while 89 Hana Bank customers had information stolen.
South Korean President Lee Jae Myung confirmed during a livestreamed cabinet meeting that AI models enabled the hacks. He stated that it is now possible to use AI to hack with ease even without specialized skills. The President instructed the cabinet to minimize damage from the ongoing security crisis.
Attribution of the cyberattacks to a specific state-sponsored group remains unclear. Speculation focuses on regional adversaries, but tracing and attributing the hacks is difficult. This incident follows previous reports of AI-orchestrated attacks in November 2025 and autonomous cyberattacks on Taiwan.
The confirmed facts establish that AI agents were the primary tool for these financial breaches. The scale of data exposure and the ease of use for attackers highlight a new vulnerability in banking security. The government is now focused on damage control while the investigation into the perpetrators continues.



Discussion
0 comments
Log in to join the thread with a thoughtful take, question, or correction.