← All posts / Policy

A President, Seven Banks, and a Suspected AI Attacker: South Korea Investigates Its Financial Sector's Worst Hacking Wave

South Korea's president told his cabinet that 'signs have emerged' of AI being used in a breach wave that hit seven financial institutions and exposed up to 68,000 people — the first time a national government has publicly flagged AI-assisted hacking against its own banking system as an open investigation.

A President, Seven Banks, and a Suspected AI Attacker: South Korea Investigates Its Financial Sector's Worst Hacking Wave

At a cabinet meeting on October 6, 2026, South Korean President Lee Jae Myung said something no head of state had said before: “In some hacking incidents, signs have emerged of AI being used, causing considerable public concern and anxiety.” The target set was his own country’s financial system. Since late September, at least seven South Korean financial institutions — including the country’s five largest commercial banks — have disclosed personal-data breaches, and investigators are now examining whether an AI-driven attack framework automated the campaign. Combined exposure is estimated at roughly 65,000 to 68,000 people, depending on the outlet.

That is the number. The signal is bigger. This is the first time a national government has publicly opened an investigation into suspected AI-assisted hacking against its banking sector — with a sitting president commenting directly on the AI angle while forensics are still running.

The timeline: how the wave unfolded

The breaches surfaced one by one, which is part of why they took days to connect. The first confirmed incident hit Yegaram Savings Bank around September 30, exposing an estimated 40,000 records containing names, dates of birth, and contact details. Within days, the five major commercial banks — KB Kookmin, Shinhan, Hana, Woori, and NH Nonghyup — were pulled into the same investigation after security teams found overlapping attack signatures. BNK Busan Bank was also named in connection with the probe.

By October 4–5, Shinhan Bank had disclosed exposure of roughly 25,000 customer records, while KB Kookmin and Hana reported smaller breaches affecting 119 and 89 customers respectively. Hyundai Capital, which disclosed a separate breach affecting 146 loan agents earlier in the year, was named in some reporting tied to the broader wave.

The combined totals vary by outlet — Firstpost, citing Wall Street Journal reporting, puts the figure at roughly 68,000 people, while domestic accounts cited more than 65,000 records. That discrepancy is itself diagnostic: banks are still reconciling logs, and the number will almost certainly move again before the investigation closes.

The suspect: an open-source AI attack framework

Several reports, including an analysis from cybersecurity firm Rescana, name an open-source framework called ARTEX AI as the tool investigators are examining. Rescana describes ARTEX AI as a large-language-model-based penetration-testing system capable of independently running reconnaissance, identifying vulnerable login endpoints, launching credential-stuffing or brute-force attempts, and verifying whether an attack succeeded — all with limited ongoing human direction.

That description matters more than any single data point, because it describes a shift in attacker economics rather than a new vulnerability class. The banks were not necessarily broken into through a novel software flaw. Investigators suspect the attackers used AI to compress the time and manual labor it normally takes a human red team or criminal crew to scan, probe, and exploit login systems at scale.

Supporting evidence comes from the infrastructure itself: investigators found that the same attacker IP address surfaced across multiple breach sites even as the broader campaign rotated through changing IP addresses over time — a pattern consistent with automated, distributed tooling rather than a single manual operator working one target at a time.

WSJ reporting went further, describing the suspected tool as a Chinese AI agent used to steal the personal information of 68,000 people. South Korean officials, notably, have not confirmed attribution and have repeatedly used hedged language — “signs have emerged,” “cannot rule out” — rather than declarative claims. That caution is appropriate: AI tool fingerprints are genuinely hard to distinguish from skilled human automation using conventional scripts.

What officials are actually saying

President Lee has been the most visible voice on the investigation. Beyond his cabinet remarks, he instructed officials to “establish the circumstances swiftly and clearly, and concentrate personnel and resources on minimising the damage.” The Record quoted him saying “signs have emerged suggesting AI agents were deployed in at least some of the attacks,” and — the line that will be quoted in policy circles for years — that “it’s now become possible to use AI to hack with ease even without specialized skills.”

Financial Services Commission Chairman Lee Eog-weon struck a more cautious tone: “we cannot rule out the possibility of hacking attacks utilizing AI.” The National Police Agency’s cyber bureau opened a probe into the attack routes and responsible parties, while the Financial Services Commission ordered emergency security inspections across the entire banking sector. Separately, emergency cyber protocols were activated across 28,000 firms.

Why this is different from a routine bank breach

South Korea logs plenty of financial-sector breaches in any given year, most tied to phishing, stolen credentials, or third-party vendor compromise. What separates this case is the suspected autonomous layer sitting behind the intrusions: an LLM-driven tool running the attack chain — scan, probe, attack, verify, adjust — with minimal human steering.

Security researchers have spent two years warning that agentic AI would eventually be used offensively at scale. This investigation is one of the first times a government has said, in public, that it believes that moment may have already arrived inside its own banking system. Every individual technique involved — credential stuffing, login endpoint scanning, IP rotation — is old. What’s new is the claim that an AI system chained them together with less manual oversight than a typical criminal operation needs. If that holds up, it lowers the skill floor for running a credible attack campaign against a national banking sector.

What happens next

The operational lessons are already actionable regardless of how attribution resolves. Login endpoints need rate-limiting and anomaly detection tuned for machine-paced probing, not just human-paced brute force. Credential-stuffing defenses built on the assumption that attackers need breaks, sleep, or shift changes are outdated. Regulators in Japan, Singapore, and the EU will almost certainly cite this case when justifying new AI-risk disclosure rules for banks.

Expect the exposure total to be revised upward as more institutions complete log reviews. Expect South Korea’s Personal Information Protection Commission to open formal proceedings. Expect attribution to remain officially unconfirmed for weeks even as media reporting continues pointing toward a Chinese-linked tool — and expect this investigation to become the canonical case study in every “AI-powered cyberattack” briefing for the rest of the decade.

The bottleneck in cyberattacks used to be skilled human attention. In October 2026, a sitting president told his cabinet that bottleneck is eroding — in his own banks.