South Korea investigates series of AI attacks on banks

South Korea investigates series of AI attacks on banks
Photo: Financial Supervisory Service building in Korea / illustrative

In South Korea, the financial regulator and police are investigating a series of cyberattacks on major banks and other financial companies, during which AI agents may have been used. The attacks resulted in personal customer data leaks at several institutions.

The Financial Supervisory Service (FSS) of South Korea identified 28 IP addresses in 12 countries that may have been used during the attacks as of October 6, reports Yonhap. The regulator passed these addresses to financial companies for verification and blocking.

One of the largest confirmed losses was the leak of data of approximately 25,000 Shinhan Bank customers. The compromised information included names, phone numbers and data on annual incomes. Yonhap sources claim that during the attack hackers used modern AI tools.

Hana Bank confirmed a leak of personal data of 89 customers. Woori Bank and NH Nonghyup Bank also recorded attempts at unauthorized access, but their protection systems blocked the attacks, and no information leaks have been detected there so far.

Overall, customer information leaks were identified in seven financial companies, including Hana Bank, KB Kookmin Bank and Shinhan Bank. President of South Korea Lee Jae-myung said that in some episodes there were signs of possible use of artificial intelligence, and instructed the government to establish the circumstances of the attacks as quickly as possible and allocate necessary resources to minimize damage.

Law enforcement agencies created a separate investigation team of 28 people. Police are checking possible violations of the information and communication network legislation and deciding whether to transfer the case to the new Serious Crimes Investigation Agency, which has jurisdiction over attacks on electronic financial infrastructure.

At the same time, final attribution of the attacks is not yet available. The identified IP addresses are located in different countries and could have been used to conceal the real location of the attackers. The authorities are also talking about the probable use of AI agents, rather than a definitively proven mechanism of all attacks.

After the incidents, Prime Minister of South Korea Han Duck-soo called for a large-scale review of the financial sector's information security system. According to her, the possible use of AI makes the situation especially dangerous due to the risk of further phishing attacks on customers whose data is already in the hands of malicious actors.