South Korea warned on Tuesday that last week’s breach of seven major financial institutions may have been driven by AI-assisted hacking, after private data tied to thousands of customers was leaked. Han Seong-sook called for measures to be taken swiftly to halt any further leaks, saying the case could be a warning for more than just the banking sector.
Her warning landed because the damage was already widening. South Korean media reports said as many as 68,000 customers may have had data taken, and Shinhan Bank, KB Kookmin Bank and Hana Bank were among the worst affected. Names, phone numbers, annual income figures, loan limits and loan products were accessed, and a small number of national identification numbers were also exposed.
Han said the incident is believed to have taken advantage of artificial intelligence and that similar hacking methods could spread beyond finance into industries, government and public sectors. She urged those affected to remain vigilant. That concern has weight because two of the largest churches in South Korea and Korea Electric Power Corp. also said on Wednesday that their online systems had been illegally accessed, raising the possibility that the breach pattern was not confined to banks alone.
Investigators have found traces of ARTEX in the bank logs, a tool described as an open-source autonomous penetration-testing agent built by a Chinese developer and freely available online. Aditya Das said that a Chinese-built tool does not by itself prove Chinese attackers were behind the breach, and that it could also be a way for hackers to hide their tracks. CrowdStrike suggested the attack may have originated in China, while the Financial Supervisory Service said it had identified 28 internet protocol addresses in the United States, Japan, Germany and at least 10 other countries tied to the bank breaches.
That spread of digital traces is what makes the case hard to pin down and harder to contain. The known facts point to a breach that used weak authentication protocols in portals used by external loan recruiters, employees’ mobile tools and sales-support systems, which would have opened more than one route in and out of the network. Hyobin Lee of Sogang University in Seoul said the name behind the tool matters less than the way it was used: the question now is whether the safeguards around banking data, and the broader systems connected to it, can be tightened before the same method is repeated elsewhere.

