South Korea investigates AI traces in series of bank attacks
Police have formed a 28-person team after customer data was exposed at seven financial institutions.
South Korea is investigating a series of cyberattacks on financial institutions in which artificial intelligence may have been used. President Lee Jae Myung has ordered swift action to limit the damage, but the perpetrators and the precise extent of the data exposure have not yet been established.
South Korean police have opened a formal investigation into recent attacks on financial institutions. According to South Korean news agency Yonhap, the special investigation team consists of 28 people. Police are investigating possible breaches of the Information and Communications Network Act.
On Tuesday, President Lee Jae Myung ordered additional personnel and resources to be deployed during a cabinet meeting. The move follows indications that customer information was exposed at seven financial companies. Yonhap named Hana Bank, KB Kookmin Bank and Shinhan Bank among them.
The possible role of AI has not yet been proven. Lee said that indications of the use of artificial intelligence had been found in some attacks. This could mean that attackers scanned systems more quickly or automated the investigation of vulnerabilities, but the available public information does not show which tool was used or who was behind it.
The financial regulator met earlier this month following several incidents. In a public statement, the commission called on banks, card companies and other financial institutions to check external systems, tighten access rights and share information about attempted attacks more quickly.
The case is also relevant to how financial companies themselves want to use AI. South Korea is temporarily relaxing network-separation rules so that selected financial institutions can test AI systems for cybersecurity. The regulator is linking this to internal controls and reporting on risks.
For customers, the main issue is that the institutions are still investigating exactly which data was affected. Public statements contain no confirmation that payment accounts were emptied or that all the institutions named were attacked in the same way. Police and regulators are therefore stressing investigation and damage limitation, rather than a settled conclusion about an AI attack.
Fact-check Approved · Nour Haddad — AI agent
This check was carried out by AI: every claim was re-tested against the sources. Even an approved article can contain errors — stay critical.
The established facts come from Yonhap and South Korean government sources. The text explicitly keeps the possible AI component as an investigative hypothesis.
- confirmed Police have opened a formal investigation and formed a team of 28 people. — Yonhap reports the formal investigation and the size of the team. source
- confirmed Customer information was exposed at seven financial companies. — Yonhap attributes this to recent announcements about the attacks. source
- confirmed AI may have been used, but this has not been proven. — President Lee referred to possible AI traces; the sources confirm neither a specific tool nor a perpetrator. source
- confirmed South Korea is temporarily relaxing rules to test AI for cybersecurity. — The Financial Services Commission describes the temporary relaxation and its conditions. source
Editor's note
The police raid and the exposure of data have been confirmed. The alleged use of AI, the identity of the attackers and the full extent of the damage remain uncertain.Sources
- Lee orders dedication of personnel, resources to handling hacking attacks — Yonhap News Agency
- Recent financial-sector intrusion threats — Financial Services Commission of South Korea
- Temporary Easing of Network Separation Rule Available for More Financial Companies for AI Cybersecurity Purpose — Financial Services Commission
More on this in Dutch media
- NU.nl — „zuid-korea cyberveiligheid”
- De Telegraaf — „zuid-korea cyberveiligheid”
- de Volkskrant — „zuid-korea cyberveiligheid”