Skip to main content

South Korea Orders Probe as AI-Linked Hacks Hit Seven Banks

South Korean President Lee Jae Myung ordered a thorough investigation after data breaches at seven banks, telling the cabinet that signs had emerged of AI being used in the attacks. Financial authorities suspect a single culprit. The order follows suspected AI-driven intrusions at five major commercial banks earlier in the week, three of which reported customer information leaks.

On this page

A presidential order after seven banks

South Korean President Lee Jae Myung has ordered a thorough investigation and full security checks after data breaches spread across the country's banking sector, telling a cabinet meeting that "signs have emerged of AI being used" in the hacking incidents and that the scale of public concern demanded a government response. Seven banks have now been drawn into the investigation, and financial authorities believe a single culprit is responsible for the attacks.

The breaches escalated quickly. Earlier in the week, five major commercial banks were reported hit by suspected AI-driven cyberattacks, with three of them disclosing leaks of customer information. By the time the president convened his cabinet, the count had grown to seven institutions and the case had moved from an industry security problem to a matter of state attention.

Where the AI came in

Officials have not published the technical detail of how AI figured in the intrusions, and the cabinet statement stays at the level of signs rather than attribution. What makes the case notable is the position it occupies in a short line of incidents where AI tools appear on the attacker's side: from agentic ransomware that deletes cloud storage in minutes, to models used to draft phishing at scale, to the disguise of automated traffic as ordinary research. A national banking sector being probed specifically for AI-assisted intrusion is the clearest sign yet that this is a policy category, not a research curiosity.

It also matters that the suspicion is about tooling rather than a model vendor's failure. Nothing in the reporting suggests a frontier lab's product misbehaved; the concern is that ordinary AI capabilities lowered the cost and raised the quality of an intrusion campaign against seven targets at once. That is the scenario defenders have been gaming for two years, and it now has a presidential investigation attached to it.

The response so far

The investigation's mandate covers both what happened and what happens next: Lee instructed officials to identify the culprit, assess the damage, and formulate countermeasures, with the presidential office citing serious public anxiety about financial data. The disclosure picture remains incomplete; three of the first five banks reported customer information leaks, and the full set of seven institutions has not been comprehensively profiled in public.

For anyone running AI systems against financial infrastructure, on either side of the security line, the Korean case is the latest evidence that the question has moved from whether AI changes attacker economics to how regulators respond when it demonstrably does. The parallel is visible in the notifications the United States has required after its own agent incidents, and in Australia's push for dual notification duties. Seoul's probe will be watched for whether it produces the first detailed public anatomy of an AI-assisted bank intrusion campaign, and for whether countermeasures become mandatory controls rather than guidance.

CuriousLM runs supported AI models locally on your device. Try CuriousLM.