Drooid Logo
Back to story perspectives

Full Breakdown

AI-Assisted Hacking Wave Hits South Korea’s Financial Sector

By Drooid · · How we work

Core Event: Coordinated AI-Powered Breaches at Major Banks

In early October 2026, seven South Korean financial institutions suffered simultaneous cyber intrusions that exposed personal data for roughly 68,000 customers. The attacks targeted auxiliary business services—loan-agent portals, employee mobile tools and sales-support systems—rather than core internet-banking platforms. Investigators found traces of the open-source ART EX tool, an AI-driven autonomous penetration-testing framework, in server logs. Compromised records included names, phone numbers, annual income, loan limits and, in a few cases, resident registration numbers.

Background & Context

The incidents follow a global rise in generative-AI applications that can automate code generation, vulnerability scanning and attack-path planning. Early reports from CrowdStrike linked the campaign to a Chinese-developed tool, but South Korean officials emphasized that tool provenance does not prove the attackers’ nationality. Analysts note that AI lowers the technical expertise required for sophisticated cyber-crime, enabling large-scale, rapid attacks.

Data & Statistics

Official Statements & Responses

  • Prime Minister Han Seong-sook warned that AI-assisted phishing could cause secondary harm and called for immediate safeguards across government agencies, public institutions and private enterprises.
  • The FSC convened an emergency meeting on Oct 4, directing all financial firms to block non-essential external access and to operate at the highest security alert level.
  • The Korean National Police Agency opened a criminal investigation under the Act on Promotion of Information and Communications Network Utilization and Information Protection.

Conflicting Reports & Gaps

  • Media outlets initially cited 68,000 compromised records, while the sum of institution-specific disclosures (? 65,000) falls slightly short, indicating incomplete aggregation.
  • CrowdStrike’s analysis suggested a Chinese-origin tool and a possible Guangdong-based suspect, yet authorities stress that tool provenance does not equate to attacker nationality and have not confirmed any individual’s identity.
  • No confirmed theft of payment credentials or other data enabling immediate financial fraud has been disclosed.

What’s Next

The police investigation continues, focusing on the technical methods and cross-jurisdictional infrastructure used by the attackers. The FSC has mandated emergency security inspections to be completed by Oct 8 and is drafting an “AI-responding-to-AI” strategy that includes expanded AI-driven testing, anomaly detection and incident-response automation. Regulators are also reviewing network-segmentation rules and considering a shift toward zero-trust architectures for both commercial banks and public-sector entities.