The South Korean government has called for a complete overhaul of hacker defenses after cyber attacks compromised the systems of seven of the country’s major financial institutions last week, leaking private data belonging to thousands of customers.
The breaches extend beyond the financial sector. Two of the nation’s largest churches and Korea Electric Power Corp. confirmed on Wednesday that their online systems had been unlawfully accessed, though it remains unclear whether one perpetrator was responsible for every attack.
On Tuesday, Prime Minister Han Seong-sook demanded swift action to stop further leaks.
“This is a serious situation because this incident is believed to have taken advantage of artificial intelligence, and if AI is used in phishing attacks, it could lead to secondary damage,” Yonhap News quoted Han as saying at a Cabinet meeting.
“It is also a serious situation in that similar hacking methods could spread beyond the financial sector to industries, as well as government and public sectors.”
Cyberattacks: How secure are smart devices really?
To view this video please enable JavaScript, and consider upgrading to a web browser that supports HTML5 video
Threats to other sectors
Han stated that government agencies, public institutions, the financial sector, and private enterprises all need to remain vigilant.
Early reports from the US-based cybersecurity firm CrowdStrike suggested the attack may have originated in China, although South Korea’s Financial Supervisory Service (FSS) identified 28 IP addresses in the United States, Japan, Germany, and at least 10 other countries involved in the bank breaches.
“South Korea officials are being careful about how they are framing their findings,” said Aditya Das, an analyst at cryptocurrency research firm Brave New Coin in Auckland, New Zealand.
In the bank logs, investigators found traces of a tool called ARTEX, an open-source “autonomous penetration-testing” agent built by a Chinese developer.
“It is freely available on the internet and officials have said explicitly that a Chinese-built tool doesn’t mean Chinese attackers,” Das told DW, adding that the use of multiple IP addresses is likely “a ploy by the hackers to hide their tracks.”
It appears the hackers exploited weak authentication protocols in portals used by external loan recruiters, employees’ mobile tools, and sales-support systems.
How much are hackers making?
To view this video please enable JavaScript, and consider upgrading to a web browser that supports HTML5 video
Data on thousands of customers lost
South Korean media reported up to 68,000 customers affected, with Shinhan Bank, KB Kookmin Bank, and Hana Bank among the worst hit. Accessible data included names, phone numbers, annual income figures, loan limits and products, along with a small number of national identification numbers.
Das noted that with a person’s name, phone number, income figure, and knowledge of a recent loan application, a fake “bank security” call can be very convincing. Once a victim transfers funds to an account specified by the scammer, recovery is very difficult.
Hyobin Lee, a professor at Seoul’s Sogang University, says the seriousness of the incident goes far beyond simple exposure of personal information.
“If criminals obtain such information, they may be able to carry out sophisticated financial fraud, identity theft, or highly targeted phishing attacks,” she said.
“Another concern is that stolen personal information can be reused or combined with other leaked databases, potentially creating security risks that persist long after the original attack,” Lee underlined.
“More broadly, such incidents can undermine public confidence in financial institutions and raise concerns about the security of the financial system as a whole.”
While major financial institutions have invested heavily in protecting core systems like internet and mobile banking, Lee said they overlooked other network elements.
“Some auxiliary systems, such as loan agent information portals and internal mobile applications used by employees, appear to have received less security attention,” she said, adding that the application of AI by the hackers is another concerning element.
Is AI the new weapon of mass data theft?
To view this video please enable JavaScript, and consider upgrading to a web browser that supports HTML5 video
AI makes hacking easier?
“In the past, identifying security vulnerabilities, developing malicious code and conducting attacks against financial institutions required substantial technical expertise and considerable time,” Lee pointed out. “Today, generative AI tools can assist with writing computer code, analyzing software vulnerabilities, processing large amounts of information and automating certain stages of cyber operations.”
AI is “lowering the technical barriers to cybercrime” and making it accessible to more bad actors, while ramping up the speed and scale of attacks to overwhelm defenses.
Lee fears AI-assisted cyberattacks will only become more frequent given those developments.
“And the risks will not be limited to financial institutions,” she said. “Hospitals, government agencies, energy infrastructure, telecommunications networks and other organizations holding sensitive information may also become increasingly attractive targets.”
Edited by: Srinivas Mazumdaru
Also Read
- Russian Opposition Leader Kara-Murza Warns France’s Sanctions U-Turn Emboldens Putin’s War
- Trump Demands Debate Between Paxton and Talarico as Texas Senate Race Boils Over
- Investigative Report Questions UAE Naturalization of Uzbek Presidential Security Deputy
- Social Media Rallies Behind #IAmJaneDoe Campaign Supporting Alleged Cornell Sexual Assault Victim

