What happened

The wave started with Shinhan Bank, which reported a breach that compromised personal credit data — names, phone numbers, annual income, loan limit details, and in some cases resident registration numbers — for about 25,000 customers. KB Kookmin Bank, Hana Bank, and Woori Bank then reported their own intrusions. The breaches spread beyond commercial banks: Yegaram Savings Bank reported roughly 40,000 customers affected, and Hyundai Capital said personal data for 146 housing-loan agents was exposed. No payment credentials have leaked, and no unauthorized transactions have been found, but regulators warn the stolen records could fuel secondary fraud like voice phishing.

On Sunday, Financial Services Commission Chairman Lee Eog-weon pulled forward an emergency meeting with bank executives and regulators. President Lee Jae Myung followed on Tuesday, saying "signs have emerged of AI being used" in some incidents and ordering officials to establish the facts quickly. Police opened a full-scale investigation. The financial watchdog shared 28 IP addresses linked to the attempts with the sector, and investigators say they cannot rule out a single perpetrator scanning multiple firms for weaknesses.

The claim, read carefully

"Signs have emerged of AI being used" is a sentence doing two jobs. It tells the public the threat is new and serious, and it commits to no specifics. Reuters, Yonhap, and the FSC have all declined to say what AI tools were used or in what capacity. AI-assisted hacking could mean anything from an attacker using a chatbot to write phishing emails to an autonomous agent conducting the intrusion. Those are very different claims with very different implications, and nobody with access to the forensic evidence has said which one applies.

The one concrete lead comes from security researchers, not the government. They found a Chinese-language string translated as "AI autonomous penetration testing console" in the HTML title of infrastructure believed to be linked to the intrusion. The string is associated with ARTEX AI, an open-source LLM-based penetration testing framework. A framework designed to help testers probe networks could plausibly have been pointed at banks. It is also exactly the kind of string an attacker can leave behind by accident, and a penetration-testing tool in the loop does not establish that AI did the hacking, or that the hacks would not have happened without it.

The opposition People Power Party has urged investigators to consider North Korean involvement. Investigators have said the attack traffic came from the US, Japan, Singapore, Vietnam, and Britain. Attribution is early everywhere.

The part that matters

The FSC chairman's response deserves a closer look than the president's rhetoric. He called for an "AI attacks defended by AI" approach — faster development of security systems capable of countering AI-powered threats. That is a procurement direction disguised as a strategy: before anyone knows what the attacks were, the answer is already to buy AI defense. It may prove to be the right answer. It is not, at this point, an evidence-based one.

There is a pattern forming across this year's AI incidents. In Australia, OpenAI's agents breached government portals, and the country learned about it months later. Now South Korea's banks are breached, and the government announces the breaches involved AI before saying what that means. In both cases the verifiable facts are about security hygiene — unpatched portals, unprotected data stores — while the AI framing arrives first and loudest. AI changes the speed of attacks. It does not explain the breaches.

Sources

  1. [1] Reuters, via Northland News Radio — “South Korea's Lee says AI appears to have been used in bank hacks” (Oct 6, 2026)Read source
  2. [2] Reuters, via BusinessWorld — “South Korea's Lee says AI appears to have been used in bank hacks” (Oct 6, 2026)Read source
  3. [3] GBHackers — “South Korea Orders Investigation Into AI-Powered Cyberattacks on Major Banks” (Oct 5, 2026)Read source
  4. [4] Zubiqo — “South Korea Probes AI Agent Involvement in Major Bank Hacks” (Oct 6, 2026)Read source