South Korea warns of AI-aided hacking after bank data breaches — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- South Korea's Prime Minister Han Seong-sook demanded a comprehensive overhaul of cyber safeguards at a Cabinet meeting, warning that AI-assisted phishing could trigger secondary damage and that similar methods could spread to industries, government, and public sectors beyond finance.
- Seven major financial institutions were breached last week, with Shinhan Bank, KB Kookmin Bank, and Hana Bank among the worst hit, exposing data on as many as 68,000 customers including names, phone numbers, annual income, loan limits, and a small number of national identification numbers.
- Korea Electric Power Corp. and two of the country's largest churches confirmed Wednesday that their online systems were illegally accessed, though South Korean officials have not yet determined whether the same perpetrator is responsible for attacks across sectors.
- The Financial Supervisory Service identified 28 IP addresses across the US, Japan, Germany, and at least 10 other countries involved in the bank breaches, while investigators found traces of ARTEX, a Chinese-built open-source penetration-testing tool — though officials stressed a Chinese-built tool does not mean Chinese attackers, per Brave New Coin analyst Aditya Das.
- Hackers exploited weak authentication in external loan recruiter portals, employees' mobile tools, and sales-support systems, according to Sogang University professor Hyobin Lee, who said core internet and mobile banking platforms received heavy investment while auxiliary systems were overlooked.
- Generative AI is lowering the technical barriers to cybercrime by assisting with code writing, vulnerability analysis, and automation, Lee warned, enabling faster, larger-scale attacks against hospitals, energy infrastructure, telecommunications, and government agencies holding sensitive data.
- US-based CrowdStrike's early findings suggest the attack may have originated in China, though Das said the use of multiple international IP addresses is likely a ploy to obscure the hackers' true location.
Why it matters: The breach shows that South Korea's heavily defended core banking systems were not the weak link — auxiliary portals and mobile tools for loan agents and employees were — and that the leaked data (income, loan status, ID numbers) is purpose-built for convincing fake-bank fraud calls. With 68,000 customers' records circulating and at least one utility plus two megachurches now reporting intrusions, the incident is already pressuring regulators to force financial institutions to extend enterprise-grade security to every networked tool, not just customer-facing ones.
Ask SkimNews



