What happened
South Korean President Lee Jae Myung has ordered a thorough investigation into a wave of personal data leaks at banks, finance companies, and public agencies, the presidential office said Sunday. Regulators responded the same day: Financial Services Commission (FSC) Chairman Lee Eog-weon convened an emergency meeting with industry associations, regulators, and executives from the affected institutions, warning the sector to respond with “the highest level of vigilance.”
Why it matters: the country’s top financial regulator now says AI may be behind the attacks — and is calling for an “AI attacks defended by AI” approach to fighting them.
What we know about the attacks
On-site investigations began after Shinhan Bank reported a breach on September 30, and regulators have since expanded probes into other reported incidents. KB Kookmin Bank and others reported cyberattacks at the end of last week, while Yonhap news agency reported that Hana Bank and Woori Bank also suffered breaches.
Yonhap, citing bank data submitted to lawmakers, reports that the attacks may have broadly scanned multiple financial companies for vulnerabilities rather than targeting a single institution — with attack traffic originating from IP addresses across the United States, Japan, Singapore, Vietnam, and Britain. Sunday’s emergency meeting was brought forward from October 7 after additional breaches were discovered at second-tier financial institutions, according to Korean media reports.
The regulator directed financial institutions to carry out comprehensive security inspections, tighten access controls, minimize external system access, and strengthen consumer protection measures — and to rapidly share attack methods, IP addresses, and other threat information across the industry.
Why it matters
This is a regulator explicitly naming AI as a suspect in real-world attacks on real banks — not a lab scenario. When the head of a national financial regulator says authorities “could not rule out the possibility that artificial intelligence was used in the attacks,” it marks a shift in how governments talk about cyber threats: AI isn’t just a tool attackers might use someday, it’s a line of inquiry in an active, ongoing investigation. The FSC’s answer — “AI attacks defended by AI” — also signals where bank security budgets are headed: more machine-speed defensive tooling, broader industry threat-sharing, and tougher audits of access controls.
For everyday users, the takeaway is practical, not theoretical: watch your bank statements, turn on transaction alerts, and assume that if your data was in these systems, it may now be in circulation.
FAQ
Which banks were hit?
Shinhan Bank reported the first breach on September 30. KB Kookmin Bank and others reported cyberattacks later in the week, and Yonhap reports Hana Bank and Woori Bank were also breached, with additional incidents at second-tier institutions.
Has AI actually been confirmed as the attack method?
No. The FSC chairman said authorities “could not rule out” that AI was used in the attacks — it’s an open possibility under investigation, not a confirmed finding.
What is the government doing about it?
The president ordered a full investigation with response measures. The FSC launched on-site probes, ordered industry-wide security inspections, tighter access controls, reduced external system access, and rapid sharing of threat intelligence across banks.
Is North Korea suspected?
South Korea’s main opposition party asked authorities to investigate possible North Korean involvement, citing past Pyongyang-linked cyberattacks on financial institutions. Regulators have not publicly attributed the attacks.
Sources: Reuters, Yonhap News Agency.

