South Korean President Lee Jae Myung
South Korea bank hacks: Lee warns AI signs found in breaches Screengrab/Joint Press Corps/Youtube

South Korean President Lee Jae Myung warned on Tuesday, 6 October, that artificial intelligence may have been used in recent bank hacks in Seoul and elsewhere, as police investigate customer data breaches affecting several financial institutions.

'In some hacking incidents, signs have emerged of AI being used, causing considerable public concern and anxiety,' Lee said during a cabinet meeting. He ordered officials to establish what happened quickly and clearly, while directing them to focus personnel and resources on limiting the damage.

The warning is significant because authorities have not identified the specific AI tools involved. They have also not disclosed the full extent of the breaches, meaning the investigation remains at an early stage.

South Korea Bank Hacks Trigger Data Leak Probe

The latest developments follow a series of attacks reported by major South Korean banks and other financial firms.

Shinhan Bank said last week that information linked to around 25,000 customers had been leaked. The details included names, phone numbers and annual income, according to Yonhap News Agency. Hana Bank also reported a leak involving 89 customers.

The Financial Services Commission said Shinhan Bank, KB Kookmin Bank and other institutions had reported cyberattacks. Yonhap reported that Hana Bank and Woori Bank were also affected.

Woori Bank and NH Nonghyup Bank faced similar attempts, although the institutions blocked unauthorised access and found no evidence that personal information had been leaked, Yonhap reported.

South Korean police have now launched an investigation into the attacks. Investigators are expected to examine whether the incidents were connected and whether the suspected use of AI formed part of a wider campaign.

A system being probed or attacked with automated tools is not the same as proving that an AI model independently carried out a breach. For now, officials have publicly described signs and suspicions, not a completed technical finding.

Regulators Race To Understand AI Threat

On Sunday, Financial Services Commission Chairman Lee Eog-weon convened an emergency meeting with regulators, financial associations and executives from affected institutions.

'We have detected multiple security breaches across various sectors in a short span of time, not only at major commercial banks but also at savings banks and specialised credit finance firms,' he said, according to Yonhap.

The FSC chief said no sensitive information that could be used for unauthorised payments appeared to have been exposed so far. He nevertheless warned that leaked personal details could be used in voice-phishing attacks or other scams.

The Financial Supervisory Service and Financial Security Institute said on Tuesday that they had shared information about 28 unique internet protocol addresses linked to recent hacking attempts. The agencies also circulated some information about the countries associated with those addresses.

The number does not establish where the attackers were based. IP addresses can be routed through different countries, and investigators have not publicly identified those responsible.

South Korea's financial sector is now being urged to strengthen defences designed for attacks that can move faster than conventional criminal operations. AI tools can assist with reconnaissance, identify potential weaknesses and generate convincing messages, but the authorities have not said which of those capabilities were allegedly used here.

Customers Left Seeking Clear Answers

Customers are left asking whether their information was exposed, what criminals might do with it and whether banks can detect similar activity before it becomes another data leak.

The issue also sits within a wider international debate about AI-assisted cybercrime. In September, Australia said an OpenAI agent had accessed files through a government health data portal in June.

An artificial intelligence research firm later said AI agents had attempted to hack a Canadian government website, although Canada said there was no indication its systems had been compromised.

Those cases remain different from the South Korean bank attacks. They show why governments are treating the possibility of AI-enabled intrusion as more than a theoretical threat.

President Lee's instruction was clear. Authorities must determine the circumstances, contain the damage and adapt cybersecurity methods to the AI era.

For customers, the immediate concern is less about the technology's label than the information already exposed. Names, phone numbers and income details may not directly authorise a payment, but combined with other data, they can make fraud attempts more convincing.