Banking Khabar / A series of cyberattacks targeting banks and financial institutions in South Korea has affected the personal information of more than 67,000 customers and related individuals. The attacks are suspected to have involved artificial intelligence (AI)-based technology and tools, raising concerns over cybersecurity in the country’s financial sector.
The attacks were reportedly carried out against several financial institutions from late September to early October. Shinhan Bank, KB Kookmin Bank, Hana Bank, BNK Busan Bank, Yegrum Savings Bank, Welcome Savings Bank and Hyundai Capital have been reported among the affected institutions.
Among the affected institutions, Shinhan Bank is reported to have recorded the largest data exposure. Information belonging to around 25,000 customers, including names, phone numbers, annual income and loan limits, was reportedly accessed without authorization.
Data linked to 119 customers of KB Kookmin Bank and 89 customers of Hana Bank was also reportedly affected. Initial reports indicate that more than 67,000 individuals and customers across various banks and financial institutions may have been affected. However, investigations are still underway to determine whether the stolen data has been publicly exposed or misused.
Investigators have reportedly found signs that attackers used AI-based automated cybersecurity and penetration-testing tools during the attacks. The use of AI can make cyberattacks more automated, faster and more targeted, making the incidents a serious cybersecurity challenge for financial institutions.
South Korean regulatory and security authorities are continuing their investigations and have increased security monitoring to prevent unauthorized access to other financial institutions. Attempts to gain unauthorized access were also detected at some other banks and financial institutions, but in several cases, access was reportedly blocked before customer data could be compromised.
The incidents highlight the need for banks and financial institutions to strengthen their investment not only in traditional cybersecurity systems but also in identifying and managing new risks created by AI. Authorities are also concerned that stolen personal and financial information could be used for voice phishing, smishing and other forms of digital fraud.
As digital banking services continue to expand, cybersecurity risks are also increasing. The incidents in South Korea show that financial institutions need to give greater priority to the potential misuse of AI alongside its legitimate applications, particularly as cyberattacks become more sophisticated and targeted.
