AI-powered attacks on banks expose technological lag in Korea's financial cyber defenses人工智能驱动的银行网络攻击暴露了韩国金融网络防御的技术滞后
Cyber defenses across Korea’s financial sector are facing intense scrutiny after a string of attacks hit banks and other financial companies, raisi...

AI-powered attacks hit seven financial firms in Korea since Thursday, exposing information on more than 67,000 people. Shinhan Bank, KB Kookmin Bank and Hana Bank were among the affected firms, and officials said the breaches exposed gaps in the sector’s defenses. President Lee Jae Myung ordered a thorough investigation on Sunday, and financial authorities held an emergency meeting the same day. The FSC warned that secondary damage such as voice phishing and smishing could follow.
Seven financial firms have reported information leaks since Thursday, including Shinhan Bank, KB Kookmin Bank, Hana Bank, Busan Bank, Yegaram Savings Bank, Welcome Savings Bank and Hyundai Capital.
More than 67,000 people are believed to have been affected, and the leaked information includes names, contact details, resident registration numbers, annual income and loan limits.
Shinhan Bank, KB Kookmin Bank and Hana Bank together spent nearly 124 billion won, or 92 million dollars, on information security last year.
Investigators found traces associated with ARTEX AI, a Chinese-language open-source autonomous penetration testing system, on a server believed to have been used in the attacks.
Financial Services Commission Chairman Lee Eog-weon said there is no indication that data directly usable for unauthorized payments has been leaked, but secondary damage such as voice phishing and smishing cannot be ruled out.
Published Oct 5, 2026 4:44 pm KST
Updated Oct 5, 2026 4:53 pm KST
Data of more than 67,000 customers across 7 companies compromised
Financial Services Commission Chairman Lee Eog-weon walks behind the heads of Korea's three largest commercial banks — from left, Hana Bank CEO Lee Ho-sung, KB Kookmin Bank CEO Lee Hwan-ju and Shinhan Bank CEO Jung Sang-hyuk — during an emergency meeting at Government Complex Seoul, Sunday. The meeting was held to discuss countermeasures against recent artificial intelligence-powered data breaches across the financial sector. Newsis
Cyber defenses across Korea’s financial sector are facing intense scrutiny after a string of attacks hit banks and other financial companies, raising fears that artificial intelligence (AI)-assisted cyberattacks could outpace existing security measures.
Seven financial firms have reported information leaks so far since Thursday, including three of the country’s largest commercial banks — Shinhan Bank, KB Kookmin Bank and Hana Bank — along with Busan Bank, Yegaram Savings Bank, Welcome Savings Bank and Hyundai Capital. More than 67,000 people are believed to have been affected.
The leaked information includes customers’ names, contact details, resident registration numbers, annual income and loan limits.
The latest incidents differ from some of the biggest cybersecurity breaches in the past, when the core IT or transaction systems of individual institutions were compromised. This time, multiple firms were targeted in quick succession, with attackers apparently looking for easier ways in.
The cyber criminals, believed to be based overseas, repeatedly probed less-protected entry points, including systems used by employees, outside contractors and loan agents, rather than trying to penetrate banks’ core networks directly.
Investigators found traces associated with ARTEX AI, a Chinese-language open-source autonomous penetration testing system, on a server believed to have been used in the attacks, although it does not mean the attacks originated in China.
The use of such tools can dramatically speed up the search for weak points. Instead of manually working through systems one at a time, an AI agent can scan for vulnerabilities, adjust its approach based on what it finds and move on to another target.
Lim Jong-in, a professor at Korea University’s Graduate School of Information Security, described the AI agents as being “capable of automatically searching for vulnerabilities, choosing to target servers operated by partner companies rather than directly attacking banks’ main systems.”
The attackers also appear to have utilized previously leaked personal information, with credential stuffing cited as one of the likely techniques used. Credential stuffing involves using already stolen usernames and passwords to try accessing accounts on other services, typically through automated login attempts.
Lag in cybersecurity exposed
The latest string of breaches has raised questions about whether the financial sector’s security systems are adequately prepared for large-scale, automated attacks using AI.
Shinhan Bank, KB Kookmin Bank and Hana Bank together spent nearly 124 billion won ($92 million) on information security last year. Yet the latest attacks appeared to bypass such defenses by exploiting weaker links elsewhere.
“The reason these breaches are particularly concerning is the combination of personal and financial information that has been exposed. A phone number on its own has limited value, but when criminals can connect it to someone’s income or potential loan limit, they gain enough context to create a highly convincing and personalized scam,” said Hwang Sung-ho, Korea country manager at cybersecurity software company Nord Security.
Hwang Suk-jin, a professor at Dongguk University’s Graduate School of International Affairs and Information Security, said advances in AI are lowering the entry barrier for cyber criminals, allowing them to automate parts of the process that previously required specialized expertise.
“As attacks are becoming more coordinated and automated, defenses cannot remain fragmented at the level of individual companies,” he said. “The existing cybercrime investigation system, specialized personnel and techniques also need to be upgraded for the AI era.”
President Lee Jae Myung on Sunday ordered officials to “approach the matter with the utmost seriousness and make every effort to conduct a thorough investigation and prepare countermeasures.”
Later that day, financial authorities convened an emergency meeting with chief executives from across the sector to discuss a response.
“There is currently no indication that sensitive information that could be directly used for unauthorized payments or other financial crimes has been leaked,” Financial Services Commission Chairman Lee Eog-weon said. “But we cannot rule out the possibility of secondary damage, such as voice phishing and smishing using the leaked data.”
He added, “As new types of cyberattacks are likely to continue occurring with greater frequency, we must also move quickly to establish security systems capable of using AI to defend against AI-driven attacks.”
Shinhan, Kookmin, Hana data breaches fuel concerns over AI-powered cyberattacks in financial sector
Lee orders thorough probe into data breaches at local banks
自周四以来,韩国七家金融机构遭到人工智能攻击,导致超过6.7万人的信息泄露。受影响的机构包括新韩银行、KB国民银行和韩亚银行。官员表示,此次事件暴露了该行业防御体系的漏洞。韩国总统李在明于周日下令对此事展开彻底调查,金融监管机构也于当日召开紧急会议。韩国金融监督管理委员会(FSC)警告称,语音钓鱼和短信钓鱼等二次攻击可能会造成进一步的损害。
自周四以来,已有七家金融公司报告了信息泄露事件,其中包括新韩银行、KB国民银行、韩亚银行、釜山银行、Yegaram储蓄银行、Welcome储蓄银行和现代资本。
据信有超过 67,000 人受到影响,泄露的信息包括姓名、联系方式、居民登记号码、年收入和贷款限额。
新韩银行、KB国民银行和韩亚银行去年在信息安全方面共花费了近1240亿韩元,约合9200万美元。
调查人员在据信用于攻击的服务器上发现了与 ARTEX AI(一款中文开源自主渗透测试系统)相关的痕迹。
金融服务委员会主席李玉元表示,目前没有迹象表明可以直接用于未经授权支付的数据已被泄露,但不能排除语音钓鱼和短信钓鱼等间接损害的可能性。
发布于2026年10月5日下午4:44(韩国标准时间)
更新于2026年10月5日下午4:53(韩国标准时间)
7家公司超过67000名客户的数据遭到泄露
周日,在首尔政府大楼举行的紧急会议上,金融服务委员会主席李玉元走在韩国三大商业银行负责人——从左至右依次为:韩亚银行CEO李浩成、KB国民银行CEO李焕柱和新韩银行CEO郑相赫——身后。此次会议旨在讨论应对近期金融领域人工智能驱动的数据泄露事件的措施。
在韩国银行和其他金融公司遭受一系列攻击后,韩国金融行业的网络防御正面临严格审查,这引发了人们的担忧,即人工智能 (AI) 辅助的网络攻击可能会超过现有的安全措施。
自周四以来,已有七家金融机构报告了信息泄露事件,其中包括韩国三大商业银行——新韩银行、KB国民银行和韩亚银行,以及釜山银行、Yegaram储蓄银行、Welcome储蓄银行和现代资本。据信,超过6.7万人受到影响。
泄露的信息包括客户姓名、联系方式、居民登记号码、年收入和贷款限额。
最新发生的事件与以往一些最严重的网络安全漏洞事件有所不同,以往的漏洞事件通常只涉及单个机构的核心IT系统或交易系统。而这一次,多家公司在短时间内接连成为攻击目标,攻击者显然是在寻找更容易的入侵途径。
据信这些网络犯罪分子来自海外,他们反复探测安全防护较弱的入口点,包括员工、外部承包商和贷款代理人使用的系统,而不是试图直接渗透银行的核心网络。
调查人员在据信曾用于攻击的服务器上发现了与 ARTEX AI(一款中文开源自主渗透测试系统)相关的痕迹,但这并不意味着攻击源自中国。
使用此类工具可以显著加快查找薄弱环节的速度。人工智能代理无需手动逐个检查系统,即可扫描漏洞,根据发现的情况调整策略,然后转向下一个目标。
韩国大学信息安全研究生院教授林钟仁(Lim Jong-in)将人工智能代理描述为“能够自动搜索漏洞,选择攻击合作伙伴公司运营的服务器,而不是直接攻击银行的主要系统”。
攻击者似乎还利用了之前泄露的个人信息,其中一种可能的攻击手段是撞库攻击。撞库攻击是指使用已被窃取的用户名和密码尝试访问其他服务的帐户,通常是通过自动登录尝试来实现。
网络安全滞后暴露无遗
最近发生的一系列安全漏洞引发了人们的质疑:金融行业的安全系统是否已做好充分准备,应对使用人工智能的大规模自动化攻击。
新韩银行、KB国民银行和韩亚银行去年在信息安全方面共投入近1240亿韩元(约合9200万美元)。然而,最新的攻击似乎绕过了这些防御措施,利用了其他方面的薄弱环节。
“这些数据泄露事件之所以尤其令人担忧,是因为泄露的信息同时包含了个人信息和财务信息。电话号码本身的价值有限,但当犯罪分子能够将其与某人的收入或潜在贷款额度联系起来时,他们就能获得足够的信息来制造极具说服力且个性化的诈骗,”网络安全软件公司Nord Security的韩国区经理黄成浩(Hwang Sung-ho)表示。
东国大学国际事务与信息安全研究生院教授黄锡镇表示,人工智能的进步降低了网络犯罪分子的准入门槛,使他们能够自动化以前需要专业知识才能完成的部分流程。
他表示:“随着攻击变得越来越协调和自动化,防御措施不能再局限于单个公司层面。现有的网络犯罪调查系统、专业人员和技术也需要升级,以适应人工智能时代。”
李在明总统周日下令官员们“以最严肃的态度处理此事,尽一切努力进行彻底调查并制定应对措施”。
当天晚些时候,金融监管机构召集了来自整个行业的首席执行官们召开紧急会议,讨论应对措施。
金融服务委员会主席李玉元表示:“目前没有迹象表明可直接用于未经授权支付或其他金融犯罪的敏感信息已被泄露。但我们不能排除利用泄露数据进行语音钓鱼和短信钓鱼等二次损害的可能性。”
他补充说:“随着新型网络攻击可能越来越频繁地发生,我们也必须迅速建立能够利用人工智能防御人工智能驱动攻击的安全系统。”
新韩、国民、韩亚数据泄露事件加剧了人们对金融领域人工智能网络攻击的担忧
李显龙下令彻底调查本地银行的数据泄露事件