A pedestrian in a cap walks past a KB Kookmin Bank branch on Feb. 2, the day the hacking incident came to light. Yonhap News
South Korea’s banking sector has been exposed to artificial intelligence-driven hacking attacks for the first time. On the 2nd, a day after Shinhan Bank disclosed a data breach affecting about 25,000 people, Kookmin Bank and Hana Bank said personal and credit information belonging to 119 and 89 customers, respectively, had been leaked. BNK Financial Group also reported the leak of 11 items of personal information on an outsourced worker, part of a simultaneous wave of hacking aimed at commercial banks. The banks say no financial transaction data was involved, but customers remain deeply uneasy.
The most troubling aspect is that the attacks exploited AI. Banks handle customers’ money and data and are considered among the most tightly secured institutions, so the fact that even they fell victim to AI-driven hacking is a grave matter. Traces of ARTEX AI, a Chinese-language open-source AI penetration testing tool, were found on a server used in the attack on Shinhan Bank. Investigators determined that outsiders gained access through credential stuffing, a technique that automatically feeds leaked IDs and passwords into login systems to probe for weaknesses. At Kookmin Bank, Hana Bank and BNK Financial Group as well, AI agents are reported to have automated the search for vulnerabilities and attack paths to extract information.
Most of the banks became aware of possible data leaks on the 30th of last month. At Shinhan Bank, the entry point was a quick-inquiry service for loan brokers; at Kookmin Bank, it was a mobile work-support system for employees. Beyond customer-facing financial transaction systems, services built for internal convenience became channels for intrusion. The episode drives home that in an era when AI attacks and AI defends, not even large banks are exempt. Financial firms and regulators must check whether AI security systems commensurate with the expansion of digital finance are actually working.
The frequency and scale of hacker attacks using AI agents will clearly grow. Preparing countermeasures is not a choice but a necessity. This is the moment to take a comprehensive look at the sector’s defenses, including vulnerability assessments, access controls and anomaly detection. Swiftly sharing confirmed weaknesses and signs of attack, and strengthening verification and response drills that assume a real attack, are equally essential. It is time to rebuild financial information security from the ground up for the AI era.
Click Here For The Original Source.
