Cyber attacks at numerous South Korean banks have prompted the country’s Financial Services Commission (FSC) to hold an emergency meeting and launch an investigation. KISA, South Korea’s data protection agency, has also been notified.
The country’s National Office of Investigation has also launched an investigation and is willing to cooperate with other agencies. There are considerations to refer the probe to the country’s Serious Crime Investigation Agency.
Cyber attacks at South Korean banks affect hundreds of thousands
The cyber attacks have targeted some of the country’s largest banks, including Shinhan Bank and KB Kookmin Bank, each with assets exceeding $400 billion. Hana Bank also experienced a cyber attack that affected its sales support system. According to local sources, the wave of cyber attacks has affected at least seven South Korean banks.
The wave of cyber attacks has exposed the personal information of at least 140,000 people, with Shinhan Bank leaking the personal information of approximately 25,000 customers and KB Kookmin Bank exposing the credit card details of 119,000 customers.
Meanwhile, the wave of cyber attacks has prompted authorities to direct banks to inspect their IT systems for indicators of compromise and to enhance their cybersecurity controls.
They should also limit exposure and enhance their authentication and access controls to prevent cyber attacks. South Korean banks were also advised to share internal security inspection results and threat information, and coordinate their responses. Impacted customers could also qualify for compensation.
According to local sources, the National Office of Investigation (NOI) is investigating potential violations of the Information and Communications Network Utilization Act. The agency has formed a 28-member team to investigate the incidents.
Experts also suggest referring the case to the Serious Crime Investigation Agency, as it involves electronic data and financial records. Additionally, NOI is willing to cooperate with other relevant agencies to investigate the cyber attacks.
NOI vows to “carry out an investigation swiftly and strictly while closely cooperating with relevant agencies to ease the public’s anxiety.”
Hackers leverage AI to breach South Korean banks
ARTEX AI, a Chinese-language AI platform, was suspected of being linked to cyber attacks on numerous South Korean banks, based on HTML pages found on the threat actor’s command-and-control (C2) servers.
Open-source ARTEX AI lowers the barrier to entry by enabling pentesters to automate a wide range of cybersecurity tasks, including information gathering, vulnerability discovery, and attack path planning. However, cybercriminals also exploit the tool for nefarious purposes.
According to Mun Chong-hyun, the head of the Genians Security Center, several security experts believe that the cyber attacks utilized ARTEX, an “AI autonomous penetration testing console” or related environments.
President Lee Jae Myung also suggested that AI was used in the cyber attacks, and ordered the deployment of the necessary resources to mitigate the damage.
“In some hacking incidents, signs have emerged of AI being used, causing considerable public concern and anxiety,” Lee said.
“Please establish the circumstances swiftly and clearly, and concentrate personnel and resources on minimizing the damage.”
However, not all cyber attacks on South Korean banks were linked to the open-source AI platform, and authorities have not associated it with any particular threat actor. At the time of publication, no cybercrime gang has claimed responsibility for the cyber attacks on South Korean banks.
Meanwhile, AI continues to play a crucial role in cybersecurity. In September 2026, a 16-year-old security researcher discovered a vulnerability that could have exposed 17 trillion records from Microsoft’s analytics platform Titan, using a self-developed AI tool.

