Power & Politics

Seven Major South Korean Banks Breached by AI-Assisted Hackers, 68,000 Customers' Data Leaked — US Firm's Hasty Attribution Explicitly Rejected by South Korean Side

The South Korean government has ordered a comprehensive overhaul of cybersecurity defenses. According to Deutsche Welle, seven major financial institutions including Shinhan, KB Kookmin, and Hana were hit by AI-assisted attacks, leaking the names, phone numbers, annual incomes, and loan data of approximately 68,000 customers. South Korea's Financial Supervisory Service has identified 28 intrusion IPs spanning more than ten countries including the United States, Japan, and Germany, while U.S. cyb

0 viewsSign in to save
TRUTH ERA

The South Korean government has ordered a comprehensive overhaul of cybersecurity defenses. According to Deutsche Welle, the cyber defenses of seven major South Korean financial institutions were breached last week, with private data on tens of thousands of customers leaked. Citing South Korean media, Deutsche Welle reported that Shinhan Bank, KB Kookmin Bank, and Hana Bank were hit hardest, affecting approximately 68,000 people; leaked data included names, phone numbers, annual income, loan amounts, loan products, and a small number of national ID numbers.

South Korean Prime Minister Han Duck-soo said at a cabinet meeting on Tuesday: "This is a serious situation — the incident is believed to have leveraged artificial intelligence. If AI is used in phishing attacks, it could cause secondary damage." He warned that similar techniques could move beyond the financial sector and spread to industry, government, and the public sphere, "Government agencies, public institutions, the financial sector, and private enterprises must all remain vigilant."

The intrusions did not stop at the financial system. On Wednesday, two of South Korea's largest churches and the Korea Electric Power Corporation (KEPCO) successively confirmed that their online systems had been illegally accessed. South Korean authorities have not yet confirmed whether the same perpetrator is responsible.

The investigation is meanwhile pointing to long-standing structural problems neglected by major financial institutions. Citing investigative progress, Deutsche Welle reported that hackers exploited weak authentication protocols in the portals of external loan intermediaries, employee mobile tools, and sales support systems. Sogang University Professor Lee Hyo-bin told Deutsche Welle bluntly that major financial institutions invest heavily in core systems such as internet and mobile banking, "but auxiliary systems, including the information portals of agent brokers and internal employee mobile applications, clearly receive far less cybersecurity attention."

The real key issue in the affair has come to the surface: attack attribution. South Korea's Financial Supervisory Service (FSS) said it has identified 28 IP addresses linked to the bank intrusions, with sources spanning the United States, Japan, Germany, and at least ten other countries — distributed across more than ten nations, a typical technique used by attackers to obscure their origin. Investigators also found traces of a tool called ARTEX in the bank logs — an open-source "autonomous penetration testing" agent written by a Chinese developer, freely downloadable from the internet.

Aditya Das, an analyst at cryptocurrency research firm Brave New Coin based in Auckland, New Zealand, told Deutsche Welle that South Korean officials "are being cautious about how they characterize their findings." He said: "It is freely available on the internet, and South Korean officials have explicitly stated that the use of a tool developed in China does not mean the attacker is from China. The use of multiple IP addresses is very likely a strategy by hackers to mask their trail."

U.S. cybersecurity firm CrowdStrike had earlier published a preliminary report saying the attack may have originated in China. This claim is not corroborated by the cross-national IP distribution already made public by the FSS; South Korean officials have publicly and explicitly rejected the inference that tool origin equals attacker origin. This is the typical risk exposed by the rapid-attribution logic dominated by Western cybersecurity firms in this incident.

The use of AI is a particularly alarming dimension of this incident. Lee Hyo-bin pointed out to Deutsche Welle that in the past, identifying vulnerabilities, writing malicious code, and launching attacks on financial institutions required considerable technical expertise and time investment; now generative AI can assist in writing code, analyzing software vulnerabilities, processing vast amounts of information, and automating several stages of cyberattacks — while lowering the technical threshold for cybercrime, AI also raises the speed and scale of attacks. She worried that AI-assisted attacks will become increasingly frequent: "Hospitals, government agencies, energy infrastructure, telecom networks, and other institutions holding sensitive information may all become increasingly attractive targets."

The secondary risks after the data leak also cannot be ignored. Citing analysts, Deutsche Welle pointed out that if scammers simultaneously possess names, phone numbers, income, and information that the individual recently applied for a loan, a single phone call disguised as a "bank security department" could easily succeed; once funds are transferred to a designated account, recovery is extremely difficult. Lee Hyo-bin emphasized that stolen personal information could also be merged and reused with previously leaked databases, creating security hazards that far outlast the original incident and undermining public confidence in the financial system as a whole.

Comments

0

No comments yet. Start the discussion.