South Korean President Lee Jae Myung has ordered a comprehensive investigation into a series of personal data leaks and cyberattacks targeting major domestic banks, financial firms, and public institutions. The presidential office instructed authorities to determine the precise scale of potential damage and introduce stricter safeguards across the financial network, amid heightened concern among regulators that attackers may have deployed artificial intelligence to carry out the intrusions.
Regulator Convenes Emergency Session Over Multi-Bank Breaches
The directive prompted Financial Services Commission Chairman Lee Eog-weon to hold an emergency meeting on Sunday with representatives from financial industry associations, supervisory bodies, and affected institutions. Officials moved the session forward from its original date of October 7 following reports of fresh security breaches across the banking sector. Regulators and bank executives reviewed existing security frameworks and evaluated recent incident patterns to identify systemic vulnerabilities before further attacks take hold.
The regulatory response escalated after Shinhan Bank reported a security breach on September 30, triggering an immediate on-site inquiry by financial watchdogs. Authorities soon expanded the investigation across the broader banking sector as additional institutions disclosed related security events. The FSC confirmed breaches affecting Shinhan Bank and KB Kookmin Bank, while domestic media reports indicated that Hana Bank and Woori Bank were also hit by recent cyber incidents.
Regulators Weigh Potential Use of Artificial Intelligence
The Financial Services Commission announced that investigators cannot rule out the possibility that artificial intelligence was leveraged in the latest wave of intrusions. In response, the commission urged financial institutions to bolster their AI-driven defensive capabilities and pursue an extensive overhaul of the industry’s cybersecurity architecture. Officials stressed that defenses must evolve rapidly to withstand increasingly automated and adaptive intrusion tactics.
Preliminary findings indicate that the perpetrators conducted automated, wide-ranging network scans to locate vulnerabilities across multiple firms rather than isolating a single target. Bank records submitted to lawmakers showed that digital traffic linked to the attacks passed through internet protocol addresses registered across several countries, including the United States, Japan, Singapore, Vietnam, and Britain. Authorities cautioned that IP address routing does not confirm the actual physical location or identity of the attackers, leaving the source unresolved.
Stricter Access Controls and Political Calls for Scrutiny
To counter ongoing vulnerabilities, the FSC instructed all financial institutions to perform sweeping security audits, enforce stringent access controls on internal networks, and minimize connections to outside systems. Financial firms must also adopt immediate safeguards to protect consumers from fraudulent activity or identity theft linked to the compromised data. In addition, regulators ordered institutions to establish real-time threat-sharing channels to circulate technical indicators, attack signatures, and suspicious IP addresses before malicious traffic spreads.
The cyber incidents have also drawn sharp attention from South Korean lawmakers. The main opposition People Power Party urged state authorities to investigate whether North Korean cyber units played a role in the operation, citing past intrusions on domestic financial networks attributed to groups linked to Pyongyang. Official investigators have not confirmed the involvement of North Korea or any specific foreign group, noting that forensic analysis remains underway to assess the full volume of exposed personal records.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics