Hackers are suspected of using an artificial intelligence agent developed in China to attack major South Korean financial institutions, exposing customer data and raising concerns that AI tools are making sophisticated cyberattacks faster and easier to execute.
The attacks affected several financial firms, while separate suspected AI-linked breaches also targeted two South Korean megachurches. Authorities have opened investigations as concerns grow over the use of AI agents to identify vulnerabilities and assist attackers.
Which South Korean Banks Were Targeted?
Cyberattacks involving AI agents were reported against several major South Korean banks, including Hana Bank, KB Kookmin Bank and Shinhan Bank.
Officials are investigating the incidents after hackers allegedly gained access to customer information. One account said personal information belonging to about 25,000 customers at Hana Bank was exposed, including the last four digits of personal credit information.
Another account said data involving 68,000 people was stolen in attacks targeting South Korea’s largest banks. The reports indicate that multiple financial institutions were affected, although the figures appear to refer to different parts of the broader series of incidents.
Investigators said the attacks showed traces of a cybersecurity tool called Artex AI, which was developed in China.
FCRF Launches CP-FRM to Build India’s Next Generation of Fraud Risk Professionals
How Was AI Allegedly Used in the Attacks?
The incidents have drawn attention because the attackers are suspected of using AI agents as part of the hacking process.
AI models are increasingly capable of helping users identify weaknesses in computer systems and exploit them. This could allow attackers to speed up activities that traditionally required more time and specialised technical knowledge.
South Korean President Lee Jae Myung said there were signs that hackers behind the incidents had used AI models, causing considerable public concern and anxiety.
“It’s now become possible to use AI to hack with ease even without specialized skills,” Lee said during a cabinet meeting.
He instructed officials to confirm the situation and ensure that damage from the incidents was minimised.
The growing capability of AI models could also make them a force multiplier for experienced hackers by assisting with planning, reconnaissance and attack execution.
Were Other Organisations Also Attacked?
The suspected AI-linked activity was not limited to banks.
Two South Korean megachurches were investigating cyberattacks that may have exposed personal information belonging to tens of thousands of people.
Yoido Full Gospel Church said information relating to about 85,000 members may have been compromised. The exposed data included names and dates of birth, while a smaller number of records contained changes to national identification numbers, addresses and telephone numbers.
Cybersecurity company Oasis Security said information connected to Sarang Church was stored on an overseas server containing tools called Artex and Sarang Church.
Initial analysis indicated that information relating to about 85,000 members may have been compromised.
Sarang Church said it had formed an emergency task force, reported the suspected incident to relevant authorities and was taking steps to determine what happened and prevent further harm.
Oasis Security said attackers had exploited a flaw in the church’s membership system that could have allowed access to data linked to as many as 89,580 registered user accounts.
Who Is Behind the Cyberattacks?
There was no clear indication in the material about who was responsible for the attacks on South Korea’s banking industry.
Attributing sophisticated cyberattacks can be difficult, particularly when attackers use techniques intended to conceal their identity and infrastructure.
South Korea’s National Office of Investigation is examining the cases involving the banks. The use of a China-developed cybersecurity tool does not by itself establish who carried out the attacks.
The incidents nevertheless highlight a broader security concern: AI tools can potentially lower the technical barrier for cyberattacks while allowing experienced operators to work more quickly.
Why Are AI Agents Becoming a Cybersecurity Concern?
AI models are becoming increasingly capable with each generation, giving legitimate security researchers powerful tools for identifying weaknesses. The same capabilities can potentially be misused by malicious actors.
Some attackers may attempt to bypass safeguards built into commercial AI products. The material also notes that some hackers exploit AI hallucinations or attempt to trick AI agents into running malware.
Open-weight and open-source models may present another challenge because some do not have the same safeguards found in commercial AI services.
Even when AI models have not replaced skilled hackers, they can make several stages of an attack easier, including reconnaissance, vulnerability discovery, planning and execution.
What Do the Attacks Mean for Financial Cybersecurity?
The suspected attacks illustrate how AI could change the speed and accessibility of cybercrime.
Banks hold large volumes of sensitive personal and financial information, making vulnerabilities in their systems particularly consequential. If attackers can use AI agents to discover weaknesses faster, security teams may have less time to detect and stop intrusions before information is accessed.
The concern is not simply that inexperienced attackers could gain new capabilities. Skilled hackers may also use AI to automate parts of their operations, allowing them to identify targets, analyse vulnerabilities and execute attacks more efficiently.
The South Korean incidents therefore raise a wider question for financial institutions and other organisations holding sensitive data: whether existing cybersecurity defences can respond quickly enough as attackers begin incorporating increasingly capable AI agents into their operations.
The420 Takeaway: “When AI Speeds Up Hacking, Defenders Have Less Time to React”
The South Korean incidents show why AI-assisted cyberattacks are becoming a serious security concern. AI may not eliminate the need for skilled hackers, but it can help accelerate vulnerability discovery, reconnaissance and attack execution. For banks and other organisations holding sensitive information, stronger defences will increasingly depend on detecting weaknesses and suspicious activity before AI-assisted attackers can exploit them at scale.
About the author — Ayesha Aayat writes on cybercrime, digital safety, and emerging online threats. Her work focuses on public awareness, legal clarity, and technology-driven risks.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics