AI-Linked Cyberattacks Expose Gaps in South Korea's Financial Defenses, Editorial Says
Seven South Korean financial firms including Shinhan, KB Kookmin and Hana reported personal data leaks, while Woori and NH Nonghyup blocked similar intrusions. The Korea Herald calls for unannounced testing and industry-wide information sharing.
Shinhan Bank reported the exposure of information belonging to about 25,000 customers, including names, phone numbers and annual income. Hana Bank reported a separate leak involving 89 customers. Police have begun investigating the attacks, and financial authorities are examining whether artificial intelligence was used, the editorial said. Regulators have identified 19 IP addresses in 12 countries associated with the recent attacks, though the ultimate perpetrators remain under investigation.
The attacks appear to have targeted systems connected to the outside world rather than core networks handling deposits and transfers, according to the editorial. At several banks, the vulnerable systems included services used by loan agents or employees, platforms that may look peripheral to internet banking but can still provide access to valuable personal information. Woori Bank and NH Nonghyup Bank faced similar attempts but prevented unauthorized access; their defenses reportedly included biometric verification, restricted IP access and tighter network separation.
The editorial argues that the use of AI changes the economics of the threat, because an attacker no longer needs to examine every potential target. AI agents can help identify exposed systems, probe weaknesses and rapidly modify attacks, making conventional methods of reconnaissance inadequate. The wide geographic spread of the identified addresses points to a further difficulty, it says, since a defense designed around known threats can struggle when attackers examine many targets and change tactics quickly.
Under those conditions, the editorial contends, the old definition of security is inadequate. A certificate can confirm that procedures were followed when an audit took place, but it cannot confirm that an obscure external-facing application will withstand an attack that changes as it unfolds. Security spending remains important, the editorial says, but the size of a budget says little about whether a system can detect and contain an intrusion in real time.
The editorial calls for static certification and annual inspections to give way to regular, unannounced exercises that test every externally accessible system, including those operated by partners and contractors. It adds that the response must also become collective, arguing that concerns about liability or reputational damage can discourage disclosure. Regulators, it says, should establish protections for prompt reporting and require rapid sharing of both successful breaches and attacks that were stopped, because a blocked intrusion can be as valuable to the industry as a successful one, revealing how an attack works and where another institution may be exposed.
The editorial notes that the urgency extends beyond finance. A separate leak at Korea Electric Power Corp. exposed information belonging to about 24,000 employees, although the company said it was unrelated to the recent AI-linked financial attacks. It argues that critical institutions have accumulated peripheral systems as their core networks became harder to penetrate, and that those outer layers can become the easiest route into sensitive data. The country, it concludes, should treat financial cybersecurity as national infrastructure protection, with service entrances, side doors and administrative portals receiving the same scrutiny as core systems.