South Korea Says AI Models May Have Been Used in Bank Cyberattacks
South Korea's president says AI models may have been used in recent bank cyberattacks as police investigate data breaches.
Yonhap reported Tuesday that South Korean police had launched a full-scale investigation into hacking attacks against commercial banks that led to a breach of customers' personal information. The Financial Services Commission said Friday that Shinhan Bank, KB Kookmin Bank and others had reported cyberattacks, while Yonhap reported that Hana Bank and Woori Bank also suffered breaches. Authorities have not disclosed details on what kind of AI tools were used or the full scale of the breaches.
On Sunday, FSC Chairman Lee Eog-weon convened an emergency meeting with financial industry associations, regulators and executives from affected institutions. He warned that the sector must respond with the highest level of vigilance. The Financial Supervisory Service and the Financial Security Institute shared data about 28 unique IP addresses and some country information linked to the recent hacking attempts with the financial sector, the FSS said Tuesday.
According to Yonhap, sources said Wednesday that a considerable number of IP addresses were found to have been used to mask those responsible for the cyberattacks. While the FSS identified 28 IP addresses in connection with the attacks, police determined that a significant number of them were used to hide the hackers' whereabouts. Investigators are tracing the attack path through international cooperation, the sources said.
The financial watchdog earlier shared the IP addresses with financial companies, along with country information, while noting the possibility that the attackers used indirect connections. In response to the cyberattacks, the National Police Agency formed a 28-member team to investigate the case.
Editor's Summary
South Korean President Lee Jae Myung said signs suggest AI models may have been used in recent cyberattacks on major banks, and police are investigating customer data breaches at several financial institutions. Regulators have shared 28 IP addresses with the financial sector, while police believe many were used to conceal the attackers' origin. The case has prompted an emergency regulatory meeting and a 28-member National Police Agency investigation team.