EXPLAINER How AI emerged as new threat in Korea's bank hacking crisis

gettyimagesbank

gettyimagesbank

AI-powered hacking could take cyberattacks to unprecedented scale, experts warn

Hackers once had to manually test security defenses, identify vulnerabilities and work out how to exploit them. Now, artificial intelligence (AI) can do much of that work, requiring little human input.

That possibility is at the center of Korea's latest security crisis in the financial sector, as investigators have found traces of an AI-powered autonomous penetration-testing tool in a series of recent cyberattacks on the country's major banks.

Since last week, Shinhan Bank, KB Kookmin Bank, Hana Bank, Yegaram Savings Bank and BNK Busan Bank have all reported data breaches, while Woori Bank and NH NongHyup Bank have detected signs of hacking attempts, though no data leaks were confirmed.

Shinhan Bank reported that about 25,000 customers were affected, with personal information including names, phone numbers, annual income and loan limits exposed. KB Kookmin reported 119 affected customers, while Hana Bank said personal information belonging to 89 customers was exposed.

The hacking spree has drawn particular concern after investigators reportedly found traces of an AI-powered tool known as ARTEX.

The Chinese-language autonomous penetration-testing tool is designed to automate tasks that typically require human expertise, including scanning systems for vulnerabilities and developing potential attack paths.

The tool can connect to AI models developed by Chinese company DeepSeek as well as OpenAI and Anthropic, allowing multiple AI agents to analyze hacking targets and potential intrusion routes.

Experts warn that AI-powered hacking could mark the beginning of a broader shift in the cybersecurity landscape.

"It would be difficult for humans to carry out attacks this fast and on such a large scale across the financial sector in just a matter of days. It is highly likely that AI was used," said Lim Jong-in, a professor at Korea University's Graduate School of Information Security.

He likened the difference in speed between regular hackers and AI-powered attacks to that between a human running and a Ferrari, saying, "It would take weeks, if not months, for human hackers to plan and carry out such large-scale attacks."

However, the professor cautioned against assuming that China was behind the latest attacks simply because traces of a Chinese-language AI tool were found.

"The actor behind the attacks remains unknown," he said, noting that some Chinese AI models are released with relatively weak safeguards, allowing anyone around the world to download and modify them for malicious purposes.

In a nutshell, AI can make hacking faster and broader by automating parts of the attack process that once required significant human effort.

Traditional cyberattacks require hackers to identify targets, probe networks, find vulnerabilities and determine how to exploit them. AI agents can automate much of that process with little human input, allowing attackers to explore multiple attack paths more quickly.

ATMs from Korea's major banks are seen in Seoul, Sunday. Yonhap

But the damage from the latest bank breaches remains relatively limited.

That stands in contrast to some of Korea's biggest data breaches in recent years, including incidents affecting nearly 40 million Tving users in June and 33 million Coupang users last year.

Hwang Suk-jin, a professor at Dongguk University's Graduate School of International Affairs and Information Security, attributed the limited scale of the damage to the attackers' indirect route into the banks, which targeted supporting networks rather than their core systems.

"Banks have core networks and supporting networks. The supporting networks have relatively weaker security, and they were targeted in this attack. Rather than entering through the front door, the attackers came in through a window, using an indirect route to steal only some of the information," Hwang said.

However, the relatively limited scale of damage does not mean the threat is over. Hwang indicated that the recent attacks may have been an initial test to identify vulnerabilities, raising the possibility of larger follow-up attacks using the information obtained in the breaches.

As the threat from AI-powered hacking is expected to grow, experts say financial firms will need to overhaul their security systems and more actively use AI technologies in their defenses.

"As attackers use AI to rapidly find vulnerabilities, defenders also need to use AI to detect weaknesses first and strengthen systems capable of responding automatically around the clock," Lim said.



Interesting contents

Taboola 후원링크

Recommended Contents For You

Taboola 후원링크