AI Agents Suspected in Attacks on Three of South Korea's Biggest Banks
South Korea is investigating attacks on Shinhan, KB Kookmin and Hana Bank that officials believe used AI agents. At least 25,000 Shinhan customers had credit data leaked.

South Korean authorities are investigating cyberattacks on three of the country's largest banks: Shinhan Bank, KB Kookmin Bank and Hana Bank. Officials believe the attackers used AI agents.
The numbers so far
Tom's Hardware, citing The New York Times, reports:
- At least 25,000 Shinhan Bank customers had personal credit information leaked last week.
- At Kookmin Bank, 99 customers and 20 current or former employees were affected.
- At Hana Bank, 89 customers had their information stolen.
South Korea's National Office of Investigation is looking at all three cases. President Lee Jae Myung said there were signs the hackers had used AI models, which had caused considerable public concern. He has asked his cabinet to confirm what happened and limit the damage. In his words, AI now makes it possible "to hack with ease even without specialized skills."
No one has been named as responsible, and attribution may take a long time.
Why this case stands out
AI-assisted attacks aren't new. The difference here is the target and the scale: three major banks in one country, in the same period, with the president publicly pointing at AI.
A lot of bank security planning assumes a serious attack needs a skilled, patient team, because reconnaissance, finding a weak point and building the exploit each took specialist time. AI agents shorten every one of those steps. The attacker doesn't have to be more skilled. They get to be faster and try more things.
Questions I'd put to an Indian bank's CISO this week
- Would we notice slow, low-volume extraction of customer credit data, or only a loud breach?
- Which internet-facing applications haven't had a fresh security review this quarter?
- Is access for former employees fully closed? Kookmin's affected list included former staff.
- Is our red team using AI agents yet? If attackers are, testing without them tells us less than we think.
I'd plan on the assumption that the attacker has an agent too.
Source: Hackers suspected of using AI agents for cyberattacks on South Korean banks — Tom's Hardware