Financial Authorities Warn of AI Hacking Risks Amid Recent Cyber Incidents

by KIM JIYOON Posted : October 4, 2026, 14:44Updated : October 4, 2026, 14:44

Lee Ok-yeon, the Chairman of the Financial Services Commission, stated that the possibility of hacking using artificial intelligence (AI) cannot be ruled out in light of recent cyber incidents in the financial sector. He emphasized the urgent need to establish AI-based security systems. The financial authorities will conduct emergency checks on vulnerable systems and authentication processes across the financial sector, and they have pledged to hold accountable those who neglect to respond to shared attack information, should similar incidents occur.

On October 4, Lee convened an emergency meeting at the Government Seoul Building with heads of financial associations and CEOs of affected financial companies to assess the response situation. Initially, the financial authorities planned to hold an emergency response meeting on October 7, but the schedule was moved up due to reports of ongoing attacks affecting savings banks and capital firms following incidents at banks.

The meeting included Lee, Financial Supervisory Service Chairman Lee Chan-jin, and leaders from major financial associations, including banking, investment, life insurance, non-life insurance, savings banks, credit finance, and fintech sectors. Representatives from financial companies that experienced breaches, such as Shinhan, KB Kookmin, Hana, BNK Busan Bank, Welcome, Ye-garam Savings Bank, and Hyundai Capital, were also present.

In his opening remarks, Lee noted, "No matter how robust a security system is, a single unmanaged vulnerability can become a weakness in the entire security framework." He added, "While no sensitive information has been confirmed as leaked so far, the potential for secondary damage, such as voice phishing, cannot be dismissed. We must remain vigilant and proactively respond with full force."

He stressed that cyber threats do not recognize boundaries between financial and non-financial sectors, and pledged to strengthen inter-agency cooperation with relevant departments, including the Ministry of Science and ICT and the National Police Agency, to respond to breach threats on a government-wide level.

Lee also mentioned the possibility that AI was used in the recent breaches, highlighting the need to enhance security systems in response. He stated, "It is difficult to say definitively, but we cannot rule out the possibility of hacking attacks utilizing AI. As new types of frequent cyber attacks may continue, we must expedite the establishment of security systems that defend against AI attacks with AI technology."

He added, "As AI technology evolves rapidly, hacking methods that exploit unexpected vulnerabilities are spreading quickly. I hope the financial sector actively participates in policies such as AI security testing and accelerates the transition to AI-based security systems."

The financial authorities suspect that the recent series of hacking incidents may have been carried out by the same attacker. This suspicion arises from the discovery of the same attacker's Internet Protocol (IP) address across multiple financial companies, as well as indications that the attacker changed IP addresses while continuing the attacks.

It is particularly suspected that the attacker may have used AI tools to conduct large-scale automated attacks on multiple financial companies. The main attack routes focused on auxiliary systems, such as employee and loan recruitment support systems or websites, rather than the core systems that handle key financial transactions. While some systems experienced leaks of customer or employee-related information, no disruptions to customer financial services or monetary losses were reported.

To prevent similar incidents from recurring, the Financial Supervisory Service has ordered a comprehensive investigation of services with inadequate authentication procedures across the financial sector, requiring corrections to be made and services to be suspended if necessary. Banks and card companies must complete their self-checks by October 6, while securities, insurance, savings banks, and electronic financial service providers must do so by October 8. After analyzing the results, any deficiencies identified will require prompt remediation.

Lee stated, "If similar incidents occur due to negligence in necessary checks and responses despite shared attack information and incident cases, we will hold those responsible strictly in accordance with relevant laws."

Tension is high in the financial sector following the discovery of widespread hacking attacks from September 30 to October 3, affecting four banks, including Shinhan, KB Kookmin, Hana, and BNK Busan Bank, as well as Ye-garam and Welcome Savings Banks and Hyundai Capital. President Lee Jae-myung has also directed thorough investigations and the establishment of countermeasures.

Kang Yu-jeong, the Chief Spokesperson for the Blue House, stated on October 4, "President Lee has been briefed on the recent incidents of personal information leaks at financial and public institutions and the current response situation. He has instructed that a serious approach be taken to ensure thorough investigations and the establishment of effective measures."




* This article has been translated by AI.