South Korea has warned that artificial intelligence may have been used in a series of cyberattacks targeting the country’s financial sector, as police launch an investigation into the breaches.
More than seven financial institutions, including some of the country’s biggest banks, have reported customer data breaches in the past week, affecting more than 68,000 people, according to the Financial Services Commission.
President Lee Jae Myung raised the alarm during a cabinet meeting on Tuesday, saying there were signs that AI had been used in some of the attacks.
“We have now reached a point where AI can make (hacking) easy for even those without special skills,” Lee said.
He warned that advances in AI were making hacking methods increasingly sophisticated and expanding the potential scale of damage.
“ The government, companies and our society as a whole need to recognise the seriousness of the current situation and remain particularly vigilant,” the president said.
Shinhan Bank among affected institutions
Shinhan Bank, one of the institutions targeted, said information linked to loan applications from about 25,000 customers had been leaked.
The exposed information included customers’ names, phone numbers and annual income.
Police said an investigation had been launched following President Lee’s directive.
A South Korean government official told AFP that it was “highly likely” that Artex AI, an open-source security testing tool believed to be a Chinese AI system, was used in the attacks.
However, officials stressed that the alleged use of the tool does not mean the hackers were Chinese.
Park Sang-won, head of the Financial Security Institute, said attackers could operate through IP addresses in different locations, making it impossible to identify them based solely on an IP address.
Japan also reports major data breaches
The security concerns extend beyond South Korea.
At least three Japanese companies have reported data leaks in recent days, while 10 others said their data may have been compromised following unauthorised access to servers and websites.
Car-sharing company Times Car reported that data involving 6.6 million accounts had been leaked.
A Japanese barbecue restaurant chain also said personal information belonging to more than 10 million app users had been exposed.
The developments have intensified concerns over the growing ability of AI-powered tools to identify software vulnerabilities and potentially assist cyberattacks against banks, businesses and government infrastructure.