Cybersecurity

AI-Enabled Cyberattacks Hit South Korean Banks as One Attacker Targets Multiple Institutions

0

South Korean banks are facing heightened cybersecurity concerns after CrowdStrike identified a likely China-based individual who allegedly used artificial intelligence tools to conduct attacks against multiple financial institutions. The findings highlight how AI agents could allow individual attackers to operate at a scale that previously required larger criminal groups.

At least nine South Korean banks have been targeted or reported as victims of cyberattacks since late September. Shinhan Bank said personal information belonging to about 25,000 customers was compromised, while KB Kookmin Bank reported a leak involving information from 119 customers. South Korean authorities have launched an investigation into the incidents.

AI changes the scale of cyberattacks

CrowdStrike said the suspected attacker used a Chinese-developed AI agent called ARTEX alongside large language models, including Anthropic’s Claude. According to the cybersecurity company, the activity demonstrates how one human operator can use AI systems to automate and accelerate parts of a cyberattack campaign.

The use of AI does not necessarily mean that the technology independently conducted every stage of the attacks. Instead, the case illustrates how attackers can combine AI agents, coding assistants and existing security tools to automate reconnaissance, vulnerability research and other technical tasks.

That distinction is becoming increasingly important for cybersecurity teams. As AI systems become more capable of carrying out multi-step activities, defenders may need to account for threats that move faster than traditional manually operated campaigns.

Financial institutions face growing exposure

Banks are particularly attractive targets because their systems contain valuable financial and personal information and are connected to large customer networks.

The South Korean incidents also demonstrate the potential impact of attacks that are distributed across multiple institutions. Rather than focusing on a single organization, an attacker using automated tools can potentially investigate and target several systems in a shorter period.

CrowdStrike said the suspected individual appeared financially motivated and used Chinese-language prompts during some AI coding sessions. The company assessed with moderate confidence that the actor was a Chinese speaker, but the activity has not been publicly attributed to a named threat group. Chinese authorities have denied involvement and said China opposes hacking activities.

AI security becomes a priority for banks

The attacks add to growing evidence that artificial intelligence is becoming part of the cyber threat landscape as well as a defensive technology.

For financial institutions, the challenge is no longer limited to protecting against conventional malware, phishing and credential theft. Security teams increasingly need to consider how attackers can use AI to automate technical workflows and scale operations.

The South Korean incidents could therefore accelerate investment in AI-powered detection, behavioral monitoring and automated incident response across the financial sector.

For banks, the central cybersecurity challenge is becoming clear: defending against AI-enabled attacks may require security systems capable of identifying and responding to automated activity at the same speed as the attackers themselves.

RWA WEEK Singapore Announces New Wave of Institutional Speakers as October Event Draws Closer

Previous article

ASOS Cyberattack Exposes Customer Data as Social Engineering Threats Target Corporate Accounts

Next article

You may also like

Comments

Comments are closed.