Entire Financial Sector Becomes Target of AI-Powered Hacking
The entire financial sector has become a target of AI-powered hacking. The scope of attacks has been confirmed to stretch from major commercial banks to savings banks, capital companies (installment financing), and mutual financial institutions (community-based financial organizations including regional agricultural and livestock cooperatives). As hackers use artificial intelligence (AI) to automatically find security vulnerabilities and repeatedly infiltrate systems, they can now attack multiple financial companies simultaneously at far lower cost and with fewer personnel than in the past. Authorities have also identified indications that Chinese-language AI hacking tools were used in some of the attacks.
There have also been confirmed cases where AI went beyond assisting hackers to directly carrying out a substantial portion of the attacks. Anthropic, an AI company, disclosed that 'GTG-1002,' a group it assessed as Chinese government-backed, abused its coding tool Claude Code to attack roughly 30 organizations. According to Anthropic, the attackers automated 80 to 90 percent of the attack process, including reconnaissance of target systems, vulnerability exploitation, credential theft, lateral movement within networks, and data collection and exfiltration. Rather than simply suggesting hacking methods, AI acted as an 'autonomous attacker,' independently deciding what to explore next and which vulnerabilities to exploit, and executing the attacks itself.
Rather than directly attacking customer-facing internet or mobile banking services, hackers used loosely authenticated satellite sites and internal business systems—such as employee systems and operational support systems—as detour routes to siphon off customer information. At Shinhan Bank, a loan-related inquiry service used by loan brokers became the attack route. Over an attack lasting about 30 hours, personal information of 25,727 customers—including names, phone numbers, annual income, and calculated loan limits—was leaked.
At KB Kookmin Bank, an attack lasting approximately 42 hours through 'RM Agent' and 'PB Agent,' mobile business support systems for employees, resulted in the leak of customer names, mobile phone numbers, addresses, and encrypted resident registration numbers. At Hana Bank, an external attack on its Sales Support System (ODS) leaked the personal information of 89 customers, while Busan Bank saw 11 cases of outsourced employee personal data leaked. Woori Bank and NH Nonghyup Bank were also targeted in hacking attacks, but no information leakage has been confirmed to date.
The attacks did not stop at commercial banks. Yesgaram Savings Bank disclosed that it discovered an unidentified hacker had accessed a server containing customer personal information on the 30th of last month. At Hyundai Capital, an attack on October 2 through a foreign IP address targeting a mortgage broker inquiry page was confirmed to have leaked the names, contact details, email addresses, and resident registration numbers of 146 loan brokers. the National Credit Union Federation of Korea blocked access attempts from the same IP as the Shinhan Bank attacker using its own security equipment, preventing any data leak. To date, no traces of the same attack have been found in the securities, insurance, or credit card sectors, nor at IBK Industrial Bank or the Export-Import Bank of Korea.
The Financial Services Commission and the Financial Supervisory Service will hold an emergency response meeting at the Seoul Government Complex on the afternoon of the 4th, convening CEOs from across the financial sector along with heads of industry associations. The meeting will be chaired by FSC Chairman Lee Eok-won, with FSS Governor Lee Chan-jin also in attendance. Authorities have ordered each financial company to complete internal security checks by the 5th.
