AIO APEX

One attacker hit seven South Korean financial firms, and regulators suspect AI tools

Seoul Economic Daily
Share:
One attacker hit seven South Korean financial firms, and regulators suspect AI tools

Financial regulators in South Korea have convened an emergency sector-wide meeting after investigators linked intrusions at seven financial companies to a single attacker. The targets include three of the country's largest banks, Shinhan Bank, KB Kookmin Bank and Hana Bank, along with BNK Busan Bank, Yegaram Savings Bank, Welcome Savings Bank and the auto-finance arm Hyundai Capital. The meeting was held on October 4, and the Financial Services Commission and the Financial Supervisory Service are coordinating the response, as first reported by Seoul Economic Daily.

The case is notable less for its scale than for its method. Investigators say the same attacker repeatedly rotated IP addresses across eight countries, including South Korea, the United States, Japan, Hong Kong, Singapore, Vietnam, Thailand and the United Kingdom. Park Sang-won, head of the Financial Security Institute, said attackers appeared to have used AI tools to run automated intrusion campaigns. One detail reported by investigators is a Chinese-language string, which reads as the title of an autonomous penetration-testing console, found on a compromised web server. That is a lead, not an attribution, and investigators have not named a responsible group.

How the intrusions happened

Regulators identified three categories of weakness. The first was internal information-inquiry services that lacked proper identity verification. The second was employee support systems that had no device access controls and contained unpatched web vulnerabilities. The third was public-facing websites that were exploited through known flaws to install malicious code and steal customer log files. None of these are novel techniques. What is different is the speed and breadth: a single operator working through many targets in a short period, changing infrastructure each time one was blocked.

The compromised data reportedly came from auxiliary employee and loan-broker systems. Reports cite around 2,200 records of corporate representatives, including names, email addresses and phone numbers. Authorities say customer-facing services were not affected and have not reported financial losses so far.

What regulators are asking firms to do

The Financial Services Commission has asked roughly 500 financial firms to review their systems against the same three weaknesses, with staggered deadlines. Banks and card companies were given until October 6, and securities firms, insurers, savings banks and e-finance providers have until October 8. For firms outside this group, the lesson is the same: a known vulnerability on a public-facing system is now a realistic entry point for an automated attacker, and the window between disclosure and exploitation is shrinking.

Why the AI angle matters

AI-assisted intrusion has been a warning topic for years, but most public cases have involved attackers using language models to write phishing emails or code snippets. A case where investigators believe automation handled reconnaissance, exploitation and infrastructure rotation across multiple institutions would be a more concrete example. Investigators have not yet published a full technical timeline, so the AI role should be treated as a suspected factor, not a confirmed one, until the forensic report is released.

As Seoul Economic Daily reported, the emergency meeting followed the discovery of the shared IP addresses across incidents at institutions that had not previously been linked. Whether the regulators' staggered review deadlines are enough will depend on how many of the 500 firms have already patched the flaws involved.

Originally reported by Seoul Economic Daily. Read the original article for additional details.

View original source
Share: