Police are investigating attacks on South Korean commercial banks that exposed customers’ personal information. President Lee Jae Myung said signs of AI use had emerged in some recent bank hacking incidents, though authorities have not publicly identified the models, operators, attack methods, or how AI materially contributed to the intrusions. His statement remains an official preliminary assessment.
At a Cabinet meeting on October 6, 2026, Lee ordered officials to establish what happened quickly and direct personnel and resources toward limiting the damage. According to Reuters’ report carried by CNA, he also called for cybersecurity methods suited to the AI era.
“In some hacking incidents, signs have emerged of AI being used, causing considerable public concern and anxiety,” Lee said.
The breaches are more firmly established than the AI attribution. The investigation concerns multiple banks and suspected AI involvement; it has not demonstrated that autonomous AI systems broke into banks.
Multiple Banks Reported Attacks, but the Full Scope Is Unknown
South Korea’s Financial Services Commission said Shinhan Bank, KB Kookmin Bank, and other financial institutions had reported cyberattacks. Reuters also cited Yonhap reporting that Hana Bank and Woori Bank had suffered breaches.
The accounts do not establish an identical outcome at every institution. Reporting a cyberattack does not, by itself, establish that customer information was stolen. While the police investigation concerns attacks that led to personal-information breaches, the available account does not provide a complete bank-by-bank breakdown of successful intrusions, unsuccessful attempts, or the information exposed.
Authorities had not disclosed the full scale of the breaches in the October 6 report. There is no confirmed total of affected customers or records, detailed list of exposed data fields, or complete account of which systems were accessed.
The disclosed harm concerns personal information. The reporting does not establish that attackers stole deposits, initiated unauthorized transfers, or compromised banks’ payment infrastructure. A customer-data breach is serious on its own; describing it as the theft of customers’ money would go beyond the evidence.
Several institutions being affected also does not establish a single coordinated campaign. Investigators still need to determine whether the attacks shared an operator, vulnerability, or technique.





