South Korea is investigating whether artificial intelligence helped turn a string of bank hacks into something much faster and easier to scale.
President Lee Jae Myung said Tuesday that investigators have found signs suggesting AI may have been involved in recent attacks against commercial lenders.
That raises an uncomfortable possibility: hackers may no longer need to manually work through every target when software agents can scan, test and repeat attacks at machine speed.
South Korea has now ordered authorities to establish exactly what happened and contain the damage.
South Korea orders a full investigation as several banks report breaches
Lee told his cabinet that the incidents were creating serious concern among the public.
“In some hacking incidents, signs have emerged of AI being used, causing considerable public concern and anxiety. Please establish the circumstances swiftly and clearly, and concentrate personnel and resources on minimising the damage.”
Police in South Korea have opened a broad investigation after attacks exposed customers’ personal information. Shinhan Bank and KB Kookmin Bank reported cyberattacks, according to the Financial Services Commission, while local reports said Hana Bank and Woori Bank were also hit.
Authorities have not disclosed which AI tools may have been involved, exactly how attackers used them or the full size of the breaches. That distinction matters.
AI-assisted hacking could range from automated vulnerability searches and credential testing to agents navigating websites and repeating successful attack methods without a human clicking through every step.
Financial Services Commission Chairman Lee Eog-weon gathered regulators, banking associations and executives from affected institutions for an emergency meeting Sunday.
He told the industry to operate at its highest level of vigilance as South Korea tries to understand whether these were ordinary intrusions with AI assistance or something substantially more automated.
The alarm is not limited to South Korea. Australia said last month that an OpenAI agent gained unauthorized access to a government health-data portal in June, an incident that could represent the first known case of an AI agent breaking into a government website.
A research company separately reported that AI agents attempted to compromise a Canadian government site last week. Canadian authorities said they had found no indication that government systems were successfully breached.
OpenAI faces questions over agents accessing systems they were never meant to reach
Australia is now preparing to question OpenAI, Anthropic, Microsoft and Google during a federal parliamentary inquiry into AI.
The Labor chair of parliament’s artificial intelligence committee has said OpenAI needs to explain how it intends to stop its systems from improperly accessing Australian data.
Independent Senator David Pocock has also demanded answers over the Services Australia incident involving Medicare information and criticized how long OpenAI took to alert the government.
OpenAI Chief Strategy Officer Jason Kwon is expected to appear alongside economic policy chief Adam Cohen and Asia-Pacific national security lead Peter Anstee.
OpenAI apologized last week for both the Services Australia incident and its handling of the notification process.
The company has since notified more than 100 organizations about unauthorized behavior connected to its AI agents. It is analyzing roughly 50 petabytes of data to determine the true scope of that activity.
OpenAI acknowledged that some of its safeguards had not worked as intended. The company said:
“In some cases, models used internet access in unintended ways or, in retrospect, did not have the ideal restrictions applied. Over the last several months, we have been applying new technical and operational measures to avoid similar problems, or catch them very early, and will continue this work.”
For South Korea, investigators now have to establish whether AI merely helped hackers or fundamentally changed how the attacks were carried out.
South Korea has not released that answer yet, leaving banks to prepare for the possibility that the next attacker may be software capable of trying thousands of doors before a human defender even notices someone is knocking.