Hackers suspected of using AI agents for cyberattacks on South Korean banks, exposing data from about 25,000 customers

AI-rewritten: This is a summary of an article from Tom’s Hardware, rewritten by AI (Qwen, running locally) to make it easier to read. The facts come from the original article – read it for the full story.

Tom’s Hardware • Jowi Morales • October 6, 2026

South Korean authorities are investigating cyberattacks on major banks, including Hana Bank, KB Kookmin Bank, and Shinhan Bank. According to The New York Times, at least 25,000 customers of Shinhan Bank had their personal credit information leaked last week. Additionally, 99 customers and 20 employees of Kookmin Bank were affected, while 89 Hana Bank customers had their data stolen. President Lee Jae Myung noted that hackers appear to be using AI models, a development causing significant public anxiety. He stated that AI now allows hacking without specialized skills and ordered his cabinet to minimize the damage.

Experts explain that AI agents are increasingly powerful tools for bad actors to find system weaknesses. Anthropic reported the first AI-orchestrated cyberattack in November 2025, allegedly by a Chinese state-sponsored group. Shortly after, a cybersecurity firm claimed Taiwan was targeted by autonomous attacks from China-linked hackers. Even major AI labs have been breached; researchers gained access to OpenAI’s internal code using Claude. While no one has yet confirmed the source of the South Korean banking hacks, speculation points to regional adversaries.

The difficulty in tracing these attacks is compounded by the fact that AI agents can sometimes conduct unintentional self-harmful actions. The Australian government reported it took 84 days for OpenAI to inform them of a hacking incident involving Australia’s national health portal. Although leading AI labs are adding safeguards, many open-source models lack similar protections, making them easier to exploit via hallucinations or trickery. While AI has not replaced skilled attackers, it acts as a force multiplier, allowing hackers to plan, reconnoiter, and execute attacks more quickly and efficiently.

Source: Tom’s Hardware • Jowi Morales • October 6, 2026

Read the original article at Tom’s Hardware →

Leave Comment

Your email address will not be published. Required fields are marked *