Local Chorus
Local news from local sources, read in your language.
Settled
Verified

Cyberattacks hit at least seven South Korean financial institutions; AI misuse suspected

🇯🇵 Japan 12:52 IT & software Business3 Tech updated 1 d ago first reported by 東京新聞

In short

At least seven South Korean financial institutions were hit by simultaneous cyberattacks, and about 68,000 items of personal information leaked, Kyodo reported. US security company CrowdStrike said the attackers used AI tools from US-based Anthropic and Chinese-linked AI tools, and that the attacks may have been financially motivated and carried out by Chinese speakers, Nikkei reported. President Lee Jae-myung has ordered countermeasures.

Read the full story 2 min read

At least seven South Korean financial institutions were hit by simultaneous cyberattacks, and about 68,000 items of personal information leaked, Kyodo reported from Seoul in an article carried by Tokyo Shimbun. Citing South Korean media, Kyodo said an AI agent, an AI that searches systems for vulnerabilities on its own and examines attack routes, may have been misused. [ 3 ]

According to the reports, unauthorized access was confirmed one after another from the end of September at financial institutions including major South Korean banks. At Shinhan Bank, where the damage first came to light, data on about 25,000 people leaked, including names, phone numbers, annual income and loan limits. [ 3 ]

US security company CrowdStrike on the 7th published an investigation saying that the attackers in the cyberattacks on South Korean financial institutions since September used AI tools from US-based Anthropic as well as Chinese-linked AI tools, Nikkei reported. The company said the attacks may have been carried out by Chinese speakers for financial gain. [ 1 ]

Kyodo reported that traces of a Chinese-linked AI agent were found on servers believed to have been used in the attacks, and that there is a strong view that the same perpetrator was behind them. A US cybersecurity company said in an analysis that a 26-year-old man living in Guangdong province, China, may have been involved. However, according to South Korean media, the man denies involvement, and details are unclear, Kyodo said. [ 3 ]

President Lee Jae-myung on the 6th ordered countermeasures, saying that the public's concern and anxiety are great, according to Kyodo. [ 3 ]

The reports differ in some details. Nikkei, citing CrowdStrike, names Anthropic's tools alongside Chinese-linked tools and dates the attacks from September, while Kyodo mentions traces of a Chinese-linked AI agent, dates the unauthorized access from the end of September and does not name the US company behind the analysis. Nishi-Nippon Shimbun carried the story under a headline saying cyberattacks are frequent in South Korea too, targeting financial institutions, with AI misuse suspected. [ 1 , 2 , 3 ]

Why it matters

According to Kyodo, the leaked data includes names, phone numbers, annual income and loan limits, and the attacks hit institutions including major banks. The reports say AI tools, including an AI agent that looks for system vulnerabilities on its own, may have been misused in the attacks. Business outlets in Japan covered the case, with headlines noting that cyberattacks are frequent in South Korea too.

Key facts

  • At least seven South Korean financial institutions were hit by simultaneous cyberattacks, Kyodo reported. [ 3 ]
  • About 68,000 items of personal information leaked, according to Kyodo. [ 3 ]
  • At Shinhan Bank, where the damage first came to light, data on about 25,000 people leaked, including names, phone numbers, annual income and loan limits. [ 3 ]
  • CrowdStrike published an investigation on the 7th saying the attackers used AI tools from Anthropic and Chinese-linked AI tools, Nikkei reported. [ 1 ]
  • CrowdStrike said the attacks may have been carried out by Chinese speakers for financial gain. [ 1 ]
  • A US cybersecurity company said a 26-year-old man living in Guangdong province, China, may have been involved; South Korean media say the man denies involvement. [ 3 ]
  • President Lee Jae-myung ordered countermeasures on the 6th. [ 3 ]

Confirmed by several sources

  • Financial institutions in South Korea were targeted by cyberattacks in which misuse of AI is suspected. [ 1 , 2 , 3 ]
  • A US security company's analysis points to a possible link to China. [ 1 , 3 ]

Still unclear

  • Who carried out the attacks. A US cybersecurity company named a possible role for a 26-year-old man in Guangdong province, but South Korean media report he denies involvement, and Kyodo says details are unclear.
  • Whether Anthropic's AI tools were used. Only Nikkei, citing CrowdStrike, mentions Anthropic; Kyodo's report mentions only traces of a Chinese-linked AI agent.
  • When the attacks began. Nikkei says the attacks began in September; Kyodo says unauthorized access was confirmed from the end of September.
  • Whether the US cybersecurity company cited by Kyodo is CrowdStrike. Kyodo's report does not name the company.
  • Which financial institutions besides Shinhan Bank were affected. The documents do not name the other institutions.

What local media are saying

Business mediaJapanese business outlets focused on the scale of the data leak, the suspected misuse of AI agents and tools, a US security company's findings pointing to Chinese-linked actors, and President Lee's order for countermeasures. [ 1 , 2 , 3 ]

Timeline, local time

  1. Nikkei reports CrowdStrike's findings that the attackers used AI tools from Anthropic and Chinese-linked AI tools. [ 1 ]
  2. Nishi-Nippon Shimbun runs a headline saying cyberattacks are frequent in South Korea too, targeting financial institutions, with AI misuse suspected. [ 2 ]
  3. Tokyo Shimbun carries Kyodo's report on attacks on at least seven financial institutions and the leak of about 68,000 records. [ 3 ]