Financial firms told to complete security checks by Thursday, as regulators circulate 28 IP addresses linked to hacking attempts
South Korean police launched a full-scale investigation Tuesday into a series of suspected AI-assisted hacking attacks on financial institutions that exposed the personal information of tens of thousands of people.
The Korean National Police Agency assigned 28 investigators across four teams from its cyberterrorism investigation unit to the case.
President Lee Jae Myung called for a swift response in a Cabinet meeting Tuesday.
"We should accelerate the development and deployment of artificial intelligence technologies specialized in cybersecurity. It is time to overhaul our society’s security paradigm for the AI era," Lee said.
"Speed is of the essence," he said, warning that technological advances were outpacing efforts to counter emerging threats. He called for an immediate review of security across the nation’s critical systems and the necessary protective measures.
Police are also reviewing whether they must notify the newly established Serious Crimes Investigation Agency of the case.
They have asked the Financial Services Commission to determine whether the affected systems qualify as electronic financial infrastructure, a classification relevant to the notification requirement.
"We are awaiting the Financial Services Commission’s interpretation of whether the affected systems qualify as electronic financial infrastructure. As the agency is newly established, it will take some time to decide whether to notify and transfer the case," a police agency official told The Korea Herald.
The Serious Crimes Investigation Agency was launched Friday as part of reforms that abolished the prosecution service and separated investigative and prosecutorial powers. It investigates major crimes, while the newly established Public Prosecution Service handles indictments and prosecutions.
Meanwhile, the Financial Supervisory Service said Tuesday it had identified 28 distinct IP addresses — numeric designations that identify locations on the internet — linked to the hacking attempts and shared them with financial firms, asking them to complete internal checks and address security weaknesses by Thursday.
It cautioned that the IP addresses do not necessarily reveal where the attackers are based because connections may have been routed through other countries.
The breaches came to public attention in early October, with Shinhan Bank disclosing on Oct. 1 that information belonging to about 25,000 customers had been leaked.
By Sunday, breaches had been reported at seven financial institutions: Shinhan, KB Kookmin, Hana and BNK Busan banks, Yegaram and Welcome savings banks, as well as Hyundai Capital.
Reports put the combined exposure at about 66,000 individuals and 2,200 corporate records. Shinhan’s affected customer count stood at 25,729, while Yegaram Savings Bank reported about 40,000.
The exposed information included names and phone numbers and, in some cases, resident registration numbers, annual income and loan limits.
Woori Bank and NH NongHyup Bank also reportedly faced similar attacks, but no data leaks have been confirmed.
The attacks may have involved ARTEX, a tool that uses AI to identify security vulnerabilities, Kim Seung-joo, a professor at Korea University’s School of Cybersecurity, said in a CBS radio interview.
"AI hacking tools will continue to emerge, making it easier for nonexperts to carry out attacks," Kim said. "As a result, these attacks will become more frequent."
yunapark@heraldcorp.com


