South Korean President Lee Jae Myung said on Tuesday that artificial intelligence appears to have been used in a wave of cyberattacks on the country's financial sector, hacks that exposed user data at seven financial firms and prompted what one official described as "a completely new kind of crisis."
According to a report from the Financial Times, the president said indications of AI involvement in some of the incidents were "causing considerable public concern and anxiety." The remarks, reported by Reuters, the New York Times, and the Wall Street Journal among others, mark one of the most direct attributions yet by a head of state linking AI tools to live cyberattacks against banks. For more context on this story, see our ongoing latest AI developments.
What Happened in the South Korea Bank Hacks
The attackers appear to have targeted less secure systems operated by third parties rather than the banks' core payment networks, according to the Financial Times reporting. In one incident, a hacker bypassed identity checks on a portal where loan brokers monitored customers' applications, exposing the personal details of roughly 25,000 Shinhan Bank customers.
No stolen funds have been reported so far, but the scale of the data exposure has put South Korea's financial regulators on alert. An official with knowledge of the situation told the Financial Times the incidents represented "a completely new kind of crisis" for the country's banking industry.
"Generative AI was used to identify vulnerabilities and launch an attack," the president said, according to the report. "It's not that South Korea has weak cybersecurity — this sort of thing could happen anywhere."
The Role of Artex, an Open-Source AI Hacking Tool
Security researchers believe a specific tool may have been involved. Moon Jong-hyun, head of the Genians Security Center, said last week that it appears Artex — a Chinese-language, open-source tool that uses AI to find and test computer system vulnerabilities — had been employed in some of the attacks, the Financial Times reported.
In a LinkedIn post, Moon likened Artex to a kitchen knife: a tool that can be used by a chef to prepare a meal, or "as a weapon by a criminal." The analogy captures the dual-use dilemma that has surrounded open-source AI security tools since they began proliferating: the same capabilities that help defenders audit their own systems can lower the barrier to entry for attackers probing someone else's.
The Wall Street Journal, which also covered the story, framed the use of a Chinese-language AI tool against South Korean banks as exposing a new category of risk for financial institutions worldwide.
Why Third-Party Systems Were the Weak Point
A recurring theme in the reporting is that the compromised systems were not the banks' most hardened infrastructure. Instead, the attackers reportedly went after peripheral, less secure applications — such as the loan-broker portal — where identity verification and monitoring may be weaker.
That pattern is consistent with what cybersecurity professionals have warned about as AI-assisted attacks become more capable: automation does not necessarily break through the strongest defenses, but it can rapidly find and exploit the weakest link in a large attack surface. Vulnerability research that once required expensive human labor — mapping applications, inspecting documentation, understanding authentication flows, and repeatedly probing systems for unusual behavior — can now be partially automated.
South Korean officials have not said whether they attribute the attacks to any specific actor, and the investigation is ongoing. The president's office did not immediately announce new regulatory measures in connection with the remarks, though the incidents are likely to intensify scrutiny of how financial firms oversee the third-party applications that touch customer data.
A Test Case for AI Cybersecurity Policy
The South Korea bank hacks arrive amid a broader global debate over AI and cybercrime. Security researchers have documented AI agents being used to attempt attacks on government websites, and AI labs have published research on emergent cyber capabilities in frontier models — findings that have fueled calls for stronger safeguards around powerful AI systems.
What distinguishes the South Korean case is its official framing: a sitting president publicly attributing attacks on major banks to AI-assisted methods, and a national conversation about whether existing cybersecurity rules — built for human adversaries — are adequate for a world where an open-source tool can automate vulnerability discovery.
For banks and other regulated industries, the incident is a reminder that their security perimeter extends well beyond core systems to the vendors, brokers, and portals that surround them. For policymakers, it raises the question of whether dual-use AI tools like Artex should face any restrictions on distribution — or whether, as Moon's kitchen-knife analogy suggests, the focus should remain on how systems are defended rather than on the tools themselves.
As the investigation continues, attention will turn to whether South Korea introduces new disclosure requirements or security standards for third-party financial applications, and whether other governments follow suit in formally addressing AI's role in cybercrime.
---
Stay Ahead of AIGet the latest AI news, analysis, and breakthroughs — all in one place.
Read more AI news →