Skip to content

South Korea investigates AI-linked data leaks at major banks

South Korean President Lee Jae Myung has ordered an investigation into widespread data leaks affecting the country’s financial sector. The Financial Services Commission (FSC) is leading efforts to address cyberattacks on major banks, with regulators suspecting the involvement of artificial intelligence and international threat actors.

Editor, Lazyfounder

Published 5 min read
South Korea investigates AI-linked data leaks at major banks
Image: South Korean president orders probe into data leaks across financial industry via source

South Korean President Lee Jae Myung has ordered an investigation into widespread data leaks affecting the country’s financial sector. The Financial Services Commission (FSC) is leading efforts to address cyberattacks on major banks, with regulators suspecting the involvement of artificial intelligence and international threat actors.

30 SEC SUMMARY

  • South Korean President Lee Jae Myung ordered a government investigation into data leaks at banks, finance companies, and public agencies.
  • The Financial Services Commission (FSC) held emergency meetings with financial institutions and regulators to address cyberattacks.
  • Major banks like Shinhan Bank, KB Kookmin Bank, Hana Bank, and Woori Bank reported breaches.
  • Authorities suspect artificial intelligence may have been used in the attacks, which originated from multiple countries.
  • The FSC directed financial institutions to strengthen cybersecurity measures and share threat intelligence.

TABLE OF CONTENTS

  • Government orders investigation into financial sector data leaks
  • AI suspected in cyberattacks; global IP addresses involved
  • Regulators push for stronger cybersecurity measures
  • Political calls for investigation into North Korean involvement
  • What this means
  • Key takeaways
  • FAQ
  • Sources

KEY HIGHLIGHTS

  • South Korean President Lee Jae Myung ordered a government investigation into data leaks at banks and financial institutions.
  • The Financial Services Commission (FSC) convened emergency meetings with regulators and executives from affected banks.
  • Shinhan Bank, KB Kookmin Bank, Hana Bank, and Woori Bank reported cyberattacks, with attack traffic traced to multiple countries.
  • Authorities suspect artificial intelligence may have been used in the attacks, which scanned multiple institutions for vulnerabilities.
  • The FSC directed financial institutions to strengthen cybersecurity measures and share threat intelligence.
  • The opposition People Power Party called for an investigation into potential North Korean involvement.

Government orders investigation into financial sector data leaks

South Korean President Lee Jae Myung has directed a thorough investigation into recent data leaks affecting banks, finance companies, and public agencies. According to Mint (Technology), the order follows a series of cyberattacks reported by major financial institutions, including Shinhan Bank, KB Kookmin Bank, Hana Bank, and Woori Bank.

The Financial Services Commission (FSC), led by Chairman Lee Eog-weon, convened an emergency meeting with financial industry associations, regulators, and executives from affected institutions. The meeting, originally scheduled for October 7, was moved up after additional breaches were discovered at second-tier financial institutions. Lee Eog-weon warned that the financial sector must respond with the highest level of vigilance.

AI suspected in cyberattacks; global IP addresses involved

Regulators could not rule out the possibility that artificial intelligence was used in the attacks. According to Mint (Technology), the attack traffic originated from IP addresses in multiple countries, including the United States, Japan, Singapore, Vietnam, and Britain.

The FSC believes the attacks may have scanned multiple financial companies for vulnerabilities rather than targeting a single institution. This suggests a coordinated effort to identify weak points across the sector.

Regulators push for stronger cybersecurity measures

Following the breaches, the FSC directed financial institutions to conduct comprehensive security inspections, tighten access controls, minimize external system access, and strengthen consumer protection measures. The commission also signaled broader upgrades to the financial sector’s cybersecurity framework.

To prevent further incidents, the FSC emphasized the need for rapid sharing of attack methods, internet protocol addresses, and other threat intelligence across the industry. On-site investigations were launched after Shinhan Bank reported a breach on September 30, with probes expanding to other reported incidents.

Political calls for investigation into North Korean involvement

The main opposition People Power Party has called for authorities to investigate the possibility of North Korean involvement in the cyberattacks. According to Mint (Technology), the party cited past cyberattacks attributed to Pyongyang against South Korean financial institutions as grounds for the inquiry.

What this means

Lazyfounder analysis — our interpretation, not reported fact.

This incident highlights the growing sophistication of cyber threats, particularly the potential use of AI to exploit vulnerabilities in financial systems. For founders and operators, it underscores the need for proactive cybersecurity measures, especially in industries handling sensitive data. The South Korean government’s response—rapid investigation, industry-wide coordination, and regulatory directives—serves as a template for how policymakers might address similar threats globally. Startups in fintech or AI should take note: compliance and security are no longer optional, and regulators are increasingly scrutinizing these areas. The involvement of international IP addresses also signals the borderless nature of cyber risks, requiring collaborations that extend beyond local jurisdictions.

Key takeaways

  • South Korea’s financial sector is under coordinated cyberattacks, prompting government intervention.
  • AI-driven cyber threats are a growing concern for regulators and financial institutions.
  • Regulators are pushing for industry-wide upgrades to cybersecurity frameworks and threat intelligence sharing.
  • The attacks appear to target multiple institutions, suggesting a broad scan for vulnerabilities rather than a single-point breach.
  • Opposition parties are urging investigations into potential state-sponsored cyber threats, adding geopolitical dimensions to the incident.

FAQ

Which financial institutions were affected by the cyberattacks?

Shinhan Bank, KB Kookmin Bank, Hana Bank, and Woori Bank reported cyberattacks. Second-tier financial institutions also experienced breaches.

Why do authorities suspect AI was used in the attacks?

Regulators could not rule out the use of artificial intelligence due to the sophistication and scale of the cyberattacks, which appeared to scan multiple institutions for vulnerabilities.

Where did the attack traffic originate?

Attack traffic was traced to IP addresses in the United States, Japan, Singapore, Vietnam, and Britain.

What measures is the FSC taking to address the breaches?

The FSC directed financial institutions to strengthen cybersecurity measures, conduct security inspections, tighten access controls, and share threat intelligence. The commission is also upgrading the sector’s cybersecurity framework.

Why is North Korea being linked to the cyberattacks?

The main opposition People Power Party called for an investigation into potential North Korean involvement, citing past cyberattacks attributed to Pyongyang against South Korean financial institutions.

Related on Lazyfounder

Sources

  1. Mint (Technology) · 2026-10-04
    South Korean president orders probe into data leaks across financial industry

This story is an original summary drafted with AI by Lazyfounder from the reporting listed above and checked by automated validation. Facts are attributed to their original publishers; sections marked as analysis are Lazyfounder's. Where a source is in another language, facts were machine-translated and quotations are reported, not reproduced. Read the original coverage via the links, and see our AI policy and corrections policy.

About the author

Editor, Lazyfounder

Tarun Mottlia edits LazyFounders, covering Indian startups, funding rounds, AI and product launches. Every story on the site is AI-assisted and checked against its cited sources before publication.

More stories by Tarun Mottlia

Get the LazyFounder Brief

Startup, funding and AI news in a five-minute read. Join the early-access list.

Lazy Founder - Powered by Blogy.in

Contact us

Have a story tip, correction or partnership idea?

Write to us at tarun.kumar@blogy.in or talk to the founder directly. We read every message.

Contact us