top of page

South Korean Bank AI Defenses Race to Restore Trust After Cyberattacks

3 hours ago
11 min read

South Korean bank AI defenses are entering an urgent test after breaches exposed customer data and deposits fell by 20.1 trillion won in 11 days. The five largest lenders held 675.5 trillion won in demand deposits on September 30. By October 11, that total had fallen to 655.4 trillion won.

The timing creates a confidence problem, but it does not prove that frightened customers withdrew the entire amount. Deposit balances move for many reasons, including corporate payments, tax schedules, and transfers into higher-yield products. Fixed-term deposits also declined, weakening a simple explanation based on customers shifting money between account types.

The more consequential change is inside the banks. KB Kookmin, Shinhan, Hana, Woori, and NH NongHyup are expanding security budgets, hiring specialists, and testing AI-based defensive systems. Their challenge is no longer limited to blocking human hackers. They must defend scattered digital services against automated tools that can search for vulnerable entry points at machine speed.

That response creates the central tension. Banks want AI to identify weaknesses before attackers find them, yet the same automation can expand risk when deployed without tight controls. South Korea’s experience is becoming an early test of whether AI-assisted defense can restore trust faster than AI-assisted attacks can erode it.

The Deposit Drop Turned Breaches Into a Confidence Test

The most important number is not the breach count alone, but the 20.1 trillion won decline that followed the disclosures.

According to the initial deposit data, demand deposits at the five largest banks declined almost 3 percent between September 30 and October 11. Fixed-term deposits fell by more than 2.7 trillion won during the same period. They ended slightly above 1 quadrillion won after five consecutive months of growth.

Those figures appeared after several financial companies reported unauthorized access to customer information. Shinhan disclosed on October 1 that information belonging to about 25,000 customers had leaked. The exposed fields included names, telephone numbers, annual incomes, and loan limits.

KB Kookmin reported 119 affected customers the next day. Hana disclosed exposure involving 89 customers. Other incidents affected Busan Bank, two savings banks, and Hyundai Capital, taking the reported total beyond 67,000 people across seven companies.

The deposit movement should still be interpreted carefully. The available reports establish a sequence, not a complete causal link. Neither the banks nor regulators have published account-level data showing how much money customers withdrew because of the breaches.

That distinction matters because calling the decline a bank run would exceed the evidence. There were no reports that customers lost access to deposits or that core payment systems stopped operating. Authorities also said they had not found evidence that the exposed data could directly authorize payments.

Yet confidence can weaken before a conventional bank run begins. Customers do not need to believe their money has already disappeared. They only need to question whether a bank understands the breach, controls its external systems, and can prevent convincing follow-up scams.

Demand deposits are especially sensitive because customers can move them quickly. A sudden balance decline therefore creates a visible pressure point, even if seasonal flows explain part of it. Banks must show that their security response addresses the actual route attackers used.

The timing also changes how executives must communicate. A narrow disclosure about affected records no longer settles the issue once balances start falling. Customers will judge whether management can protect every service carrying trusted bank data, not only the transaction system.

That is why the incident has moved beyond a privacy notification. It is now a test of whether security investment can defend institutional trust.

South Korean Bank AI Defenses Target the Weakest Systems

South Korean bank AI defenses are shifting from perimeter protection toward continuous testing of the smaller systems surrounding core banking networks.

The reported attackers did not break directly into the most protected transaction platforms. They targeted peripheral services used by employees, contractors, and loan agents. These systems can hold sensitive customer information without receiving the same protection as a bank’s central ledger.

At Shinhan, reports identified a loan-progress inquiry service used by loan brokers as one compromised point. At KB Kookmin, attackers reportedly reached an internal mobile work-support system. This pattern reveals why large security budgets did not prevent the disclosures.

A bank can heavily protect its central network while leaving hundreds of smaller web applications exposed. Each contractor portal, internal dashboard, and sales tool creates another authentication process. It also creates another software stack that needs testing, monitoring, and timely updates.

Attackers can automate that discovery work. An AI agent, meaning software that selects and performs steps toward a goal, can scan services and adjust its next action. It can repeat those steps across many targets without requiring continuous human direction.

Woori Bank is already using Xint, an AI-based security testing product developed by Korean cybersecurity company Theori. The system generates attack scenarios and performs penetration tests, which are controlled attempts to identify exploitable weaknesses. Woori also uses internally developed tools.

KB Kookmin is testing defensive technology with several security companies, including Stealth Solution. Its ethical hackers are evaluating active defense systems against different AI-assisted attack patterns. Ethical hackers operate with authorization to expose weaknesses before criminals exploit them.

NH NongHyup plans to introduce an AI red-teaming system during the second half of 2027. Red teaming simulates an adversary to test systems, data, and organizational responses. The bank’s planned platform will examine AI models and services from an attacker’s perspective.

Hana is developing real-time responses for hacking attempts against devices and servers. It is also pursuing automated penetration testing and AI-based cybersecurity platforms. These projects reflect a common objective: shorten the gap between a weakness appearing and defenders finding it.

The banks are increasing conventional resources alongside automation. KB Kookmin plans to raise its 2027 information security budget above 100 billion won. Its 2026 budget was 86.07 billion won, according to banking industry figures.

Shinhan says its next security budget will be the industry’s highest, although it has not disclosed an amount. Woori is considering an increase exceeding 20 percent for security systems. It also expects to expand its specialist workforce by at least 10 percent.

These measures address speed and coverage, but spending alone cannot guarantee resilience. The critical question is whether banks apply those resources to the forgotten systems attackers actually probe.

AI Attack Automation Versus AI Defense Automation

The contest is not simply AI against AI, but scalable discovery against accountable control.

Attackers gain leverage when automation makes broad exploration inexpensive. They can inspect numerous internet-facing services, vary their inputs, and continue wherever a system responds unexpectedly. A single missed validation rule can become the opening they need.

Defenders face a harder constraint. They must protect legacy applications, partner connections, employee tools, and new digital products at the same time. They must also avoid disrupting legitimate banking activity while testing those systems.

This imbalance explains the interest in automated red teaming. A defensive agent can repeat attack scenarios across more applications than a small testing team can inspect manually. It can also rerun those scenarios after software changes, exposing regressions that a yearly audit might miss.

However, the defender remains responsible for every automated action. Security teams must restrict what a testing agent can reach, record its activity, and verify its findings. An uncontrolled defensive tool can interrupt services or expose sensitive information itself.

The attacks were reportedly associated with ARTEX, an open-source autonomous penetration-testing project. Investigators found traces connected to the tool on infrastructure believed to support the campaign. That evidence does not establish the attackers’ location, identity, or nationality.

Reports describe ARTEX as coordinating AI agents that gather information, identify vulnerabilities, and plan possible intrusion routes. Its developer, known publicly as Autumn-27, later stopped public updates. The developer said bad actors had abused the project.

Stopping updates does not remove copies already downloaded. It also cannot prevent another developer from building a similar system. The broader security problem therefore extends beyond one repository or one developer’s decision.

Open-source security software has legitimate uses. Researchers, internal defenders, and consultancies use shared testing tools to reproduce attacks and improve protection. Restricting access can slow some misuse, but it can also deny defenders the same methods.

The harder issue involves operational controls. A responsible organization can require authorization, isolate testing environments, limit credentials, and preserve detailed logs. A malicious operator can remove those safeguards and direct the same capabilities toward public targets.

That tradeoff makes attribution especially important. The presence of Chinese-language software does not prove Chinese government involvement or even a China-based attacker. Investigators identified network addresses across multiple countries, while acknowledging that attackers can route traffic through third-party infrastructure.

The technical investigation also indicated similar addresses across attacks against banks. Similar infrastructure can support a connection between incidents, but it does not identify the human operator behind them.

AI can complicate the picture further. An attacker can combine a public agent with commercial models, stolen credentials, scripts, and rented servers. Describing the entire campaign as an AI attack risks hiding the ordinary control failures that made access possible.

The defensive lesson is concrete. Banks need automation because attackers can scale reconnaissance. They also need conventional authentication, access controls, patching, and application design because AI cannot compensate for weak foundations.

The Breaches Exposed a Peripheral-System Security Gap

The campaign appears to have succeeded where trusted business workflows met weaker authentication, not where banking technology was strongest.

Investigators and security specialists have pointed toward external or internal support services rather than core transaction platforms. These applications support real work, but they often sit outside the systems receiving the most intensive protection.

One reported technique involved sending many values to a loan-related service to discover valid customer identifiers. Once the service returned a useful response, an attacker could use that clue to request additional information. Automation makes this process faster and easier to repeat.

Credential stuffing may also have played a role. Credential stuffing uses usernames and passwords stolen elsewhere to attempt access on another service. The technique depends on password reuse and weak controls, not an entirely new class of AI capability.

Multifactor authentication can reduce that risk by requiring another form of proof. Rate limits can restrict repeated requests, while anomaly detection can flag unusual access patterns. Proper authorization checks can stop one user from retrieving another customer’s record.

These controls sound basic because they are basic. Their importance does not decline when attackers add AI. Automation increases the cost of leaving them inconsistent across dozens of applications.

The banks’ earlier security spending shows why totals can mislead. Shinhan, KB Kookmin, and Hana reportedly spent almost 124 billion won on information security during 2025. Yet the recent financial-sector breaches still reached less-protected services.

A budget can fund monitoring platforms, consultants, and defensive staff while gaps remain at a contractor portal. Security depends on where the money goes, how systems are inventoried, and whether findings are repaired promptly.

The leaked data also has value beyond direct account access. A criminal who knows a customer’s name, income, loan limit, and recent banking relationship can construct a persuasive message. That context can make a fraudulent loan call appear legitimate.

Financial Services Commission Chairman Lee Eog-weon said officials had no indication that directly usable payment information had leaked. He also warned that voice phishing and fraudulent text messages remained possible forms of secondary harm.

This is where the trust problem becomes personal. A bank can truthfully say that its core platform remained safe while customers still face convincing scams. Victims may not distinguish between a compromised transaction database and data taken from a loan-support system.

The institutional boundary matters less to someone receiving a call that includes private financial details. Customers reasonably associate that information with the bank, regardless of which application stored it.

Therefore, South Korean bank AI defenses cannot focus only on identifying malware. They must map where customer information travels, minimize unnecessary fields, and monitor every interface exposing those fields.

AI testing can help locate these paths, but remediation remains a management task. Someone must own each application, assess each finding, and close the weakness before the next automated scan.

Bigger Budgets Will Not Resolve the Verification Gap

The banks must improve defenses while investigators still lack conclusive proof about AI’s exact role in every breach.

Officials and news reports have repeatedly described the incidents as AI-assisted. Traces linked to ARTEX support that hypothesis. The speed, breadth, and apparent automation of the attacks also fit an agent-driven campaign.

However, public evidence does not yet reconstruct the full attack chain. It remains unclear which actions an AI model selected independently, which were scripted, and which required direct human control. Those distinctions matter when designing countermeasures.

If AI mainly accelerated reconnaissance, banks need broader attack-surface monitoring. If agents adapted exploitation steps during the intrusions, defenders need behavior-based controls that detect unusual sequences. If stolen credentials did most of the work, identity security deserves greater emphasis.

The answer may combine all three. Modern attackers rarely depend on a single technique. They assemble tools around whichever weakness produces results.

Authorities must also avoid premature geographic attribution. The Financial Supervisory Service identified addresses linked to 12 countries, but some locations remained unresolved. Separate reporting described 28 addresses across at least 12 countries.

A public tool’s language or origin does not identify its operator. Attackers routinely use virtual servers, compromised machines, and relays located far from their physical location. An independent international assessment likewise noted official caution around attribution.

There is another unresolved question around the deposit decline. The timing gives banks a reason to act quickly, but investigators have not shown that breach fears caused every transfer. Publishing more detailed flow data would help separate normal movement from a cybersecurity-driven confidence response.

Transparency can carry risks during an active investigation. Disclosing precise technical weaknesses can aid copycat attackers. Yet vague assurances can deepen suspicion if customers believe institutions are minimizing events.

Banks therefore need a disciplined disclosure model. They should explain which information was exposed, which systems were affected, and what customers should monitor. They should distinguish confirmed findings from hypotheses about tools and attackers.

They must also report whether promised improvements produce measurable results. A larger budget is an input, not an outcome. Head count and software purchases do not show whether critical flaws are being repaired faster.

Useful measures include the time needed to discover exposed services, close high-risk vulnerabilities, and disable compromised credentials. Banks can also measure whether red-team findings recur in later tests.

Regulators have a role in establishing comparable reporting. Without common measures, each institution can describe its program as advanced while customers cannot evaluate relative risk.

AI defense also introduces governance questions. Banks must decide which data their models can inspect, where test results are stored, and who can authorize simulated attacks. These rules need the same attention as model accuracy.

The global financial risk extends beyond isolated privacy incidents. Research published by the International Monetary Fund documents the growth of cyber events and digital fraud across finance. Connected services can transmit operational and confidence shocks between firms.

South Korea’s banks now have an opportunity to demonstrate a more credible model. That model requires verified findings, controlled automation, and evidence that remediation is improving. Branding every security project as AI will not meet that standard.

Three Signals Will Show Whether Trust Is Returning

The next phase should be judged by verified remediation, deposit stability, and evidence about the attack chain.

The first signal is what regulators disclose after their technical investigation. Investigators need to establish how attackers entered each organization and whether the same operator connected the incidents. They should also clarify the specific role of AI automation.

A detailed reconstruction would strengthen the case for agent-based defenses if it shows that software adapted across targets. A finding centered on reused credentials and weak validation would shift attention toward identity and application controls. Either result would give banks a clearer investment priority.

The second signal is whether deposit balances stabilize after disclosures and customer notifications. One short period does not establish a lasting confidence crisis. Continued declines, especially at affected institutions, would strengthen the link between cybersecurity and funding pressure.

A reversal would not make the breaches harmless. It would suggest that customers accepted the banks’ explanations or treated the movement as temporary. Transparent reporting will make that interpretation more credible.

The third signal is whether announced investments produce operational changes during 2027. KB Kookmin’s planned budget increase, Woori’s proposed spending and staffing growth, and NH NongHyup’s red-teaming system create specific commitments. Customers and regulators can track whether those projects arrive on schedule.

The strongest evidence will come from coverage and response time. Banks should show that peripheral applications receive the same continuous scrutiny as central systems. They should also demonstrate that automated findings move quickly into repair work.

This incident matters outside South Korea because most large organizations have the same structural weakness. Sensitive information spreads across customer portals, sales systems, mobile tools, and contractor services. Attackers only need the least protected path.

Knowledge workers also face a related challenge after an incident. Decisions, evidence, remediation tasks, and customer communications can fragment across documents and meetings. A controlled AI knowledge base can help teams preserve that context, although it cannot replace security controls.

South Korean bank AI defenses will succeed only if they improve the complete system around the models. That includes asset inventories, authentication, data minimization, testing, response, and public accountability.

The practical question for every organization is straightforward: can its defenders identify a forgotten service before an automated attacker does? Security leaders should map externally reachable systems, verify who owns them, and test how quickly critical findings become fixes. The banks’ next disclosures will reveal whether their AI spending is changing that equation or simply adding another layer of software.

Give every agent the context to do better work

Connect your agents to the knowledge, decisions, and history already organized in remio.

remio currently supports Windows 10+ (x64) and Macs with Apple silicon.

Your AI Partner at Work
Get more done with remio

Plan. Create. Deliver.
All in one place.

bottom of page