At least 25,000 Shinhan Bank customers had their personal credit information leaked last week, according to reports. KB Kookmin Bank saw 99 customers and 20 current or former employees affected, while Hana Bank had 89 customers whose information was stolen.
The South Korean National Office of Investigation is looking into all three cases. President Lee Jae Myung commented on the incidents during a livestreamed cabinet meeting, saying there were signs that the hackers used AI models, "causing considerable public concern and anxiety." He added that "it's now become possible to use AI to hack with ease even without specialized skills" and instructed his cabinet to confirm the situation and minimise damage.
There is no indication yet of who is behind the attacks. Attribution is difficult, especially if the actors know how to cover their tracks. AI agents have also been known to conduct unintentional cyberattacks on their own; the Australian government recently reported that OpenAI took 84 days to inform it of an AI agent hacking a national health portal.
The incidents follow earlier examples of AI-orchestrated cyberattacks. In November 2025, Anthropic said it had foiled what it described as the first AI-orchestrated cyberattack originating from China. Months later, a cybersecurity firm reported that Taiwan was targeted by the first end-to-end autonomous cyberattack by China-linked hackers.
While leading AI labs are believed to put safeguards in place to prevent misuse, some hackers exploit model weaknesses such as hallucinations and prompt injection vulnerabilities.