South Korea's financial regulators have issued a highest alert warning after a wave of cyberattacks on banks and other lenders. At least seven financial institutions have confirmed data leaks. Regulators say AI-powered hacking tools may have been used.
The Financial Services Commission (FSC) held an emergency meeting on October 4,2026, with chief executives and security heads of major banks and financial firms. Regulators had called in the executives on October 3 after the breaches came to light. FSC Chairman Lee Eog-weon said, "We cannot rule out the possibility that AI was used in the attacks." He added that the whole financial sector must recognize the gravity of the situation and remain on the highest alert.
According to reports, Shinhan Bank, KB Kookmin Bank, Hana Bank, BNK Busan Bank and Yegaram Savings Bank among those hit and some reports also mention Woori Bank and a capital firm. However, the full list has not been confirmed.
Estimates of the exposed data range from about 40,000 customers at one savings bank to more than 65,000 across the whole campaign. The data is reported to include personal details and loan information. These numbers are not yet verified.
The Financial Supervisory Service (FSS) has sent security guidance and a list of 28 malicious IP addresses to about 500 financial firms. It has ordered emergency checks and told firms to block outside access by default unless it is essential. Banks and card companies must finish their checks by October 6. Securities firms, insurers and savings banks have until October 8. Police have launched a major investigation.
Reports say traces of an AI hacking tool called Artex AI, also written ARTEX AI, were found in the attacks. It is described as an open-source system built on large language models that can scan for weak points and launch attacks with little human direction. This is not independently confirmed.
Lee said, "We must hurry to establish a security system that defends against AI attacks with AI." He was calling for automated, real-time defenses.
South Korea has one of the world's most digital banking systems, and a tool that automates attacks could let a small group hit many targets quickly. If several banks share the same weak spots, trouble at one firm can become a risk for the whole system.
Customers whose data was exposed face a higher risk of identity theft and fraud. Banks are expected to step up monitoring and may contact customers about possible scams.
Authorities have not said whether one group is behind all the attacks, or whether any money has been stolen with the leaked data.




