
South Korea suspects AI in bank hacks. The evidence trail is still incomplete
Several South Korean financial firms reported cyberattacks and customer-information breaches. At a cabinet meeting, the country's president said signs had emerged that AI was used in some incidents and urged investigators to establish the circumstances quickly. That is a significant official warning, but it is not a public forensic report identifying a model, attacker, exploit chain or autonomous agent. Reuters says the Financial Supervisory Service shared 28 unique IP addresses linked to the recent attempts with the sector, while police opened an investigation. IP addresses can help defenders block and correlate activity; they do not by themselves prove AI involvement. The uncertainty matters for both security and public trust. If AI made reconnaissance, phishing or exploitation cheaper, banks may need to adapt detection and rate controls. If familiar tools and weak access controls explain the attacks, calling it an 'AI hack' too early could distract from the protections customers needed all along. South Korean regulators are pushing institutions to examine exposed systems and share indicators. Customers need a separate set of answers: what information was affected, whether accounts or credentials were exposed, what fraud monitoring is in place, and when they will be notified. There is no need to dismiss the AI hypothesis to insist on evidence. A technical timeline, reproducible indicators and an independent incident review would let defenders distinguish a new capability from conventional automation. Until then, the established story is that banks were hit and the AI role remains under investigation.



