In early October, South Korea's financial sector suffered a string of intrusions: systems at several banks were breached with data leaks, hitting Shinhan Bank, KEB Hana and others. On October 6 President Lee Jae-myung demanded a thorough investigation and called for a cyber-defense framework against AI attacks — putting "AI involvement" into presidential language and lifting the incident beyond an ordinary security breach.
Attribution: Clues Left in AI Coding-Tool Sessions
A threat-hunting report from CrowdStrike became the focal point. Cited by Korean tech media, it assessed the attacker as a likely Chinese-language user with possibly profit-driven motives; subsequent reporting by Yonhap and Asia Economy said the suspect is believed to be a 26-year-old man living in Guangdong, China — with part of the locating evidence coming from sessions left by AI coding tools used in the attacks. The Wall Street Journal's Chinese edition commented that hackers weaponizing AI tools exposes systemic risk across finance.
Multi-Source Facts at a Glance
· Lianhe Zaobao: consecutive breaches across Korean finance, with "autonomous AI penetration tools" surfacing.
· CrowdStrike report (via Korean media): attacker likely a Chinese-language user, motive possibly profit; multiple mainstream AI tools reportedly used during the attacks.
· Yonhap / Asia Daily: suspect believed to be a 26-year-old based in Guangdong; President Lee demanded a probe and an AI-attack defense system.
Why AI Makes Attacks "Cheaper"
Compared with traditional kill chains, large models slash the barrier to intrusion: reconnaissance, vulnerability analysis, phishing copy and malicious scripting can all be delegated to AI, so attackers no longer need to master every technical step. What Zaobao calls "autonomous AI penetration tools" implies parts of the chain may already run semi-automatically. A Chosun Ilbo editorial went further: AI hackers now pose an all-around threat to the financial sector and a serious security problem.
Finance being hit first is no accident: banks hold high-value data and money rails, so intrusion pays far more than elsewhere; institutions are densely interconnected, letting one failed link propagate through clearing and payment networks into systemic risk; and strict regulation multiplies the reputational and compliance cost — making finance the ideal proving ground for AI-powered attacks.
The Defense Side Is Signaling Too
Tellingly, markets reacted: CrowdStrike's CEO said traditional tools are no longer sufficient against AI-driven threats, and the stock jumped more than 20% (Cailianshe). Capital is pricing an "AI offense-defense arms race." For enterprises and governments the lesson is that beyond perimeter defense they need AI-era depth: auditing of agent behavior, real-time detection of anomalous sessions, and fine-grained control over data egress.
In NineZenith's finance and government practice, the TianDun intelligent security stack pairs AI operation audit trails with least-privilege principles — precisely for the new normal where attackers also use AI. (Information synthesized from Lianhe Zaobao, WSJ Chinese, Yonhap, Cailianshe and other public reports)