Three of South Korea's biggest banks got hacked, and investigators think an AI agent did the legwork.
Shinhan Bank confirmed a breach that exposed personal credit information for roughly 25,000 customers last week. KB Kookmin Bank said 99 customers and 20 current or former employees were affected, while Hana Bank reported 89 customers hit. South Korea's National Office of Investigation is now examining all three cases. President Lee Jae Myung told a livestreamed cabinet meeting there are signs the attackers used AI models, and ordered ministers to confirm what happened and contain the damage.
Lee's own framing is the real story here: AI has lowered the skill floor for hacking enough that a head of state is saying so on camera. It also fits a pattern - Anthropic disclosed an AI-orchestrated attack by a Chinese state-sponsored group in November 2025, and researchers later linked a wave of fully autonomous attacks on Taiwan to China-linked hackers. No one has attributed the Korean bank intrusions to a specific actor yet, and attribution for AI-assisted attacks is notoriously hard to pin down.
Call it a trend, not an anomaly: even OpenAI has been breached by researchers wielding Claude, and open-weight models without safety guardrails make this kind of automation available to basically anyone willing to read the docs.