
Damage from artificial intelligence-driven hacking is spreading from commercial banks to the entire financial sector, including savings banks, capital firms and mutual credit cooperatives. Brokerages, insurers and credit card companies are conducting their own investigations, so further damage cannot be ruled out. Concerns over AI hacking are mounting, yet security awareness and investment across the financial industry remain low. The five largest financial holding companies posted record net profit of more than 20 trillion won last year, but spending on information protection at the five major banks fell 2.4% from a year earlier. That is why Financial Services Commission Chairman Lee Eok-won called for preemptive security investment, warning that "a single unmanaged gap can become the weak point of the entire security system."
This hacking episode is of a different order from past attacks that targeted specific financial firms. This time, AI was mobilized to strike multiple institutions simultaneously. The tool used was an AI-based hacking program developed in China, but the possibility cannot be ruled out that North Korea, which possesses world-class hacking capabilities, will target not only the financial system but also national infrastructure networks such as telecommunications, power and transportation. Without proper preparation, the country faces a dilemma in which the further AI adoption advances, the more exposed it becomes to AI-driven hacking.
The government must first move quickly to build a joint response system for the financial sector. Large financial companies have some capacity for security investment, but smaller firms struggle to secure the funding. If underinvestment leaves security holes at small and mid-sized financial companies, the damage will spread to the financial system as a whole. A firewall must be established so that malicious code and AI attack patterns identified at one financial company can be immediately detected and blocked by others. A joint recovery system is also urgently needed to keep core financial services such as payments, lending and deposits running in the event of a large-scale hack. The Bank of Korea's point that a "cyber stress test" is needed to verify the response capacity of the entire financial industry, not just simulation drills at individual companies, deserves attention.
Financial regulators are not free of responsibility either. They must move away from the practice of summoning financial companies after the damage is done to assign blame or impose penalties after the fact. Existing IT security rules have limits in countering attacks involving generative AI and AI agents, so the relevant regulations need to be overhauled promptly. This is a time for the public and private sectors to respond jointly, with a sense of urgency that the financial network itself could collapse.






