Cyberattacks using AI agents against several of the largest South Korean banks, including Hana Bank, KB Kookmin Bank, and Shinhan Bank, are currently being investigated by South Korean authorities. According to The New York Times, at least 25,000 Shinhan Bank customers had their personal credit information leaked last week, while 99 customers and 20 current or former employees of Kookmin Bank have been affected. 89 Hana Bank customers were also affected by the hacks, which led to their information being stolen.South Korea’s National Office of Investigation is looking at all three cases, which has also caught the attention of President Lee Jae Myung. The South Korean president said that there were signs that the hackers behind these incidents used AI models, “causing considerable public concern and anxiety,” and that he has instructed his cabinet to confirm the situation and to ensure that the damage from these incidents is minimized. “It’s now become possible to use AI to hack with ease even without specialized skills,” Lee said during the livestreamed cabinet meeting. AI models are becoming more powerful with every release, and bad actors are taking advantage of them to find weaknesses in secure systems and exploit them. Anthropic reported the first instance of an AI-orchestrated cyberattack in November 2025, which was allegedly orchestrated by a Chinese state-sponsored group. A few months after that, a cybersecurity firm said that Taiwan was targeted by the first-ever end-to-end autonomous cyberattacks by China-linked hackers. Even AI labs that built these AI models aren’t immune from the AI-powered hacks, as security researchers breached OpenAI using Claude and gained access to its internal codebase. There has been no indication yet of who’s behind the attacks on South Korea’s banking industry — speculation may focus on Seoul’s regional adversaries, but it can be difficult to trace and attribute hacks, especially if the actors know how to cover their tracks. Aside from that, AI agents are known to conduct unintentional cyberattacks on their own, with the Australian government complaining that it took OpenAI 84 days to inform it of a hacking incident involving Australia’s national health portal.While the leading AI labs are believed to be putting safeguards in place to help prevent their models from being used in illegal and unethical ways, some hackers exploit hallucinations and trick AI agents into running malware. Aside from that, many open-weight and open-source models lack similar guardrails, making it easier for hackers to use them in their activities. While AI models haven’t replaced skilled attackers yet, they have made planning, reconnaissance, and attack execution so much easier and could serve as a force multiplier, allowing hackers to act more quickly and efficiently.