SBS NEWS

News > Society

Unaware Even After Hacking Ends... Did AI Find the Vulnerabilities?

Jeong Seong-jin

Published : Oct 3, 2026 11:04 PM

Video

[Anchor]

The problem is that despite such widespread hacking attacks, no one realized it in a timely manner. They targeted vulnerable security points, and it is suspected that artificial intelligence may have even designed the attacks themselves.

Reporter Jeong Seong-jin explains in detail.

[Reporter]

KB Kookmin Bank, where the personal information of 119 customers was leaked, first became aware of the incident at 7:00 PM on September 30.

This was already after the hacking attack had ended.

The hacking lasted for over 42 hours from 11:19 PM on September 27 until the evening of September 29, two days later, but it was only discovered 68 hours later.

Yegaram Savings Bank experienced its first hacking attack on September 18, but remained unaware of the hacking attempts for over 10 days.

As the hacking incident at Shinhan Bank, which resulted in the leak of personal information of some 25,000 people, became known and financial authorities launched a full-scale inspection, other financial companies also belatedly learned of their data leaks.

After sharing the 10 IP addresses that hacked Shinhan Bank with each financial institution for verification, it was revealed that Hana Bank and Hyundai Capital had also been attacked from the same IPs.

In the process, it was also confirmed that widespread hacking attempts had targeted Woori Bank and Nonghyup Bank as well.

Because the targets of the hacking were loan recruiter or employee systems rather than the main systems used by customers, security was weak and detection appears to have been difficult.

The security industry suspects that AI was not only utilized in the hacking, but that AI may have even designed the attacks targeting vulnerabilities.

Artex AI, which is presumed to have been used in this hacking, is an autonomous penetration testing tool. Experts suggest that an AI designed to patch security vulnerabilities was instead weaponized as a hacking tool, allowing it to precisely pinpoint vulnerable spots.

[Moon Jong-hyun / Director, Genians Security Center: "If you try to approach the main site directly, it is more likely to trigger monitoring. Therefore, there may have been an AI collection phase that gathered information in advance to target areas where security could be weaker or slightly more vulnerable..."]

With AI-based hacking attacks emerging as a realistic threat, experts point out that a comprehensive overhaul of security systems is necessary, extending beyond core computing networks to peripheral business systems.

(Video edited by: Choi Hye-ran, Design: Kang Yoon-jung, Kim Ye-ji, Seo Seung-hyun)