
The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.
Multiple major South Korean banks, including Shinhan, KB Kookmin, Hana, and BNK Busan, suffered data breaches after coordinated hacking attacks using AI-powered automated tools. Sensitive personal information of thousands of customers and employees was leaked, raising concerns over AI-driven cyber threats and prompting emergency security responses from authorities.[AI generated]
Why's our monitor labelling this an incident or hazard?
The article explicitly mentions the use of AI-based hacking tools in the cyberattacks against major banks, which have directly resulted in the unauthorized access and leakage of sensitive personal information of thousands of customers. The AI system's use in automating and enhancing the hacking attempts is a direct contributing factor to the harm caused. The harm includes violations of privacy and data protection laws, which fall under violations of human rights and legal obligations. The attacks also targeted critical financial infrastructure systems, indicating disruption risks. Since the harm has already occurred and is directly linked to AI-enabled hacking, the event is classified as an AI Incident.[AI generated]