AI-Powered Cyberattacks Cause Data Breaches at South Korean Banks

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

A series of AI-powered cyberattacks targeted major South Korean banks, including Hyundai Capital, Shinhan Bank, KB Kookmin Bank, Hana Bank, and BNK Busan Bank, resulting in the exposure of sensitive personal data of thousands of customers and 146 housing loan recruiters. President Lee ordered a thorough investigation.[AI generated]

Why's our monitor labelling this an incident or hazard?

The article explicitly states that the personal information leak was caused by an information inquiry attack utilizing AI, indicating the AI system's involvement in the malicious use of the system. The harm is realized as personal data of 146 housing loan recruiters, including sensitive internal data, was leaked. This constitutes a violation of privacy and possibly labor rights, fitting the definition of harm under AI Incident (c). The incident involves the use and misuse of an AI system leading directly to harm, thus it is classified as an AI Incident.[AI generated]
AI principles
Privacy & data governanceRobustness & digital security

Industries
Financial and insurance services

Affected stakeholders
ConsumersWorkers

Harm types
Human or fundamental rights


Articles about this incident or hazard