AI-Driven Hacking Causes Major Data Breach in South Korean Financial Sector

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

A hacking attack, presumed to have used AI, led to the leakage of sensitive personal data from major South Korean banks and public institutions. The incident raised concerns about AI-enabled phishing and potential further harm, prompting government calls for urgent security system overhauls and rapid investigation.[AI generated]

Why's our monitor labelling this an incident or hazard?

The event involves an AI system used in a hacking attack that has resulted in the leakage of personal information, which constitutes harm to individuals' privacy and rights. The AI's involvement is explicit and the harm has materialized, fulfilling the criteria for an AI Incident. The article focuses on the incident and its consequences rather than on responses or future risks alone, so it is not Complementary Information or an AI Hazard.[AI generated]
AI principles
Privacy & data governanceRobustness & digital security

Industries
Financial and insurance servicesGovernment, security, and defence

Affected stakeholders
General publicBusiness

Harm types
Human or fundamental rightsReputationalEconomic/Property

AI system task:
Content generation


Articles about this incident or hazard