
It has been confirmed that the artificial intelligence (AI)-suspected hacking attacks that recently swept through the financial sector also occurred just one month ago. In late August, iM Bank was infiltrated up to its internal systems but managed to prevent information leakage through real-time response measures. Prior to this, financial authorities had demanded high-level AI-based vulnerability inspections from 10 financial companies subject to network separation regulation relaxation to prepare for hacking, and actual attack cases did occur, yet an information leakage incident ultimately took place. Criticism is emerging that complacency and inadequate responses within the financial sector were a primary cause of this incident.
According to industry sources on the 6th, commercial bank iM Bank detected in late August that external hacking forces had infiltrated its internal systems. While the suspected AI agent attacks and IP (Internet Protocol) addresses involved in recent incidents at seven financial companies differed, they were similar in that they utilized AI for hacking. iM Bank immediately shared attack information with the Financial Security Institute and launched joint response measures to block further infiltration and information leakage.
Subsequently, iM Bank took follow-up actions, including analyzing the attack path and vulnerabilities from the time and enhancing its security level. As a result, although AI-suspected hacking attacks continued to target the financial sector recently, no signs of infiltration were found at iM Bank. It is analyzed that experiencing a similar attack one month earlier and reinforcing vulnerabilities had a decisive impact in preventing actual damage.
In contrast, unlike iM Bank, KB Kookmin Bank, Shinhan Bank, Hana Bank, BNK Busan Bank, and others were helpless against attacks suspected to be carried out by AI agents at the end of last month, resulting in the leakage of customers’ personal credit information.
Notably, while financial authorities lifted network separation regulations in June, they required 10 financial companies that received non-objection letters to conduct AI-based vulnerability testing, but it was confirmed that a significant number of these companies failed to comply. Financial authorities had originally mandated that the 10th financial companies conduct high-level AI-utilized vulnerability testing by the end of July.

Unlike other financial institutions, these banks received an exception to network separation regulations and were granted authority for the first time to test internal vulnerabilities using external high-performance AI, such as by contracting with “Amazon Bedrock,” a fully managed enterprise generative AI service. Conducting proper vulnerability testing requires expensive tokens, necessitating substantial cost investment. Furthermore, even when vulnerabilities are discovered, there is insufficient security personnel available to immediately improve them, leading to delays in fulfilling obligations and procrastination.
Ultimately, financial authorities demanded the results of vulnerability tests last month. Although they initially planned to share the vulnerability inspection results from the 10th financial companies with second-phase network separation relaxation target companies, this did not proceed as planned. Amid this situation, information leakage incidents occurred at Shinhan Bank and Hana Bank, which were first-phase network separation relaxation targets.
A financial sector official pointed out, “Even if vulnerability testing could not fully encompass attacks on the ‘perimeter,’ which was the target of this AI hacking, the fact that the opportunity to inspect main programs using AI was missed clearly reveals the complacent security awareness of financial companies,” adding, “Taking this incident as an opportunity, proper AI-utilized vulnerability inspections must be conducted, even if it requires additional investment in personnel and costs.”