October 6, 2026, (Inside AI) — South Korean President Lee Jae Myung told a cabinet meeting on Tuesday that artificial intelligence models are believed to have played a role in recent cyberattacks targeting the country's banks, and he urged the government to build cybersecurity defenses designed for the AI era.
The disclosure marks one of the first times a sitting head of state has publicly tied AI tools to a live financial-sector intrusion. It also raises fresh questions about how banks detect and stop attacks that can adapt faster than conventional defenses.
Lee did not name the affected lenders or say how many incidents occurred. He said the government is investigating the breaches and would coordinate with financial regulators and police.
"AI models are believed to have been used in some recent hacking incidents against banks," Lee said, according to an official account of the meeting. "We need to develop cybersecurity methods suited to the AI era."
Read: India's AI Cyber Threat Gap Widens as Autonomous Attacks Rise
The president's remarks came during a broader discussion of national digital security. He ordered agencies to review current safeguards and propose upgrades, according to sources familiar with the meeting who spoke on condition of anonymity because the discussions were private.
The Attack Surface Is Shifting Fast
Security researchers have warned for years that generative AI could lower the cost and raise the speed of cyberattacks. Large language models can draft convincing phishing emails, generate malware variants, and probe systems for weaknesses at scale.
South Korea's financial sector is a frequent target. The country's Financial Security Institute reported a rise in attempted intrusions on banking networks in 2025, though it did not attribute those attempts to AI. The latest incidents, if confirmed, would represent a shift from automated scripts to adaptive, model-driven attacks.
AI-driven attacks differ from traditional hacking in one key way: they can learn from failed attempts and adjust in real time. That makes static defenses, such as fixed firewall rules and signature-based detection, less effective. Banks typically rely on layered security, but few have deployed AI-native defenses at scale.
Lee's call for AI-era cybersecurity echoes similar moves in other countries. The European Union has begun drafting guidance on AI-enabled threats under its AI Act. The U.S. Cybersecurity and Infrastructure Security Agency has issued advisories on adversarial use of AI, though it has not confirmed a major bank breach tied to the technology.
Read: OpenAI and 100 Others Warn Window to Defend Against AI Attacks Is Narrowing
South Korea has its own framework. The AI Basic Act, passed in 2025, includes provisions on high-impact AI systems, but it focuses more on transparency and accountability than on offensive AI threats. Lee's comments suggest the government may push for new rules or funding specifically for AI-era defense.
The president's statement also puts pressure on banks to disclose more. Under current South Korean law, financial firms must report breaches to regulators within 24 hours, but public disclosure timelines are looser. That gap can leave customers unaware of risks for weeks.
Industry groups have not yet responded publicly to Lee's remarks. A spokesperson for the Korea Federation of Banks declined to comment, saying the matter is under investigation. Inside AI could not independently verify which banks were targeted or whether the AI models were used offensively or as part of the attackers' toolkit.
Defense Must Learn As Fast As Attack
Cybersecurity experts say the answer is not to ban AI but to fight fire with fire. Banks are already testing AI-based threat detection that flags unusual transaction patterns or login behavior. But those systems often run on older data and struggle against novel attack methods.
"If attackers are using AI to probe and adapt, defenders need AI that can do the same, and they need it in real time," said Kim Soo-yeon, a cybersecurity researcher at KAIST, who was not involved in the government probe. "Most banks are not there yet."
The cost of upgrading is significant. A full AI-native security stack can run into millions of dollars for large banks, and smaller institutions may lag. That creates a two-tier system where well-funded banks harden faster than community lenders.
Lee's remarks may accelerate a shift already underway. South Korea's financial regulators have been piloting AI-based monitoring tools since 2024. The Financial Services Commission has not said whether those pilots will be expanded or made mandatory.
For now, the investigation continues. Lee said the government would share findings when ready. He also called for international cooperation, noting that cyberattacks often cross borders.
The broader lesson may be simpler. AI is no longer just a tool for productivity or customer service. It is now part of the threat landscape, and the defense has to keep pace.