October 9, 2026, (Inside AI) — A wave of cyberattacks targeting financial institutions and major corporations in South Korea and Japan has exposed how artificial intelligence is dramatically lowering the technical barriers to entry for cybercriminals. Nine South Korean banks and two mega-churches are currently investigating breaches that may have involved AI-powered tools, while Japanese companies including Daiwa Securities, SoftBank Corp, and the Lawson convenience store chain have reported a sharp increase in security incidents.
The timing and scale of these attacks suggest a fundamental shift in the cyberthreat landscape. Japan recorded more cybersecurity incidents in the first nine months of 2026 than in all of 2025, according to data from TrendAI. September alone saw 86 incidents, representing an 18% increase from August and a 37% jump from July. South Korea reported 1,236 cyber incidents in the first half of the year, up 20% from the same period last year.
AI Tools Democratize Cybercrime Capabilities
Cybersecurity specialists say AI is enabling attackers to automate tasks ranging from scanning for software vulnerabilities to crafting sophisticated phishing campaigns. This automation makes cybercrime faster, cheaper, and significantly harder to detect.
"AI doesn't get tired... My view is that Japan is essentially being subjected to carpet bombing," said Nobuo Miwa, president of Tokyo-based cybersecurity firm S&J Corp.
The most striking example comes from South Korea, where US cybersecurity company CrowdStrike identified a suspected 26-year-old China-based attacker behind the bank incidents. According to CrowdStrike's assessment, this individual would probably not have been able to carry out such a campaign without AI assistance. The attacker reportedly used a Chinese-developed AI agent and Anthropic's Claude Code to conduct operations aimed at financial gain.
"While (the hacker's) capabilities were not terribly sophisticated they were effective," said Adam Meyers, CrowdStrike's senior vice president of counter adversary operations.
The implications extend beyond individual attackers. AI-powered tools are also making it harder for defenders to identify suspicious behavior in real time.
"With general-purpose AI models, even ordinary users with malicious intent can ask the system to look for vulnerabilities and it will do much of that work for them," said Choi Kyoungjin, director of the Center for AI, Data and Policy at Gachon University near Seoul.
Regulatory Response Accelerates Across Region
South Korean government data reveals a troubling shift in attack patterns. While server hacking cases declined, reports of distributed denial-of-service attacks rose 56.7% and ransomware incidents jumped 76.8% compared to the previous year.
Although the breaches have not yet resulted in material financial losses, analysts warn that risks could escalate if stolen data is weaponized in phishing or text-message "smishing" campaigns.
"We expect the incidents to result in regulatory penalties, customer compensation costs, and a sector-wide increase in cybersecurity spending," wrote Karen Wu, senior analyst at Fitch, in a research note.
Regulators in both countries have begun responding. South Korea's Financial Services Commission has directed financial industry associations, regulators, and affected executives to complete a 12-point cybersecurity self-assessment. In Japan, digital transformation minister Toshiharu Furukawa convened a meeting of ministries and agencies on Thursday following the recent attacks. The National Cybersecurity Office plans to issue warnings to businesses.
The warnings about AI's role in cybercrime are increasingly coming from the technology's own developers. Google and Anthropic have both issued alerts about AI-assisted attacks becoming more common globally.
"At this point, we can assume that all threat actors are using AI in some capacity and their operations have benefited," John Hultquist, chief analyst at Google's Threat Intelligence Group, said last month.
The attacks represent a threshold moment that has rendered many traditional security assumptions obsolete. Attackers have crossed a critical line in effort, motivation, and technical capability, while AI has largely erased language and other barriers that once hindered foreign hackers from operating in East Asian markets.
"The attackers have experienced a breakthrough that has rendered many of the old assumptions obsolete," Miwa said. "Our defences need their own breakthrough as well."
For financial institutions across the region, the path forward requires stronger security controls and more rigorous testing as AI capabilities continue to evolve. As Meyers noted, "The genie is out of the bottle, so to speak."