AI-driven cyber threats hit South Korea and Japan as 9 banks face attacks, ransomware surges 76.8%

Reviewed byNidhi Govil

5 Sources

Share

South Korea and Japan are battling a wave of AI-driven cyber threats targeting banks and major corporations. Nine South Korean banks and companies like SoftBank Corp, Daiwa Securities, and Lawson face attacks as AI lowers the technical barrier for cybercriminals. Ransomware incidents jumped 76.8% while DDoS attacks rose 56.7% in South Korea's first half of 2026.

News article

AI Cybercrime Enables Less Skilled Attackers to Target Major Institutions

South Korea and Japan are confronting an alarming surge in cyberattacks as artificial intelligence tools democratize cybercrime, enabling even technically unsophisticated threat actors to launch effective campaigns

1

. Nine South Korean banks and two mega-churches are currently investigating breaches potentially involving AI-driven cyber threats, while Japanese financial institutions including Daiwa Securities, SoftBank Corp, and the Lawson convenience store chain have reported incidents in what cybersecurity experts describe as a relentless wave of attacks

2

.

The scale of the problem is stark. Japan recorded 86 cybersecurity incidents in September 2026 alone, representing an 18% increase from August and a 37% jump from July

3

. More troubling still, the country logged more incidents in the first nine months of 2026 than during all of 2025, according to data from TrendAI

1

. Nobuo Miwa, president of Tokyo-based cybersecurity firm S&J Corp, characterized the situation bluntly: "AI doesn't get tired... My view is that Japan is essentially being subjected to carpet bombing"

2

.

China-Based Attacker Used Anthropic's Claude Code in Bank Breaches

CrowdStrike's investigation into the South Korean bank incidents revealed how AI lowers bar for cybercriminals with limited expertise. The cybersecurity company identified a suspected 26-year-old China-based attacker who leveraged a Chinese-developed AI agent alongside Anthropic's Claude Code to execute the campaign

4

. "While (the hacker's) capabilities were not terribly sophisticated they were effective," explained Adam Meyers, CrowdStrike's senior vice president of counter adversary operations

1

. The individual, assessed to be pursuing financial gain, would probably not have been able to carry out the attacks without AI assistance, according to CrowdStrike

5

.

This case illustrates a critical shift in the threat landscape. AI tools are automating tasks from vulnerability scanning and phishing campaign creation to identifying software weaknesses, making cybercrime faster, cheaper, and harder to detect

3

. The technical barrier that once protected organizations has largely evaporated, with AI erasing language obstacles and other challenges that previously hindered foreign hackers

1

.

Ransomware and DDoS Attacks Spike Across South Korea

South Korea reported 1,236 cyber incidents in the first half of 2026, marking a 20% increase from the previous year

2

. While server hacking cases declined, ransomware and DDoS attacks surged dramatically. Reports of distributed denial-of-service attacks rose 56.7%, and ransomware incidents jumped 76.8%, according to government data

4

. These figures underscore how AI-powered tools are reshaping the cybercrime landscape, with attackers crossing new thresholds in "effort, motivation and technical capability," as Miwa noted

5

.

Choi Kyoungjin, director of the Center for AI, Data and Policy at Gachon University near Seoul, highlighted another concerning dimension: "With general-purpose AI models, even ordinary users with malicious intent can ask the system to look for vulnerabilities and it will do much of that work for them"

1

. This accessibility means cybersecurity experts now face adversaries who can leverage sophisticated capabilities without deep technical knowledge.

Financial Institutions Face Regulatory Penalties and Rising Costs

Although the breaches targeting financial institutions have not yet resulted in material financial losses, the risks are escalating

2

. Karen Wu, senior analyst at Fitch, warned that stolen data could fuel phishing or text-message "smishing" campaigns, amplifying the potential damage. "We expect the incidents to result in regulatory penalties, customer compensation costs, and a sector-wide increase in cybersecurity spending," Wu wrote

3

.

Meyers from CrowdStrike emphasized that the South Korean bank incidents underscore the need for stronger security controls and more rigorous testing as AI evolves. "The genie is out of the bottle, so to speak," he said

1

. The comment reflects a sobering reality: AI-assisted attacks are not a future threat but a present challenge demanding immediate action.

Tech Giants Warn All Threat Actors Now Use AI

Warnings about AI's expanding role in cybercrime are increasingly coming from the technology's own developers. Both Alphabet's Google and Anthropic have cautioned that AI-assisted attacks are becoming more common globally

5

. John Hultquist, chief analyst at Google's Threat Intelligence Group, stated last month: "At this point, we can assume that all threat actors are using AI in some capacity and their operations have benefited"

2

.

This assessment carries significant implications for defenders. AI-powered tools are making it harder to distinguish malicious behavior from legitimate activity, creating detection challenges that compound the volume problem

4

. Organizations must now assume adversaries have AI capabilities and adjust their defensive postures accordingly.

Regulatory Responses and Cybersecurity Assessments Underway

Regulators in both countries have initiated responses to the crisis. South Korea's Financial Services Commission has directed financial industry associations, regulators, and affected executives to complete a 12-point cybersecurity self-assessment

1

. In Japan, digital transformation minister Toshiharu Furukawa convened a meeting of ministries and agencies following the recent attacks, with the National Cybersecurity Office planning to issue warnings to businesses

3

.

Yet Miwa expects elevated levels of cyberattacks to persist. "The attackers have experienced a breakthrough that has rendered many of the old assumptions obsolete," he said. "Our defences need their own breakthrough as well"

5

. This call for defensive breakthroughs highlights the asymmetry currently favoring attackers and the urgent need for security innovation to match the offensive capabilities AI has unlocked.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved