Forgotten Dairies
AI Hacks Banks. Customers Pay for Institutional Complacency, by Fransiscus Nanga Roka
When preventable failures cause harm, authorities should specify when customers must be notified, expedite support for fraud monitoring with the cost passed through to third parties, and make compensation procedures easily accessible. Transnationally, investigators require the capacity for rapid, lawful evidence preservation and infrastructure tracing on a scale used to manage cooperation among institutions. Instead of attribution, it may not be the language of a tool or the location of a server.
For a bank, it can protect its payment network, see to minimizing ever-growing fraudulent activities and still making people who would put their faith in it27 South Korea’s new attacks illustrate why a promise of core systems secure doesn’t provide much comfort to victims when criminals leave with data that can make their next fraud horrifyingly persuasive.
News on the attacks emerged in late September 2026. On October 2, the Financial Services Commission held an emergency meeting and ordered for firmer defenses, citing September 30 as when hackers broke into Shinhan Bank. Each of Korean lenders that were also hacked, including KB Kookmin and Hana.
This month, at Shinhan, some 25,000 customers’ information – names and telephone numbers as well as annual income and borrowing limits – was laid bare on an unsecured loan-recruiter service. They are deeply personal financial records and can provide swindlers with a tailored arsenal of data for cons.
October 6, President Lee Jae Myung said early signs that AI was a part of the bubble had been revealed and called for an immediate investigation. That qualification matters. The fact that AI could have played a role does not prove every intrusion was completely autonomous, took seconds, or bypassed encryption. The claims must be proved by investigators, backed up with forensic evidence.
However, the broader image is alarming. The Reporting alleged that Artex, which is an Open-Source Software (OSS) AI Security tool, was used against systems run by a third party. Seven financial firms said their user data had been compromised but reported no stolen funds. The entry points were seemingly more support services than core payment networks.
The strategic risk is simple: automation speeds up the hunt for unaddressed vulnerabilities, while siloed responsibility keeps those vulnerabilities from being remedied. A loan portal might seem like a side customer-facing solution on an org chart. It is the bank to a customer whose financial identity is exposed.
Outsourcing must never become an accountability escape hatch. Institutions gather data to evaluate borrowers, market products and earn income. This should be their responsibility to protect that information as they pass it down the service chain. The contractor that they chose, the access controls that were designed and the security budget were not made by customers.
The immediate theft is an opportunity cloak, too, hiding a predictable second wave. An income and borrowing limit aware fraudster can impersonate a reputable lender. With a cloned voice or fake executive video, stolen data becomes the shell for blackmail, identity theft and fraudulent payment instructions.
It is important for banks to maintain an urgent catalogue of each externally available service (including cloud usage, APIs, etc.) patches access rights and tracks aberrant data retrieval. Independent review of remediation should be mandated by regulators, bao platform for broker and sales system Until the payment network, companies which conduct security assessments are leaving customers outside of the perimeter.
Defensive AI can help in detection and investigation. They must exist under appropriate permission limits and recommendation mechanisms should be run through an audit process, particularly for disruptive actions that require human approval. Buying a second agent doesn’t make up for overaccess, missing systems or poor supervision.
When preventable failures cause harm, authorities should specify when customers must be notified, expedite support for fraud monitoring with the cost passed through to third parties, and make compensation procedures easily accessible. Transnationally, investigators require the capacity for rapid, lawful evidence preservation and infrastructure tracing on a scale used to manage cooperation among institutions. Instead of attribution, it may not be the language of a tool or the location of a server.
There should also be accountability for boards when breaches where deficiencies are recorded occur time and again. Cybersecurity spend needs to be measured on actual protection, not slides and compliance certificates.
The South Korea ominous advisory reaches well beyond Seoul: banks cannot brag about smart automation and classify customer protection like a sub-contract. If profit-bungs don’t get ported (or not all, or some) to customers, and instead institutions keep the profits while the risk is taken on by customers, then we’re in for deep trouble not least from a governance perspective.
Fransiscus Nanga Roka
Faculty of Law University 17 August 1945 Surabaya and managing Partner Law Firm Victorious Indonesia

You must be logged in to post a comment Login