South Korean banks and Japanese corporations are grappling with a wave of cyberattacks that experts attribute to the growing use of AI by hackers. These developments are driving urgent regulatory and cybersecurity responses as AI enables more frequent and sophisticated attacks with less technical expertise.
- AI tools accelerate cyberattacks by automating key attack steps.
- South Korea and Japan see significant rise in cyber incidents this year.
- Regulators and companies intensify cybersecurity efforts in response.
What happened
In recent months, multiple South Korean banks and large Japanese companies such as Daiwa Securities, SoftBank, and Lawson have experienced a surge in cyberattacks. These attacks have raised suspicions that AI-enabled tools were used to facilitate hacking efforts, from automating vulnerability searches to crafting sophisticated phishing campaigns. For instance, South Korea reported a 20% year-over-year increase in cyber incidents in the first half of 2026, with notable rises in DDoS and ransomware attacks.
Cybersecurity firms and authorities are still investigating the exact role AI played in these breaches. A notable case involves a suspected China-based attacker who leveraged Chinese-developed AI agents and Anthropic’s Claude Code to execute financial cybercrime campaigns against South Korean banks. Despite the relatively low technical sophistication of this actor, the AI assistance made the attacks effective and harder to detect.
Why it matters
The increasing use of AI in cybercrime lowers the technical barrier for attackers, enabling individuals with limited skills to conduct complex operations. This shift broadens the threat landscape significantly, making cyberattacks more frequent, faster to execute, and more challenging to mitigate. Experts warn this trend allows attackers to operate around the clock without fatigue and overcome language barriers that previously limited cross-border hacking.
As a result, financial institutions and corporations in South Korea and Japan face heightened risks of data breaches, financial losses, and reputational damage. Regulatory authorities expect these attacks to drive stricter cybersecurity compliance requirements, increased spending on security infrastructure, and potential penalties for affected organizations, underscoring the critical need for improved defenses.
What to watch next
Regulatory responses are accelerating in both countries. South Korea’s Financial Services Commission has mandated comprehensive cybersecurity self-assessments for financial entities, while Japan’s government is coordinating cross-agency efforts to issue warnings and strengthen protection. Companies will likely increase investments in AI-driven security technologies to counter the threat from AI-assisted attacks.
Industry observers anticipate a continuing wave of cyberattacks leveraging AI, with attackers refining tactics and evading detection. The development of new cybersecurity breakthroughs, possibly involving AI-based defense tools, will be critical to keep pace with evolving threats. Monitoring regulatory updates and corporate response strategies in the region will provide important insights into the future cybersecurity landscape.