AI-assisted cyberattacks have struck major South Korean institutions, compromising data from megachurches and financial firms in a series of breaches that have prompted emergency inspections and renewed warnings about machine-speed hacking.
Yoido Full Gospel Church in Seoul, once recognized by Guinness as the world's largest congregation, said Wednesday that personal data tied to 850,000 members may have been stolen. The compromised information includes names, dates of birth and a log of record changes. The church said the exposed file contained 2,629 changes to resident registration numbers, 3,964 changes to phone numbers and 7,202 changes to addresses.
South Korea's internet security agency, KISA, flagged the suspected breach to the church on Tuesday afternoon. The church then blocked outside access to its systems, changed server passwords and began notifying members. It also plans to replace its firewall and bring in security firms to hunt for additional weaknesses.
Cybersecurity company Oasis Security found the data on an overseas server alongside attack logs and account details linked to Yoido and a second Seoul megachurch, Sarang Church. Sarang reportedly lost about 89,000 member records and 286 employee records, including the senior pastor's data. Logs suggest that theft occurred in August, and the church has formed an emergency task force and reported the incident to authorities.
The breach logs contained signs of AI sub-agents, or helper programs launched by an AI model to handle separate parts of a job, along with long attack reports that appear machine-written. President Lee Jae Myung confirmed Tuesday that AI is believed to have been used in recent hacks on South Korean commercial banks.
An investigation by CrowdStrike released October 7 found attackers left behind Claude Code session records, memory files and configurations related to ARTEX, an open-source penetration-testing tool developed in China. CrowdStrike said hackers used ARTEX together with large language models from late September into early October. The firm could not identify the group responsible, but assessed with moderate confidence that the attacker was Chinese-speaking and motivated by financial gain, with no indications of state involvement.
Among the affected financial institutions, Shinhan Bank reported 25,727 compromised records, while KB Kookmin reported 119, Hana 89 and BNK Busan 11 outsourced developers. Yegaram Savings Bank notified about 40,000 affected customers, Welcome Savings Bank reported 2,200 corporate record breaches and Hyundai Capital reported 146 loan agents affected. Detection times varied sharply: Shinhan detected the intrusion within 15 hours, Hana needed almost 42 hours, and KB Kookmin detected the breach in 68 hours.
South Korea's government cancelled plans to expand exemptions from network-separation rules. At an October 4 meeting, Financial Services Commission Chairman Lee Eog-weon called for increased vigilance, and regulators ordered security inspections of around 500 companies. Reports indicated attackers used external services with lower protection levels rather than directly breaching core banking systems controlled by the banks.
The incidents fit a broader trend. An IMF report from June found AI-enabled adversary activity rose 89% between 2024 and 2025, with average breakout time falling to 29 minutes. BIS researchers warned that the window to detect and respond to attacks has narrowed dramatically, while a PwC survey found 84% of security and finance leaders expect larger cybersecurity budgets, though only 22% would allow AI to act fully autonomously in defense.
Although the breaches affected traditional financial and religious institutions rather than crypto platforms directly, they underline growing systemic concern about AI-powered cyber risk. No direct theft of bank funds or demonstrated financial contagion was reported, and no cryptocurrency token was directly implicated.