South Korea and Japan investigate cyberattacks as experts assess AI’s role
Nine South Korean banks and two mega-churches are investigating attacks, while Japanese companies face a surge in incidents. AI’s involvement remains under investigation.
Nine South Korean banks and two mega-churches were investigating cyberattacks potentially involving artificial intelligence, while Japanese businesses faced a surge in incidents, Reuters reported on October 9. The attacks have prompted government responses in both countries and warnings about risks from stolen data, although authorities are still investigating whether and how AI was used in many breaches.
Japanese companies affected by recent cyber incidents include Daiwa Securities, SoftBank and convenience-store chain Lawson, according to the Reuters report published by CNA. The reporting does not establish that those incidents and the South Korean bank attacks formed a single coordinated campaign.
What links the South Korean bank attacks to AI
Cybersecurity company CrowdStrike assessed that a suspected 26-year-old attacker based in China probably could not have carried out the South Korean bank campaign without AI assistance. According to its account, reported by Reuters, the individual sought financial gain and used a Chinese-developed AI agent alongside Anthropic’s Claude Code.
That account remains CrowdStrike’s assessment. The reporting does not identify the suspect, establish a state-directed operation or provide a charge or court finding. Being based in China also does not establish the individual’s nationality.
Adam Meyers, CrowdStrike’s senior vice president of counter adversary operations, described the attacker’s capabilities as effective despite limited sophistication. He said the incidents demonstrated the need for stronger security controls and more rigorous testing as AI develops.
Specialists interviewed by Reuters said AI can automate work ranging from searching for software vulnerabilities to preparing phishing campaigns. Choi Kyoungjin, director of Gachon University’s Center for AI, Data and Policy, said general-purpose models could undertake much of the vulnerability-searching work for ordinary users with malicious intentions. He also warned that AI tools were making suspicious behaviour harder to detect.
Cyber incident figures show growth, not AI’s share
Japan recorded more cybersecurity incidents in the first nine months of 2026 than in all of 2025, according to TrendAI data cited by Reuters. Its September figure was 86 incidents, approximately 18 percent above August and 37 percent above July.
Those figures describe growth in the cited dataset, rather than an established count of every attack nationwide. The report provides neither full-year comparison totals nor detailed methodology, and the figures do not measure the proportion of incidents involving AI.
South Korean government data cited by Reuters recorded 1,236 cyber incidents in the first half of 2026, up 20 percent from a year earlier. Server-hacking cases fell, while reports of distributed denial-of-service attacks increased 56.7 percent and ransomware reports rose 76.8 percent. Those statistics cover a different period and reporting system from the Japanese figures.
Banks face data risks as governments respond
Reuters reported that the bank breaches had not yet resulted in material financial losses. Fitch senior analyst Karen Wu nevertheless warned that stolen information could create further risks through phishing or text-message ‘smishing’ campaigns. The reporting does not establish affected customer numbers or a complete inventory of stolen data.
Wu expected regulatory penalties, customer compensation costs and increased cybersecurity spending across the banking sector. Those were forecasts, rather than confirmation that penalties had been imposed or compensation paid.
South Korea’s Financial Services Commission directed financial-industry associations, regulators and affected executives to complete a 12-point cybersecurity self-assessment, Reuters reported. No completion deadline or results demonstrating improved security were established in the report.
In Japan, digital transformation minister Toshiharu Furukawa convened ministries and agencies on October 8 following the attacks. Reuters reported that the National Cybersecurity Office planned to warn businesses. Whether those measures will reduce attacks remains unestablished.
Anthropic’s earlier findings provide a separate precedent
In research published on August 27, 2025, Anthropic said it had disrupted a Claude Code-assisted theft and extortion operation targeting at least 17 organisations. Targets included healthcare, emergency services, government and religious institutions. Some ransom demands exceeded $500,000, the developer said; that does not establish that victims paid those amounts.
Anthropic said Claude Code helped automate reconnaissance, credential harvesting and network intrusion, and assisted decisions about stolen information and extortion demands. Its account provides earlier evidence from a developer about misuse of its own technology, but does not establish a connection to the current Korean or Japanese incidents.
The unresolved question in the current cases is how extensively attackers relied on AI in each breach. The Reuters reporting offers specialist assessments and aggregate incident figures, but no victim-by-victim technical findings that would establish AI’s contribution across the affected organisations.
Sources and context
- South Korea, Japan buffeted by hacks as AI lowers bar for cybercriminalsCNA / Reuters
- Detecting and countering misuse of AI: August 2025Anthropic
AI-assisted article checked against the listed sources. NewsJaws did not conduct interviews or attend the reported events.
About NewsJaws Desk
AI-assisted reporting and explainers reviewed against the linked source documents. No claim of on-scene reporting or original interviews.