Skip to content

AI cyberattacks surge in South Korea and Japan as threats intensify

AI cyberattacks surge in South Korea and Japan as threats intensify
  • Nine South Korean banks and two megachurches are investigating suspected AI-linked cyberattacks, while Japanese companies including Daiwa Securities, SoftBank and Lawson face a surge in security incidents.
  • Japan recorded more cybersecurity incidents in the first nine months of 2026 than throughout 2025. South Korea reported 1,236 incidents in the first half, with ransomware cases rising 76.8%.
  • CrowdStrike identified a suspected China-based attacker who allegedly used AI tools to target South Korean banks, raising concerns about automated hacking, financial losses and increasing cybersecurity costs.

South Korean and Japanese companies are strengthening cybersecurity defenses following a wave of attacks that security specialists say demonstrates how artificial intelligence is making cybercrime more accessible to attackers with limited technical expertise.

Nine South Korean banks and two megachurches are investigating cyber incidents that may have involved AI tools. In Japan, major companies including Daiwa Securities, SoftBank and convenience store operator Lawson have been affected by a recent increase in cyberattacks, according to Bloomberg.

Investigators have yet to establish whether AI was used in many of the incidents or determine its precise role. Cybersecurity experts nevertheless warn that AI is allowing attackers to automate vulnerability scanning, develop phishing campaigns and conduct malicious operations with fewer resources, reducing costs and making suspicious activity harder to identify.

Japan recorded more cybersecurity incidents during the first nine months of 2026 than in the whole of 2025, according to TrendAI data. The monthly total reached 86 in September, an increase of approximately 18% from August and 37% from July.

The acceleration suggests attackers have crossed a threshold in effort, motivation and technical capability. AI has also largely eliminated language barriers and other obstacles that previously limited the effectiveness of foreign cybercriminals targeting Japanese organizations.

US cybersecurity company CrowdStrike identified a suspected 26-year-old attacker based in China in connection with the incidents involving South Korean banks. The company assessed that the individual was financially motivated and probably could not have conducted the campaign without AI assistance.

According to CrowdStrike, the suspect used a Chinese-developed AI agent alongside Anthropic’s Claude Code to support the operation.

AI-assisted cyberattacks are also creating additional detection challenges for security teams, according to Choi Kyoungjin, director of the Center for AI, Data and Policy at Gachon University near Seoul.

With general-purpose AI models, even ordinary users with malicious intent can ask the system to look for vulnerabilities and it will do much of that work for them.

South Korea registered 1,236 cybersecurity incidents during the first half of 2026, a 20% increase from the corresponding period a year earlier, government figures showed.

Although server hacking incidents declined, distributed denial-of-service (DDoS) attacks increased 56.7%, while reported ransomware incidents climbed 76.8%.

The attacks on South Korean financial institutions demonstrate the need for tighter security controls and more extensive testing as AI capabilities advance.

The incidents have not yet produced material financial losses, but the potential consequences could become more substantial if compromised information is subsequently exploited in phishing attacks or fraudulent text-message campaigns known as smishing.

Fitch Ratings warned in a research note that stolen data could expose financial institutions to additional operational and financial risks.

Concerns about AI-enabled cybercrime are also being raised by the companies developing the technology. Alphabet’s Google and Anthropic have both warned that attackers are increasingly incorporating artificial intelligence into cyber operations worldwide.