[Exclusive] 'AI hacking is an urgent threat,' yet banks find 1,000 vulnerabilities every year, with some left unaddressed for three years
- Input
- 2026-10-04 15:35:58
- Updated
- 2026-10-04 15:35:58


[Financial News] As AI-powered cyberattacks spread across the financial sector, some information-security vulnerabilities found at South Korean banks have remained unaddressed for three years, an investigation has found. Banks are conducting more penetration tests each year to identify vulnerabilities, but some cannot be remediated immediately because they require a complete system replacement.
Banks unable to fix discovered vulnerabilities
Data submitted by the Financial Supervisory Service on the 4th to the office of Park Sang-hyuk, a Democratic Party of Korea lawmaker and the ruling party's secretary on the National Policy Committee, showed that 20 banks conducted a total of 481 penetration tests from 2022 through August this year and identified 4,777 valid vulnerabilities.
Penetration testing, or simulated hacking, is a targeted inspection method designed to demonstrate whether a financial company's information technology infrastructure can be breached using the same techniques as actual hackers, or cyberattackers. Banks conduct penetration tests several times a year using their own security personnel and white-hat hackers from the Financial Security Institute.
The volume and speed of vulnerability discovery are rapidly increasing as AI use expands. The problem is that some vulnerabilities cannot be addressed immediately even after they are found. In 2024, 20 South Korean banks conducted 107 penetration tests and identified 1,071 vulnerabilities, but one bank had failed to remediate two of them by August. That bank is one of five specialized banks.
The Financial Supervisory Service said, "It is difficult to disclose the bank in question and the specific vulnerabilities." Revealing details of the unaddressed vulnerabilities or identifying the financial company could expose an attack route to hackers.
AI attacks are accelerating, but responses remain limited
According to the Financial Supervisory Service, addressing the vulnerabilities requires shutting down the system or replacing it entirely, making immediate action difficult. Until remediation is complete, the bank is applying separate protective measures, such as registering blocking rules on security devices and strengthening monitoring, the agency explained.
Financial companies operating outdated systems often find that discovered vulnerabilities cannot be resolved with a simple software patch. A financial-security industry official said, "Addressing some vulnerabilities requires examining and completely replacing all the systems built up over decades. In some cases, the employees who were working at the time have retired, leaving no relevant records," adding, "We do not know how much the related work will cost, who can do it, or even whether the necessary technology exists."
In other words, they can only check every day for signs of an attack near the vulnerability, with no way to fix it. One vulnerability found at a specialized bank last year also remains unaddressed.
A financial-security industry official said, "Remediation requires pouring in money and manpower," adding, "Even when a company knows where it is vulnerable, the relevant software developer may not provide a patch or update, or the company may be unable to apply it immediately even if one is provided."
Small and midsize financial firms on alert as AI attacks spread
Large financial companies with their own AI-response capabilities can apply patches and strengthen security immediately after discovering a vulnerability. Smaller financial companies, however, often lack the capabilities and funding not only to address vulnerabilities promptly but sometimes even to deal with them after discovery.
Since June, the Financial Services Commission has been carrying out emergency easing of network-separation regulations for 49 financial companies with total assets of at least 10 trillion won, at least 1,000 permanent employees, and an obligation under the Electronic Financial Transactions Act to appoint a Chief Information Security Officer (CISO). The regulations are being relaxed in three stages to prepare for AI attacks using AI agents. The move reflects concerns that small and midsize companies lack the ability to respond to AI attacks.
Financial holding companies view improving the security capabilities of their smaller affiliates as a key task. At a June forum on responding to hacking and voice phishing in the age of AI transformation (AX), Jin Ok-dong, chairman of Shinhan Financial Group, acknowledged, "Companies with smaller profits, revenues and workforces cannot defend themselves against cyberattacks on their own." Jong-ryong Yim, chairman of Woori Financial Group, also said, "Smaller affiliates that are not large enough to apply for emergency easing of network-separation regulations are even more vulnerable in terms of security."
Park Sang-won, president of the Financial Security Institute, said at the time, "The time available to respond between the disclosure of a software vulnerability and its actual exploitation is shrinking," adding, "It is becoming increasingly important not only to discover vulnerabilities quickly but also to link that discovery to remediation as quickly as possible."
Concerns are also growing in the non-bank financial sector about small and midsize firms with relatively limited security personnel and investment capacity, as a series of personal-information breach incidents that recently emerged in the banking sector have been confirmed.
Park Sang-hyuk said, "Cases have been identified in which banks found vulnerabilities through penetration testing but failed to complete remediation into the following year, citing the need for a complete system replacement, among other reasons." He added, "As hacking attacks on banks intensify, increased security investment and improvements to aging IT infrastructure must support efforts to ensure that vulnerability discoveries lead to prompt remediation rather than ending with identification alone."
[email protected] Park Moon-soo and Seo Ji-yoon Reporter