SEOUL — FRIDAY, OCTOBER 9, 2026 — Companies in South Korea and Japan are racing to harden their defenses after a wave of cyberattacks that security experts say marks a turning point: artificial intelligence lowering the bar for less-skilled criminals. Nine South Korean banks and two mega-churches are probing intrusions that may have involved AI tools, Reuters reported Friday morning, while Japanese firms including Daiwa Securities, SoftBank Corp and the Lawson convenience-store chain have been hit by a recent surge. Behind the Korean bank hacks, CrowdStrike says, is likely a 26-year-old in China’s Guangdong province — armed with AI coding assistants that let one person do the work of a crew.
02 The Wave
The scope, laid out in Reuters’ Friday-morning report, is striking. In South Korea, nine banks are investigating attacks that may have involved AI tools — alongside two mega-churches, an unusual target set that suggests the intrusions were opportunistic rather than narrowly financial. In Japan, the victims named include Daiwa Securities, one of the country’s major brokerages; SoftBank Corp, the telecom giant; and Lawson, the convenience-store chain with thousands of locations.
The trend data is worse than the incident list. Japan recorded more cybersecurity incidents in the first nine months of 2026 than in all of 2025, according to TrendAI figures cited by Reuters. September alone saw 86 incidents — up about 18 percent from August and about 37 percent from July. Whatever is driving the surge, it is accelerating.
Nobuo Miwa, president of the Tokyo-based cybersecurity firm S&J Corp, told Reuters: “AI doesn’t get tired… My view is that Japan is essentially being subjected to carpet bombing.” The metaphor is deliberate: not a few precision strikes, but a volume of attacks no human team could sustain — because the attackers are no longer fully human teams.

03 One 26-Year-Old, Two AI Tools
The most detailed attribution so far concerns the South Korean bank hacks. CrowdStrike, the U.S. cybersecurity firm, said the suspected attacker is likely a 26-year-old in China’s Guangdong province, assessed with “moderate confidence” as a Chinese speaker motivated by money rather than espionage, Reuters reported on October 8.
The toolkit is the story. According to CrowdStrike, the suspect paired ARTEX — a Chinese open-source penetration-testing tool — with Claude Code, Anthropic’s AI coding assistant. The combination let a single operator probe, adapt and scale: the attacker reportedly asked Claude where threat actors sell Korean data-breach information, and had it draft a “security researcher résumé” listing a Telegram account, his age, his education and a location in Maoming, Guangdong, according to Inside Telecom’s account of the findings.
Adam Meyers, CrowdStrike’s senior vice president of counter-adversary operations, told Reuters the assessment was sobering precisely because the tradecraft wasn’t elite: “While (the hacker’s) capabilities were not terribly sophisticated they were effective.” As Meyers told the LA Post: “And this is significant because it allows one human to target many customers in a very short period of time using the power of AI.”
04 The Damage and the Response
The confirmed damage is still being counted. Shinhan Bank said about 25,000 customers’ personal information was compromised, while KB Kookmin said 119 customers were affected, according to the LA Post — numbers that sound modest until you consider they represent the customers a single 26-year-old reached with AI assistance, in a campaign still under investigation.
South Korean authorities are treating the wave as a national-security matter, not just a banking problem. President Lee Jae Myung said Tuesday that signs had emerged AI was used in some of the incidents and called for heightened cybersecurity measures across the country, Reuters reported. South Korean police have launched a formal probe into the bank hacks.
The two mega-churches in the victim list are a reminder that the targeting is indiscriminate: when the cost of attacking collapses, attackers don’t need a reason to pick you. Any organization with a network and data is in the blast radius — which, as Miwa’s “carpet bombing” line suggests, is now essentially everyone.

05 What It Means
The deeper significance is structural. For years, the cybersecurity industry’s comfort was that sophisticated attacks required sophisticated attackers — teams with time, money and expertise. The Korea-Japan wave suggests that comfort is expiring. When a single financially motivated 26-year-old with off-the-shelf AI tools can rattle nine banks, the limiting factor on cybercrime is no longer skill. It’s intent.
That shift is why the story traveled from Seoul and Tokyo to the front pages overnight. Defenders now face adversaries who don’t sleep, don’t tire and can iterate at machine speed — “AI doesn’t get tired,” as Miwa said — while the economics of defense still assume human-paced attackers. Closing that gap, rather than catching one suspect in Guangdong, is the work of the next decade.
Follow the Previously newsroom as the police probe and the banks’ forensic reviews develop through Friday.
There is also a policy reckoning coming for the AI labs whose tools are being repurposed. Claude Code is a legitimate developer product; ARTEX is an open-source testing framework. Neither was built for crime, yet together they gave a lone operator in Guangdong the reach of an organized crew. CrowdStrike’s “moderate confidence” attribution — careful, probabilistic language — reflects how hard these cases are to close: the suspect’s self-drafted résumé, complete with Telegram handle and hometown, may be bravado, misdirection, or both. What isn’t in doubt is the trend line. September’s 86 incidents in Japan, up 37 percent since July, say the carpet bombing has already begun.
Sources
- Reuters — “South Korea, Japan buffeted by hacks as AI lowers bar for cybercriminals”: the wave, victims, TrendAI figures, Miwa quote, Lee Jae Myung response. Reuters · Oct 9, 2026
- Reuters — “Suspect behind South Korea bank hacks may be 26-year-old in China, cybersecurity firm says”: CrowdStrike attribution, ARTEX and Claude Code details, Meyers quotes. Reuters · Oct 8, 2026
- LA Post — CrowdStrike findings coverage: Shinhan and KB Kookmin customer figures, Meyers “one human” quote. LA Post · Oct 8, 2026
- Inside Telecom — “CrowdStrike says China-based suspect used AI tools in South Korean bank hacks”: résumé detail, Telegram and Maoming specifics. Inside Telecom · Oct 8, 2026



