One way to think about bank security is as a building with a very fancy front door. The front door — the internet and mobile banking apps customers actually use — gets the biometric locks, the encryption, the compliance reviews, the annual penetration tests. But a bank is a big building, and over the years it has added a lot of other doors. There is a door for the outside loan brokers who need to check how a customer’s application is coming along. There is a door for sales staff checking things on their phones. Each door gets a lock, but perhaps not the same lock, because securing every door to front-door standard is expensive and someone decided, reasonably enough at the time, that the door used by mortgage brokers was not where the crown jewels were kept.

Last week in South Korea, someone with a lot of patience and some AI tooling went around trying the side doors. According to the Chosun Ilbo, citing financial industry sources on Sunday, the targets were not the banks’ core networks. At Shinhan Bank, the attackers went after a system used by loan agents to track customers’ applications. At KB Kookmin Bank it was a mobile work-support system for employees; at Hana Bank, a sales-support system. Hyundai Capital saw personal data leak from a system used by mortgage brokers. A senior financial regulator told the paper the attacks concentrated on “peripheral systems used by loan agents or outside sales staff” rather than customer-facing banking, exploiting the fact that “it is difficult to apply the same level of security to every system.”

The genuinely elegant part — elegant in the way a picking technique is elegant — is how the attackers handled account lockouts. Most login systems have a rule: get the password wrong five times and the account freezes and an alarm goes off. The attackers apparently knew the rule, and so, as one bank IT official described it, if the lockout threshold was five wrong passwords, they tried four and moved on to the next account. The alarm’s entire design premise is that an attacker will keep pounding one account until something breaks. An attacker who never breaks anything, who just politely tries four passwords on each of a hundred thousand accounts, stays under the tripwire indefinitely. “With AI, you can repeat this kind of work quickly across an enormous number of accounts,” the official said.

None of the underlying tricks are new. Trying passwords leaked from one site on another site, or guessing common passwords at random, is among the oldest sports on the internet. What changed, Kim Seung-ju, a professor at Korea University, told the paper, is that “AI-based vulnerability analysis and attack automation tools have rapidly become mainstream, ushering in an era where hackers can use them with ease.” The part of credential stuffing that used to cost money — the humans — has been automated away. Yonhap reported last week, via the Claims Journal, that AI tools were already suspected in the Shinhan breach; regulators have since ordered sector-wide security checks.

Who did it is murkier. Similar methods turned up at several institutions, and the same IP addresses appeared in some of the attacks, so the regulator would not rule out a single actor. Some pages on web servers believed to have been used in the hacks contained a Chinese phrase meaning “AI autonomous penetration.” But the financial authorities and the Financial Security Institute caution that this pins down nothing: attackers route through servers and IPs all over the world — the Shinhan attack alone drew on IPs in Korea, the US, Japan, Hong Kong, Singapore, Vietnam, Thailand and the UK — and the Chinese-made AI hacking tool said to have been used is publicly available, so anyone can pick it up. A tool being Chinese is evidence about who wrote it, not who pointed it.

There is also a backhanded compliment buried in the forensics. The Financial Security Institute noted the attackers did not burrow deep to exfiltrate bulk data or paralyse systems; they wandered from bank to bank skimming relatively small amounts of personal information. “The yield is low relative to the effort, which is far from the kind of attack sophisticated hackers usually prefer,” an FSI official said. In other words, this does not look like a state-backed operation or a big criminal enterprise. It looks like what happens when a mediocre attack becomes nearly free to run at scale: you stop needing to be good at this.

That is the uncomfortable structural point. Korea’s financial sector spent the long Gaecheonjeol holiday weekend with security staff working shifts or logging in remotely to watch for suspicious connections. But, as one financial company IT official put it, mock drills are ultimately “inspections against known attack methods,” so a genuinely new attack type means the response is “a remedy after the fact.” Defense is benchmarked against the last war; offense, supercharged by AI, gets to invent the next one on a shorter cycle.

Park Chan-am, chief executive of the security firm Stealien and a well-known hacking expert, drew the obvious conclusion: banks concentrated on their core systems while partner-facing and peripheral systems “were pushed down the priority list,” and now that AI has expanded the speed and scope of attacks, the periphery has to be brought up to standard too. Which is a politely Korean way of saying the building has thirty doors and someone just demonstrated that twenty-five of them have four-tries-then-move-along locks.

The fix is not mysterious. It is just expensive, and until last week it did not look urgent.