South Korea is investigating a major cybersecurity incident affecting seven financial institutions, including Shinhan Bank, KB Kookmin Bank and Hana Bank. President Lee Jae Myung ordered an investigation after authorities identified signs that artificial intelligence tools may have been involved in attacks against financial-sector infrastructure.
What makes the incident particularly significant is the reported discovery of traces associated with a Chinese-language open-source AI penetration-testing framework. Such tools can legitimately help security teams discover vulnerabilities, but the same automation capabilities can potentially be repurposed by attackers to accelerate reconnaissance, vulnerability discovery and exploitation.
The disruption goes beyond another banking cyberattack. Autonomous and agentic AI changes the economics of hacking. Attackers can potentially automate repetitive stages of an intrusion, analyse large attack surfaces, adapt techniques and operate at a speed that traditional human-centric security operations may struggle to match.
Banks therefore face an expanding threat surface across identities, APIs, cloud infrastructure, employees, customers, third parties and AI agents. Traditional authentication establishes identity at one moment; it does not necessarily determine whether an authenticated user, device or autonomous agent subsequently begins behaving abnormally.
The emerging security architecture must move beyond one-time authentication to continuously observing and analysing user and AI-agent behaviour, verifying every interaction, and responding dynamically to anomalies, while enforcing least-privilege access, controlled permissions, continuous monitoring and auditable governance.
This is where we suggest considering BehaviourID with a Post-Quantum Cryptography (PQC) integration layer as part of a broader zero-trust architecture. BehaviourID can contribute continuous behavioural risk signals after authentication, while PQC can help organisations prepare cryptographic infrastructure for future quantum threats. Combined with identity security, deepfake detection, privileged-access controls, AI-agent governance and human oversight, this creates a stronger defence against autonomous AI: do not permanently trust an authenticated identity or agent—continuously verify its behaviour, permissions and actions.





