Data breaches in Japan and South Korea are raising concerns that AI is making cyberattacks faster and easier to scale, although its involvement has not been established in every incident.
At least nine South Korean banks have disclosed attacks or been identified as targets in local reporting since late September. CrowdStrike said the suspected attacker was likely a China-based individual who used a Chinese-developed AI agent and Anthropic’s Claude Code, according to Reuters. That attribution remains the cybersecurity company’s assessment.

Millions of records exposed in Japan
Japan’s Times Car reported a leak affecting 6.6 million users, while Daiwa Securities said an attack on a contractor’s server potentially exposed 220,000 customer records, SBS reported.
The scale of those breaches does not, by itself, establish that AI was responsible. They nevertheless highlight the volume of sensitive information exposed when corporate systems or outside providers are compromised.
A separate attack shows how AI can scale the damage
In a separate investigation published on September 22, Forbes reported that a Chinese-speaking attacker used DeepSeek, Kimi and an older Claude model to target as many as 100 organisations.
Gambit Security researchers found evidence of access to at least 30 websites between September 10 and 15. The attacker’s server contained details for approximately 618,000 credit cards.
Researcher Eyal Sela described the campaign as one of “the most severe abuses of AI for exploitation seen so far.”
Anthropic said it banned the account involved. Researchers also found that newer Claude versions had blocked attempted misuse, illustrating that safeguards can make a difference.
Related: Top AI Leaders Call for Slowing Down AI Development.
The business risk extends beyond stolen data
Breaches can bring service disruption, customer compensation, regulatory scrutiny and lasting damage to trust. Attacks involving contractors also expose weaknesses beyond a company’s own systems.
AI-based security tools may help defenders respond, but they still need effective access controls, timely software updates and tested incident-response plans.
The emerging risk is the speed and scale at which attackers can operate. Businesses need evidence that their defences can keep pace.
Disclosure: This article does not represent investment advice. The content is for informational and educational purposes only.

