South Korea orders probe as data breaches hit Shinhan, KB Kookmin and other lenders
President Lee Jae Myung ordered a thorough investigation after a string of intrusions exposed data of more than 60,000 customers at South Korean banks and lenders.
At a glance
- Shinhan Bank (about 25,000 customers) and Yegaram Savings Bank (about 40,000 customers) reported the largest leaks, according to Korean media.
- KB Kookmin, Hana, BNK Busan, Hyundai Capital and Welcome Savings Bank were also affected; attackers reportedly targeted weaker peripheral systems used by loan agents.
- Police reportedly found traces of a Chinese-language AI penetration-testing console on a server used in the Shinhan attack; attribution remains unconfirmed.
- The Financial Services Commission held an emergency meeting and ordered firms to run internal security inspections.
South Korean President Lee Jae Myung on October 4 ordered authorities to conduct a thorough investigation into a series of data breaches that hit several of the country's banks and lenders in recent days, according to Korea JoongAng Daily and The Korea Times. Financial regulators convened an emergency meeting with industry executives, warning that the attacks may have been powered by artificial intelligence.
What happened
According to Korea JoongAng Daily, Shinhan Bank reported that personal and credit information of about 25,000 customers had been exposed, while Yegaram Savings Bank reported a leak affecting about 40,000 customers. Smaller incidents were reported at KB Kookmin Bank (119 customers), Hana Bank (89 customers), BNK Busan Bank (11 outsourced developers) and Hyundai Capital (146 mortgage loan agents). Welcome Savings Bank was also named among the affected institutions; The Kyunghyang Shinmun put its exposure at roughly 2,200 corporate clients and said two online investment-linked finance companies were also hit.
The Kyunghyang Shinmun reported that the intrusions took place between September 27 and 30. JoongAng Daily said securities firms, insurers, card companies and state-run banks had not been affected.
The Korea Times reported that the exposed data included names, phone numbers, annual income figures, loan limits and, in some cases, resident registration numbers.
Technical details
According to Investing.com, the attackers targeted external websites and servers used by loan agents and employees, which had weaker security oversight than core banking systems. The Kyunghyang Shinmun described automated brute-force attacks that fed values into loan broker services to identify valid customer numbers and then harvest additional records.
The Korea Times reported that police found traces of a Chinese-language AI penetration-testing tool on a server used in the Shinhan attack, with a page title referencing an "AI autonomous penetration testing console". The outlet said this suggests possible use of ARTEX, an open-source autonomous penetration-testing system built on a large language model. Kyunghyang reported that the tool was published on GitHub in late July, but that IP addresses linked to the attacks traced back to eight countries, making attribution based on routing alone impossible, according to officials. The identity of the attackers has not been confirmed.
Financial Services Commission (FSC) Chairman Lee Eog-weon said "the possibility of AI-powered attacks cannot be ruled out," JoongAng Daily reported.
Response
President Lee instructed officials to treat the matter with the utmost seriousness and draw up countermeasures, according to the reports. The FSC chairman told the emergency meeting that the whole industry must remain on the highest alert and ordered financial firms to review their security systems and adopt AI-based defensive measures. Investing.com reported that institutions were told to run internal security inspections and report findings to authorities. Police have opened an investigation, The Korea Times said.
What to do
Customers of the affected institutions should expect follow-up phishing and voice-phishing attempts that use leaked names, phone numbers and loan details. Financial organisations elsewhere should review internet-facing peripheral systems such as broker and agent portals, enforce rate limiting and lockouts against automated enumeration, and monitor for high-volume requests that iterate over customer identifiers.
Sources
- President Lee orders probe into cyberattacks on Korean banks — Korea JoongAng Daily
- Lee orders thorough probe into data breaches at local banks — The Korea Times
- Korean finance breached by a two-month-old Chinese AI — The Kyunghyang Shinmun
- South Korea orders financial sector security checks after data breaches — Investing.com via Yahoo News
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



