Skip to content
TECH CEO Daily

South Korea bank breaches hit Shinhan, KB and Hana amid suspected AI-powered attacks

Shinhan says about 25,000 customers were affected; the regulator ordered audits of every externally exposed system as analysts point to AI attack automation.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1Shinhan, KB Kookmin and Hana disclosed breaches between September 30 and October 2; Shinhan says about 25,000 customers were affected.
  • 2Each breach ran through a secondary system: a loan-agent tool, an employee app and a sales-support system.
  • 3Analysts suspect AI attack automation tools; neither the banks nor authorities have confirmed that.

The news

South Korea bank breaches at Shinhan Bank, KB Kookmin Bank and Hana Bank, disclosed between September 30 and October 2, drew an emergency regulatory meeting and, according to BleepingComputer, a presidential order for a thorough investigation. Several threat analysts suspect AI-driven attack tools were involved, according to Genian Security Center head Moon Jong-hyun, BleepingComputer reported.

Shinhan Bank said information on about 25,000 customers leaked after an attacker bypassed identity verification in a mobile inquiry service that loan agents use to check application progress, The Korea Herald reported. The data included names, phone numbers, annual income and calculated loan limits, plus 66 resident registration numbers, South Korea's national ID numbers. The bank confirmed the breach on Wednesday, September 30.

KB Kookmin Bank said 119 customers were affected after unauthorized external access to an employee mobile work-support system, detected on the evening of September 30. The leaked details varied by customer and included names, phone numbers, addresses and encrypted resident registration numbers, Digital Today reported. The bank said it notified customers individually and would fully compensate any damage.

Hana Bank said hackers accessed its sales support system and exposed personal information on 89 customers, including resident registration numbers, names, addresses, contact details and employer names, according to The Korea Herald. The Gulf Daily News reported that financial information was not compromised. BNK Financial Group also reported a breach of 11 records containing outsourced employees' personal information.

The Financial Services Commission (FSC) met with the Financial Supervisory Service and security officials on Friday, October 2. In a statement that day, the FSC told financial companies to immediately audit all externally exposed IT systems, strengthen authentication and access controls, remove unnecessary information exposure and quickly share attack details such as IP addresses. It said affected firms must provide consumer protection and compensation without disruption.

Yonhap reported that a server used in the attacks hosted an HTML page whose title contained a Chinese-language string linked to ARTEX AI, an open-source penetration-testing system that uses agents to automate reconnaissance, vulnerability discovery and attack planning, according to BleepingComputer. Moon Jong-hyun, head of the Genian Security Center, wrote on LinkedIn that several threat analysts believe AI-based attack automation tools were involved. Neither the banks nor the authorities have confirmed that, and no attacker has been publicly named.

The numbers

Shinhan Bank customers affected (approx.)
25,000
Resident registration numbers in the Shinhan leak
66
KB Kookmin Bank customers affected
119
Hana Bank customers affected
89
BNK Financial Group records exposed (outsourced staff)
11

Why CEOs should care

Every one of these breaches came through a side door. Shinhan's ran through a tool for loan agents, KB Kookmin's through an employee work app and Hana's through a sales-support system. Chief information security officers (CISOs) at U.S. banks, lenders and fintechs should inventory internet-reachable partner, broker and employee portals, test their identity checks as hard as the main customer app, and ask why a tool such as a loan-status checker holds income data or national ID numbers at all.

The FSC's directive doubles as a checklist any board can borrow: audit every externally exposed system, including ones customers never see, cut unnecessary data exposure, tighten authentication and share attacker details quickly with peers. Boards and audit committees should ask management how fast it could produce that inspection report if a regulator demanded one on a short deadline, as the FSC has.

CFOs should note the cost line. KB Kookmin pledged full compensation for any damage, and the regulator told affected firms to deliver compensation without disruption. If analysts are right that automated tools were used, several institutions can be probed within days of each other, as happened here, so incident budgets and cyber insurance terms should assume clustered attacks rather than one-off events.

The bigger picture

South Korea's response shows how fast a cluster of breaches can climb from bank IT desks to the top of government. Shinhan and KB Kookmin each hold more than $400 billion in assets, BleepingComputer noted. Hana said it learned of hacking attempts at another financial institution on Thursday, October 1, according to The Korea Herald, suggesting the attempts spanned several institutions in a short period.

ARTEX AI is described as a penetration-testing system, software meant for authorized security testing. If its use is confirmed, it would be a high-profile case of an agent-based testing tool turned against major banks, and a reason to assume that overlooked, internet-facing systems will be found faster than before.

What’s next

The FSC said it will send financial firms security vulnerability checklists, require inspection results within a short timeframe, and analyze the causes and attack methods to prepare institutional improvements. Watch for those findings, any official word on whether AI tools were used, and whether more institutions report breaches.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Shinhan BankKB Kookmin BankHana BankFinancial Services CommissionSouth Korea

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.