Shinhan, KB Kookmin data breaches raise concerns over AI-powered cyberattacks
Summary
A series of data breaches at Shinhan Bank and KB Kookmin Bank has raised concern in Korea’s financial sector over AI-powered cyberattacks. KB Kookmin Bank said personal information of 119 customers was leaked through abnormal external access to an employee mobile system on Friday. Shinhan Bank disclosed a breach affecting about 25,000 customers a day earlier, and regulators opened an investigation and held an emergency response meeting.
Key Facts
- KB Kookmin Bank said the leaked information included names, phone numbers, addresses and resident registration numbers in encrypted format.
- The compromised KB Kookmin system provides mobile access to work tools for staff and does not handle customer transactions.
- Shinhan Bank said an unauthorized party bypassed authentication to access a service used by loan agents to check application status.
- The exposed Shinhan data included names, phone numbers, annual income, borrowing limits and other personal and credit information submitted for loan applications.
- The Financial Services Commission and the Financial Supervisory Service dispatched investigators to the affected firms and shared intrusion details with relevant agencies.
Generative AI lowers barriers to hacking, raising fears of faster, wider attacks

From left are headquarters of KB Kookmin Bank and Shinhan Bank in Seoul / Korea Times file
A series of data breaches at Shinhan Bank and KB Kookmin Bank, two of Korea’s largest commercial banks, has heightened concerns in the financial sector over increasingly sophisticated cyberattacks using artificial intelligence (AI).
On Friday, KB Kookmin Bank said that personal information belonging to 119 customers was leaked after abnormal external access to a mobile system used by employees. The leaked information varied by customer and included names, phone numbers, addresses and resident registration numbers in encrypted format.
The bank stressed that the compromised system provides mobile access to work tools for staff and does not handle customer transactions, including online and mobile banking. It also pledged to fully compensate for any losses resulting from the data breach.
"We have activated an emergency response system across the company, including a thorough review of all our processes to prevent further damage and recurrence," a bank official said.
The incident came a day after Shinhan Bank disclosed a data breach affecting about 25,000 customers.
Shinhan said an unauthorized party bypassed authentication to access a service used by loan agents to check the status of applications. The exposed data included customers’ names, phone numbers, annual income and borrowing limits, along with other personal and credit information submitted for loan applications.
According to local media reports, traces of a Chinese-language AI penetration-testing tool were found on a server believed to have been used in the attack, raising concerns that AI could accelerate cyberattacks and broaden their scope. Regulators' investigation remains underway.
The server’s HTML title reportedly contained a Chinese phrase meaning “AI autonomous penetration testing console,” suggesting a possible link to ARTEX AI, an open-source autonomous penetration-testing system built on a large language model. The server is suspected of having been used in a credential stuffing attack against Shinhan Bank.
Credential stuffing involves using stolen usernames and passwords to attempt to access accounts on other services, often through large-scale automated login attempts.
Security experts say advances in AI are lowering the technical barriers to cyberattacks. The technology is moving beyond suggesting attack methods, with AI agents capable of combining disparate information to identify vulnerabilities, launch attacks and refine their tactics based on the results.
The recent breaches at two of the country’s largest commercial banks have heightened concerns about these evolving threats. Financial institutions face particular risks as customer information is increasingly handled by loan brokers, outsourced service providers and digital platforms.
Amid growing concerns, the Financial Services Commission (FSC), the country’s top financial regulator, held an emergency response meeting later in the day. It said it and the Financial Supervisory Service had dispatched investigators to the affected firms as soon as the breaches were reported.
The regulators have also shared details of the attacks, including the IP addresses and intrusion methods used, with relevant agencies to help prevent further damage.
“Preventing data leaks requires financial institutions to maintain a high level of readiness,” FSC Secretary General Shin Jin-chang said. “We will strengthen coordination by monitoring intrusion attempts and rapidly sharing threat intelligence, while examining the causes of the breaches and attack methods to identify and swiftly introduce necessary regulatory improvements.”
Explore More
- Q.
- Q.
- Q.