Shinhan, Kookmin, Hana data breaches fuel concerns over AI-powered cyberattacks in financial sector
Summary
Shinhan Bank, KB Kookmin Bank and Hana Bank reported data breaches in Seoul on Friday, heightening concerns in the financial sector over AI-powered cyberattacks. KB Kookmin said 119 customers were affected, while Hana Bank said 89 customers had their personal information exposed. Regulators held an emergency response meeting and dispatched investigators to the affected firms.
Key Facts
- KB Kookmin Bank said personal information belonging to 119 customers was leaked after abnormal external access to a mobile system used by employees.
- Hana Bank said personal information belonging to 89 customers was exposed after an external hacking attempt on its sales support system.
- Shinhan Bank disclosed a separate breach affecting about 25,000 customers after an unauthorized party bypassed authentication to access a service used by loan agents.
- The Financial Services Commission said it and the Financial Supervisory Service dispatched investigators to the affected firms and shared the IP addresses and intrusion methods with relevant agencies.
- The regulators said they would strengthen coordination, monitor intrusion attempts and examine the causes and attack methods to prepare regulatory improvements.
Generative AI lowers barriers to hacking, raising fears of faster, wider attacks

From left are headquarters of KB Kookmin Bank and Shinhan Bank in Seoul / Korea Times file
A series of data breaches at Shinhan Bank, KB Kookmin Bank and Hana Bank, three of Korea’s largest commercial banks, has heightened concerns in the financial sector over increasingly sophisticated cyberattacks using artificial intelligence (AI).
On Friday, KB Kookmin Bank said that personal information belonging to 119 customers was leaked after abnormal external access to a mobile system used by employees. The leaked information varied by customer and included names, phone numbers, addresses and resident registration numbers in encrypted format.
"We have activated an emergency response system across the company, including a thorough review of all our processes to prevent further damage and recurrence," a Kookmin Bank official said.
Later that day, Hana Bank said personal information belonging to 89 customers had been exposed following an external hacking agent’s attempt to gain unauthorized access to its sales support system. The leaked information included customers' resident registration numbers, names, addresses, email addresses, phone numbers and workplace information.
The lender said it immediately blocked the relevant IP address, launched an emergency response team and notified affected customers.
"We sincerely apologize for causing concern and inconvenience to our customers," a Hana Bank official said.
The two banks stressed that the compromised systems were separate from their internet and mobile banking platforms and that no customer financial transaction information had been leaked. They also pledged to fully compensate for any losses resulting from the data breach.
On the same day, BNK Financial Group said personal information belonging to 11 outsourced workers had been leaked in a cyberattack, while Woori Bank and NH NongHyup Bank said they had also faced hacking attacks but no information had been exposed.
Those incidents came a day after Shinhan Bank disclosed a data breach affecting about 25,000 customers.
Shinhan said an unauthorized party bypassed authentication to access a service used by loan agents to check the status of applications. The exposed data included customers’ names, phone numbers, annual income and borrowing limits, along with other personal and credit information submitted for loan applications.
According to local media reports, traces of a Chinese-language AI penetration-testing tool were found on a server believed to have been used in the attack against the bank. Regulators' investigation remains underway.
The server’s HTML title reportedly contained a Chinese phrase meaning “AI autonomous penetration testing console,” suggesting a possible link to ARTEX AI, an open-source autonomous penetration-testing system built on a large language model. The server is suspected of having been used in a credential stuffing attack.
Credential stuffing involves using stolen usernames and passwords to attempt to access accounts on other services, often through large-scale automated login attempts.
Security experts say advances in AI are lowering the technical barriers to cyberattacks. The technology is moving beyond suggesting attack methods, with AI agents capable of combining disparate information to identify vulnerabilities, launch attacks and refine their tactics based on the results.
The recent breaches at the country’s major banks have heightened concerns about these evolving threats. Financial institutions face particular risks as customer information is increasingly handled by loan brokers, outsourced service providers and digital platforms.
Amid growing concerns, the Financial Services Commission (FSC), the country’s top financial regulator, held an emergency response meeting later in the day. It said it and the Financial Supervisory Service had dispatched investigators to the affected firms as soon as the breaches were reported.
The regulators have also shared details of the attacks, including the IP addresses and intrusion methods used, with relevant agencies to help prevent further damage.
“Preventing data leaks requires financial institutions to maintain a high level of readiness,” FSC Secretary General Shin Jin-chang said. “We will strengthen coordination by monitoring intrusion attempts and rapidly sharing threat intelligence, while examining the causes of the breaches and attack methods to identify and swiftly introduce necessary regulatory improvements.”
Explore More
- Q.
- Q.
- Q.