my timesThe Korea Times
  1. Business
  2. Banking & Finance

AI-powered attacks on banks expose technological lag in Korea's financial cyber defenses

Listen

Summary

AI-powered attacks hit seven financial firms in Korea since Thursday, exposing information on more than 67,000 people. Shinhan Bank, KB Kookmin Bank and Hana Bank were among the affected firms, and officials said the breaches exposed gaps in the sector’s defenses. President Lee Jae Myung ordered a thorough investigation on Sunday, and financial authorities held an emergency meeting the same day. The FSC warned that secondary damage such as voice phishing and smishing could follow.


Key Facts

  • Seven financial firms have reported information leaks since Thursday, including Shinhan Bank, KB Kookmin Bank, Hana Bank, Busan Bank, Yegaram Savings Bank, Welcome Savings Bank and Hyundai Capital.
  • More than 67,000 people are believed to have been affected, and the leaked information includes names, contact details, resident registration numbers, annual income and loan limits.
  • Shinhan Bank, KB Kookmin Bank and Hana Bank together spent nearly 124 billion won, or 92 million dollars, on information security last year.
  • Investigators found traces associated with ARTEX AI, a Chinese-language open-source autonomous penetration testing system, on a server believed to have been used in the attacks.
  • Financial Services Commission Chairman Lee Eog-weon said there is no indication that data directly usable for unauthorized payments has been leaked, but secondary damage such as voice phishing and smishing cannot be ruled out.
By Park Han-sol
  • Published Oct 5, 2026 4:44 pm KST
  • Updated Oct 5, 2026 4:53 pm KST

Data of more than 67,000 customers across 7 companies compromised

Financial Services Commission Chairman Lee Eog-weon walks behind the heads of Korea's three largest commercial banks — from left, Hana Bank CEO Lee Ho-sung, KB Kookmin Bank CEO Lee Hwan-ju and Shinhan Bank CEO Jung Sang-hyuk — during an emergency meeting at Government Complex Seoul, Sunday. The meeting was held to discuss countermeasures against recent artificial intelligence-powered data breaches across the financial sector. Newsis

Financial Services Commission Chairman Lee Eog-weon walks behind the heads of Korea's three largest commercial banks — from left, Hana Bank CEO Lee Ho-sung, KB Kookmin Bank CEO Lee Hwan-ju and Shinhan Bank CEO Jung Sang-hyuk — during an emergency meeting at Government Complex Seoul, Sunday. The meeting was held to discuss countermeasures against recent artificial intelligence-powered data breaches across the financial sector. Newsis

Cyber defenses across Korea’s financial sector are facing intense scrutiny after a string of attacks hit banks and other financial companies, raising fears that artificial intelligence (AI)-assisted cyberattacks could outpace existing security measures.

Seven financial firms have reported information leaks so far since Thursday, including three of the country’s largest commercial banks — Shinhan Bank, KB Kookmin Bank and Hana Bank — along with Busan Bank, Yegaram Savings Bank, Welcome Savings Bank and Hyundai Capital. More than 67,000 people are believed to have been affected.

The leaked information includes customers’ names, contact details, resident registration numbers, annual income and loan limits.

AI-powered attacks

The latest incidents differ from some of the biggest cybersecurity breaches in the past, when the core IT or transaction systems of individual institutions were compromised. This time, multiple firms were targeted in quick succession, with attackers apparently looking for easier ways in.

The cyber criminals, believed to be based overseas, repeatedly probed less-protected entry points, including systems used by employees, outside contractors and loan agents, rather than trying to penetrate banks’ core networks directly.

Investigators found traces associated with ARTEX AI, a Chinese-language open-source autonomous penetration testing system, on a server believed to have been used in the attacks, although it does not mean the attacks originated in China.

The use of such tools can dramatically speed up the search for weak points. Instead of manually working through systems one at a time, an AI agent can scan for vulnerabilities, adjust its approach based on what it finds and move on to another target.

Lim Jong-in, a professor at Korea University’s Graduate School of Information Security, described the AI agents as being “capable of automatically searching for vulnerabilities, choosing to target servers operated by partner companies rather than directly attacking banks’ main systems.”

The attackers also appear to have utilized previously leaked personal information, with credential stuffing cited as one of the likely techniques used. Credential stuffing involves using already stolen usernames and passwords to try accessing accounts on other services, typically through automated login attempts.

Lag in cybersecurity exposed

The latest string of breaches has raised questions about whether the financial sector’s security systems are adequately prepared for large-scale, automated attacks using AI.

Shinhan Bank, KB Kookmin Bank and Hana Bank together spent nearly 124 billion won ($92 million) on information security last year. Yet the latest attacks appeared to bypass such defenses by exploiting weaker links elsewhere.

“The reason these breaches are particularly concerning is the combination of personal and financial information that has been exposed. A phone number on its own has limited value, but when criminals can connect it to someone’s income or potential loan limit, they gain enough context to create a highly convincing and personalized scam,” said Hwang Sung-ho, Korea country manager at cybersecurity software company Nord Security.

Hwang Suk-jin, a professor at Dongguk University’s Graduate School of International Affairs and Information Security, said advances in AI are lowering the entry barrier for cyber criminals, allowing them to automate parts of the process that previously required specialized expertise.

“As attacks are becoming more coordinated and automated, defenses cannot remain fragmented at the level of individual companies,” he said. “The existing cybercrime investigation system, specialized personnel and techniques also need to be upgraded for the AI era.”

President Lee Jae Myung on Sunday ordered officials to “approach the matter with the utmost seriousness and make every effort to conduct a thorough investigation and prepare countermeasures.”

Later that day, financial authorities convened an emergency meeting with chief executives from across the sector to discuss a response.

“There is currently no indication that sensitive information that could be directly used for unauthorized payments or other financial crimes has been leaked,” Financial Services Commission Chairman Lee Eog-weon said. “But we cannot rule out the possibility of secondary damage, such as voice phishing and smishing using the leaked data.”

He added, “As new types of cyberattacks are likely to continue occurring with greater frequency, we must also move quickly to establish security systems capable of using AI to defend against AI-driven attacks.”

Read More

  • Shinhan, Kookmin, Hana data breaches fuel concerns over AI-powered cyberattacks in financial sector
  • Lee orders thorough probe into data breaches at local banks

Explore More

  • Q.

  • Q.

  • Q.