South Korea Investigates Whether AI Helped Hack Its Banks, Exposing 68,000 Customers
South Korea's financial regulator and police are investigating a week-long run of data breaches at seven banks and lenders that exposed more than 68,000 customers, after President Lee Jae-myung said there are signs artificial intelligence was used.
South Korea's financial sector is reeling after a run of data breaches at seven banks and lenders, disclosed over one week starting 1 October 2026. President Lee Jae Myung told a cabinet meeting on 6 October there are "signs" artificial intelligence was used, and police launched a full-scale investigation the same day.
South Korea Investigates Whether AI Helped Hack Its Banks, Exposing 68,000 Customers
Seoul, South Korea — The breaches hit Shinhan Bank, KB Kookmin Bank, Hana Bank, BNK Busan Bank, Hyundai Capital, Yegaram Savings Bank and Welcome Savings Bank. The Financial Services Commission puts the total affected at more than 68,000 people. Regulators cannot rule out that AI played a role, and the attacks reached beyond the country's five major banks into the secondary financial sector.
What the President Said on Tuesday
President Lee Jae Myung addressed the breaches directly at a cabinet meeting on 6 October. "There are signs that artificial intelligence was used in some hacking attacks, causing considerable concern and anxiety among the public," he said. He warned that the barrier to entry for attackers has collapsed. "We have now reached a point where AI can make (hacking) easy for even those without special skills," Lee said. He described a widening threat. "With advances in AI technology, hacking methods are becoming increasingly sophisticated, while the scope of the damage is spreading across all areas on a scale that is difficult to compare with the past," he said. His conclusion was blunt: "The government, companies and our society as a whole need to recognise the seriousness of the current situation and remain particularly vigilant." Police said the investigation was launched at Lee's urging. He also instructed officials to develop and supply AI tailored to cybersecurity.
Seven Firms, One Week, Sixty-Eight Thousand People
Look at the numbers firm by firm. Shinhan Bank reported roughly 25,000 customers affected — names, phone numbers and annual income — with Korea JoongAng Daily putting the figure at 25,727. Leaked items included calculated loan limits, 66 resident registration numbers and 97 connecting information values. KB Kookmin Bank lost data on 119 customers. Hana Bank exposed 89 customers. BNK Busan Bank saw 11 outsourced developers affected. Yegaram Savings Bank disclosed a breach of about 40,000 customer records — the largest at a single firm — including names, birth dates and contact details. Welcome Savings Bank uncovered up to 2,200 corporate customer records. Hyundai Capital exposed information belonging to 146 mortgage loan agents. Woori Bank and NH Nonghyup Bank were targeted but blocked access. The totals differ: the FSC says more than 68,000; AsiaFocus says more than 65,000; one industry tally puts it at roughly 66,000, still subject to investigation.
The Door They Came Through Was Not the Vault
Here is what should calm nerves, at least partly. The attacks targeted employee and sales-support systems, not core internet and mobile banking platforms. The intruders went after internet-facing systems used by employees and loan agents, not the internal networks that manage account balances and transaction records. A source from a financial regulatory agency said: "Passwords and CVC numbers were not directly exposed, so the likelihood of immediate unauthorised transactions is low." The banks said no customer transaction information was leaked. At Shinhan, attackers entered random values into a service for checking loan applications until they found valid customer numbers, then pulled the attached information. The attacks did not go through the apps customers use for online or mobile banking. The damage still spread beyond Korea's five major banks and into the secondary financial sector, which the Banking Act does not govern.
Nearly Three Days to Notice
Now consider how long the intruders had inside. Even at Korea's largest banks, the attacks went undetected for hours and even days. Shinhan Bank took 15 hours and 26 minutes to detect its breach. Hana Bank took 41 hours and 44 minutes. KB Kookmin Bank needed 67 hours and 41 minutes — nearly three days. Those figures come from Korea JoongAng Daily. The detection times at the savings banks and at BNK Busan Bank have not been confirmed. The Financial Supervisory Service alerted about 500 financial firms to the malicious IP addresses identified across the attacks and issued security guidance. A Kookmin Bank official said: "We have activated an emergency response system across the company, including a thorough review of all our processes to prevent further damage and recurrence."
The Tool Investigators Keep Naming
Traces of a Chinese-language AI hacking tool called "Artex AI" were reportedly found in the attacks on major commercial banks. A government official told AFP it was "highly likely" that Artex AI — an open-source security testing tool believed to be a Chinese AI system — was used. But officials have said its use does not indicate that the attackers were Chinese. Financial Services Commission Chairman Lee Eog-weon said on 4 October: "We cannot rule out the possibility that AI was used in the attacks." The Korea Times editorial of 5 October noted: "The AI agent was initially developed as a 'white hat' security tool for conducting simulated cyberattacks and autonomously identifying system vulnerabilities." Investigators at the Korea Financial Security Institute picked the tool out through a data signature its traffic leaves behind.
Two Counts, Twelve Countries, and No Name
The infrastructure trail leads across the globe, but it does not lead to a suspect. The Financial Supervisory Service pinpointed 19 internet protocol addresses in the United States, Japan and 10 other countries, industry sources said. Aju Press reports the same 19 addresses across 12 countries and territories, with five in the United States and two each in Japan, Sweden and Germany; the others traced to Hong Kong, Singapore, Vietnam, Thailand, Malaysia, Spain, Latvia and South Korea. Separately, the FSS and the Financial Security Institute shared data about 28 unique IP addresses with the financial sector. Park Sang-won, head of the Financial Security Institute, cautioned: "Attackers can move between and use IP addresses in multiple locations, so it is impossible to identify an attacker based on an IP address alone." The institute said the IP address was the same across the banking sector but differed in the savings-bank sector, while the attack methods were similar.
Why Leaked Loan Data Is Worse Than a Password
The stolen data goes beyond names, contact details and resident registration numbers. It includes borrowing records that can reveal a person's financial circumstances — customer identification numbers, loan application details, calculated credit limits, final decision codes and market interest rates. That combination makes voice-phishing scams far more convincing. A scammer could cite a victim's actual loan application, claim to be calling with the bank's decision and ask for additional verification or the installation of a malicious app. Because the caller already knows the victim's financial details, the approach could easily be mistaken for a legitimate call from the bank. A password reset offers only limited protection once names, contact details, identification numbers and loan records have been exposed. The FSC chairman said no sensitive data that could be used for unauthorised payments appeared to have leaked so far, but warned the stolen files could still be exploited for voice phishing.
What 124 Billion Won of Security Did Not Buy
The spending contrast is stark. Shinhan Bank, KB Kookmin Bank and Hana Bank spent approximately 124 billion won — about 92 million US dollars — on information security last year and received top-grade certifications. MK reports the three banks' security-related budget was 123.9 billion won. Shinhan had achieved top-grade personal information protection for six consecutive years. KB Kookmin emphasised continuous personal information monitoring. Hana Bank said it operates an integrated security control centre 24 hours a day, 365 days a year. And yet the breaches still happened. Authorities flagged weak authentication and excessive data retention and access as key weaknesses in the industry's defences, and warned that similar security failures would face stern penalties. FSC Secretary General Shin Jin-chang said the commission would "thoroughly analyse the causes and methods of the attacks and swiftly develop measures to strengthen the system."
This Is Not Only South Korea's Problem
South Korea is not alone in confronting this. In September, Australia said an OpenAI agent breached a government health data portal in June, gaining unauthorised access to files, in what could be the first known instance of an AI agent hacking a government website. An AI research firm said last week that AI agents tried to hack into a Canadian government website, casting the effort as a failed hacking attempt, while Canada said there were no indications its systems were compromised. The ability of AI systems to find previously unknown software vulnerabilities and hack banks, companies or government infrastructure is in the global spotlight as leading labs release ever-more advanced models. Financial-sector breaches carry higher stakes than earlier leaks this year at telecom carrier SK Telecom and streaming service Tving, and at e-commerce platform Coupang last year.
What Happens Next, and What Customers Can Actually Do
Police have formed a 28-member team to investigate on suspicion of violations of the information and communications network law. Officials are reviewing whether the case should go to the newly launched Serious Crime Investigation Agency. The National Office of Investigation said: "(We) will carry out an investigation swiftly and strictly while closely cooperating with relevant agencies to ease the public's anxiety." Banks and card companies were given until 6 October to complete emergency security checks; securities firms, insurers, savings banks and electronic financial businesses have until 8 October. The FSC ordered comprehensive inspections of all externally exposed IT assets. For customers, the advice is practical: ask your financial institution what information was compromised, and use safeguards that block new credit transactions or remote account openings if needed. The financial authorities said they would oversee affected companies to ensure they protect and compensate customers.
By Jessica Ali, Staff Writer
This article was produced with AI-assisted research and editorial support. Sources: Yonhap News Agency, Korea JoongAng Daily, The Korea Herald, The Korea Times, KBS World, AFP via The Star, Reuters via The Japan Times, MK
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0
Comments (0)