Full Breakdown
AI-Linked Breaches at South Korean Banks Raise Security Concerns
By Drooid · · How we work
Core Event
In late September, cyber incidents exposed personal credit data for roughly 25,000 customers of Shinhan Bank, 99 customers and 20 employees of KB Kookmin Bank, and 89 customers of Hana Bank. The attacks also affected BNK Busan Bank, two savings banks, a regional bank and a consumer lender. South Korean authorities have opened formal investigations and are probing whether artificial-intelligence (AI) tools were used to locate and exploit vulnerabilities.
Background & Context
AI-driven automation is reshaping cyber-crime by lowering the technical barrier for attackers. Open-source penetration-testing tools such as ARTEX, which runs on models from Anthropic or OpenAI, have been cited in Korean reports as possible vectors. Similar AI-enabled breaches have been reported in Australia, prompting regulators to question whether existing laws can keep pace with rapidly evolving AI capabilities.
Timeline
- Late September – Attackers accessed loan-lookup services and mobile-work support systems across multiple banks, extracting data over a roughly 30-hour window.
- Early October – The National Office of Investigation launched a formal inquiry.
- Following week – The Financial Services Commission ordered all financial firms to inspect every internet-facing system and remediate gaps by the upcoming Thursday.
- Subsequent days – Police opened a criminal investigation; regulators issued consumer alerts warning of potential fraud using the stolen loan information.
Data & Statistics
- Shinhan Bank: ? 25,000 customers affected.
- KB Kookmin Bank: 99 customers + 20 employees affected.
- Hana Bank: 89 customers affected.
- BNK Busan Bank: data on 11 outsourced developers exposed.
- Total compromised records exceed 25,000 individuals across the sector.
Official Statements & Responses
President Lee Jae Myung told his cabinet that “signs have emerged” of AI involvement, emphasizing the need for a “swift and clear” confirmation and rapid damage mitigation.
U.S. Federal Reserve Vice Chair for Supervision Michelle Bowman reiterated that “strong cyber hygiene” – including phishing-resistant multifactor authentication and robust identity-access controls – is essential to counter the gaps observed in Korea.
Conflicting Reports & Gaps
Two Korean news agencies offered differing technical explanations for how attackers bypassed Shinhan’s phone-verification step. Yonhap attributed the breach to credential stuffing, while Dong-A Ilbo described enumeration. Neither source clarified which method ultimately succeeded, and the bank’s notice only referenced “abnormal means” without specifying the technique.
Verbatim Quotes
- “It’s now become possible to use A.I. to hack with ease even without specialized skills,” — Mr. Lee, president
- “Generative AI was used to identify vulnerabilities and launch an attack. It’s not that South Korea has weak cybersecurity— this sort of thing could happen anywhere.” — The Financial Times (FT)
What’s Next
The Financial Services Commission has set a deadline for all banks to complete internet-facing system reviews and remediate identified vulnerabilities by the forthcoming Thursday. Police investigations remain ongoing, and regulators have warned that fraudsters could exploit the stolen loan data to craft convincing fake loan offers. Strengthening AI-driven defensive tools and enforcing rigorous third-party access controls will be critical to preventing similar incidents.
