South Korean President Lee Jae Myung ordered a thorough investigation on Oct. 4 into a series of data breaches affecting banks and other financial institutions, according to the presidential office.
The incidents have reached major commercial banks, a regional bank, a savings bank and a finance company. Tens of thousands of customers have been affected, while authorities are also investigating whether AI-assisted tools played a role. South Korea’s Financial Services Commission (FSC) has told the sector to tighten access controls, review exposed systems and share threat information quickly.
Breaches spread across South Korea’s financial sector
According to Korea JoongAng Daily, the incidents have affected major commercial banks as well as regional and nonbank financial institutions. The spread across different parts of the sector prompted regulators to widen their response beyond individual firms and call for broader security reviews.
| Shinhan Bank | About 25,000 customers |
| Hana Bank | 89 people |
| KB Kookmin Bank | 119 people |
| BNK Busan Bank | 11 outsourced developers |
| Yegaram Savings Bank | Roughly 40,000 customers |
| Hyundai Capital | 146 housing loan agents |
The Korea Times reported that the exposed information included names, phone numbers, annual income, and loan limits, while some customers’ resident registration numbers were also compromised. Financial authorities said they had not found evidence that sensitive information directly usable for unauthorized payments had been exposed, but warned that the stolen data could still support secondary attacks such as voice phishing.
Investigators are looking at possible AI-assisted attacks
FSC Chairman Lee Eog-weon said authorities could not rule out the possibility that AI was used in the attacks. He also called on financial firms to accelerate the use of AI-based security tools as investigators examine how the breaches were carried out.
The Korea Times, citing industry officials, reported that traces of a Chinese-language AI penetration-testing tool were found on a server believed to have been used in the Shinhan Bank attack. The server’s HTML title reportedly contained a phrase translating to “AI autonomous penetration testing console,” raising questions about a possible connection to ARTEX AI, an open-source autonomous penetration-testing system based on a large language model.
The reported server traces do not confirm that ARTEX AI was used to carry out the Shinhan breach, or that AI tools were involved in the other incidents. Police are investigating the attacks, while the FSC has publicly described AI involvement as possible rather than confirmed.
Regulators order tighter controls and faster threat sharing
Reuters reported that South Korean regulators directed financial institutions to conduct comprehensive security inspections, tighten access controls, minimize external system access and strengthen consumer protection measures.
The FSC also said attack methods, IP addresses, and other threat information would be shared quickly across the industry to help prevent additional incidents. The emergency response included banks, securities firms, insurers, credit card companies, savings banks and fintech companies, although Korea JoongAng Daily reported that several of those sectors had not shown signs of similar attacks at the time.
Reuters, citing Yonhap, reported that regulators believe attackers may have broadly scanned several financial companies for vulnerabilities rather than concentrating on a single institution.
Must-read security coverage
- UK Police Convicts Pair in £5.5 Billion Bitcoin Launder Case
- Blackpoint Cyber vs. Arctic Wolf: Which MDR Solution is Right for You?
- How GitHub Is Securing the Software Supply Chain
- 8 Best Enterprise Password Managers
Attack traffic crossed several APAC countries
Reuters, citing Yonhap’s reporting on bank data submitted to lawmakers, said attack traffic came from IP addresses in the United States, Britain, Japan, Singapore and Vietnam. The IP locations show the international footprint of the traffic, but do not establish where the attackers themselves were located.
For financial institutions across APAC, South Korea’s response puts attention on internet-facing systems, access controls and rapid sharing of threat indicators between institutions. The data already exposed also creates a separate risk, as attackers could use legitimate personal and financial details to make phishing or social engineering attempts more convincing.
For security teams, the practical takeaway is to review externally accessible systems and access permissions, share threat indicators promptly, and prepare for phishing attempts that exploit exposed customer details.
Other news: AI coding agents reportedly exposed 13,000 internal screenshots from 343 tech companies in public GitHub repositories, highlighting how weak approval and audit controls can turn routine agent workflows into data leaks.