AI-linked attacks hit five South Korean banks; Shinhan confirms widest data exposure

AI-linked attacks hit five South Korean banks; Shinhan confirms widest data exposure
AI-linked attacks hit five South Korean banks between Oct 1–3. Shinhan reported the widest blow, with about 25,000 customers affected and fields like names, phone numbers, annual income, and loan limits exposed — including 66 resident registration numbers. Hana, KB Kookmin, and BNK reported much smaller counts; Woori and NongHyup reported no personal data exposed. Investigators say credential-stuffing was part of the attack, but the exact entry point at each bank is still unconfirmed.

Between October 1–3, 2026, attackers hit customer-facing systems at five South Korean financial institutions. Shinhan Bank reported the widest impact, with about 25,000 customers affected and a confirmed set of exposed fields. Hana Bank reported 89 customers affected via its ODS system, KB Kookmin Bank 119 via an employee mobile support system, and BNK Busan Bank about 11 outsourced development workers. Woori Bank and NH NongHyup reported attacks but no personal information exposed.

The access path is partly established and partly unresolved. Investigators with the Financial Services Commission and Financial Supervisory Service have said a credential-stuffing technique — bulk attempts with known username-and-password pairs on the assumption some are reused — was part of the attack. But the specific entry point at each bank has not been confirmed, and the agencies have not said which systems the login attempts targeted, so the confirmed technique does not yet pin down the vector.

ARTEX AI remains a suspicion

Investigators have traced a tool called ARTEX AI on a server linked to the Shinhan attack, which they suspect was used to automate the intrusions. Neither the banks nor the authorities have confirmed that the tool was actually used, so the precise mechanism — weak or reused credentials, a compromised worker account, or a platform vulnerability — remains undisclosed. What is confirmed is an AI-assisted element to the campaign, with Hana's incident attributed by investigators to AI tool use, but the specific tool chain is not established.

What got out

Exposed fields vary by institution. At KB Kookmin, reported leaks include names, phone numbers, addresses, and resident registration numbers. BNK Financial reported 11 records of outsourced employees' personal information. At Shinhan, the reported exposure includes names, phone numbers, annual income, and loan limits — and, more specifically, 66 resident registration numbers and 97 CI identifiers, alongside broader fields still under verification. The full loan-limit figures are reported exposure, not confirmed loss. Resident registration numbers carry a standing risk: unlike passwords, they don't expire after a breach and aren't rotated.

Scale and response

The confirmed leak is smaller than the attempted attack. Only certain fields at Shinhan, Hana, and KB Kookmin are confirmed exposed; the Woori and NongHyup attacks remain contained or unverified. The two- and three-figure counts at Hana and KB Kookmin are small against Shinhan's 25,000, so this is uneven damage rather than a uniform breach wave.

President Lee Jae-myung ordered a thorough probe of the financial and public-sector leaks. The Financial Services Commission, Financial Supervisory Service, and police opened investigations expected to run for months, with security officials convening an emergency meeting and ordering checks of externally accessible systems across the sector.

The decisive unknown remains the precise access path. Whether the entry came through reused credentials, a compromised employee account, or a platform vulnerability has not been disclosed, and neither the banks nor authorities have confirmed the ARTEX AI tool's actual use. Until that is pinned down, affected customers can't know which credentials were in play, and other institutions can't tell whether the same path is still open.