TechArtificial Intelligence6 MIN READ

AI-Assisted Hacks Hit South Korea's Biggest Banks, Prompting a Presidential Order for Full Security Checks

Breaches at Shinhan, KB Kookmin, Hana and BNK Busan banks, with signs that AI automation tools were used, have exposed data on tens of thousands of customers and prompted President Lee Jae Myung to order an investigation.

By Aravind Kumar · Author5 October 2026Breaking
AI-Assisted Hacks Hit South Korea's Biggest Banks, Prompting a Presidential Order for Full Security Checks

A wave of cyberattacks on South Korean banks, in which investigators have found signs that AI-based automation tools were used, has exposed personal and financial data of tens of thousands of customers. The breaches have prompted the country's president to order a full investigation into the security of the financial system.

The attacks, which took place between late 27 September and early 2 October, hit some of the country's largest lenders. Shinhan Bank, a unit of Shinhan Financial Group, said information on about 25,000 customers had been exposed, including names, phone numbers, annual income, loan limits and, in some cases, resident registration numbers.

Further disclosures followed. KB Kookmin Bank said data on 119 people, 99 customers and 20 employees, had been leaked, including names, phone numbers, addresses and encrypted registration numbers. Hana Bank reported that information on 89 customers had been exposed, including registration numbers, addresses, email addresses, phone numbers and workplace names. BNK Busan Bank said data on 11 outsourced development staff had been compromised.

Reports also identified breaches at Yegaram Savings Bank, affecting tens of thousands of customers, and at Hyundai Capital, involving data on housing loan agents. Woori Bank and Nonghyup were attacked using similar methods, but no leakage was confirmed.

The back door, not the front door

The attackers did not break into core banking platforms used by customers. Instead, they targeted peripheral systems: web pages used by loan recruiters and agents, and mobile work and sales support systems used by employees and contractors.

That pattern is significant. Banks typically invest most heavily in securing their customer-facing apps and core ledgers. Systems built for intermediaries and internal staff, sometimes developed by outside contractors, can receive less attention, yet they often connect to sensitive data.

Signs of AI at work

What has drawn particular concern is evidence that the attackers used automated, AI-driven tools. Investigators found traces of an AI-based automation tool in the Shinhan incident and reported common IP addresses across attacks on several financial institutions, according to reports.

An information security professor told South Korean broadcaster SBS that the attackers appeared to keep "breaching and pushing through until they find a way," adding that the timeframes involved meant manual work "would have been completely impossible."

Mun Chong-hyun, a director at cybersecurity firm Genians, warned that "as AI-related technologies advance, source codes are being shared indiscriminately and used for malicious AI hacking attempts, so many people need to take caution."

Authorities have not yet established unified attribution for the attacks or confirmed that AI systems independently carried them out. But the episode is one of the most prominent public cases of suspected AI-assisted intrusions against major financial institutions.

A swift official response

The response has escalated quickly. The Financial Supervisory Service launched an emergency on-site inspection after the Shinhan breach was reported on 1 October. Financial authorities held an emergency meeting and ordered a comprehensive inspection of all systems exposed to the internet across the sector. Police launched an investigation on 2 October.

On 4 October, President Lee Jae Myung ordered a thorough investigation, directing officials to develop response measures with "a grave awareness of the seriousness of the matter."

The risk that follows a breach

“As AI-related technologies advance, source codes are being shared indiscriminately and used for malicious AI hacking attempts, so many people need to take caution.”
— Mun Chong-hyun, director, Genians

Beyond the immediate leak, security experts warn that the stolen data could fuel further fraud. Sungho Hwang, a manager at NordVPN Korea, noted that the Shinhan breach exposed both personal and financial information, which could enable highly personalised scams enhanced by generative AI.

Information such as income levels and loan limits is particularly valuable to fraudsters. It allows them to craft convincing messages posing as banks or lenders, offering loans or demanding repayments. Combined with AI tools that can generate realistic text and voice, such data can make phishing attempts much harder to detect.

758dd2fc-5a3d-497b-923a-6d90ed7dc4e1.png

Why the world is watching

South Korea has one of the most digitally advanced banking systems in the world, with very high rates of mobile banking adoption. That makes it an early indicator of the threats other markets may face.

The episode illustrates a concern regulators have raised for some time: that AI lowers the cost and increases the speed of cyberattacks. Tasks that once required skilled hackers working for days, such as scanning for vulnerabilities, testing many variations of an attack or adapting to defences, can increasingly be automated.

For banks, that changes the economics of defence. Systems that were considered low risk because they were obscure or had limited exposure may no longer be safe if automated tools can probe them continuously. ## How AI changes the attacker's toolkit

Security specialists describe several ways AI can amplify attacks of this kind. Automated tools can scan large numbers of web pages and applications for known weaknesses far faster than human teams. They can generate and test many variants of an exploit, adapting when one is blocked. And they can analyse the responses they receive to decide what to try next.

None of these techniques is new. What AI changes is their cost and scale, allowing small groups to run campaigns that once required large, skilled teams. That is why defenders increasingly argue that they will need AI-driven monitoring of their own to keep pace.

Lessons for India's banks and fintechs

For India, where digital payments and mobile banking have grown at extraordinary speed, the Korean breaches carry clear lessons. Indian banks and non-bank lenders rely heavily on networks of agents, direct selling associates and third-party technology vendors. Each of those connections can become an entry point.

The Reserve Bank of India has tightened requirements on IT governance, outsourcing and cyber resilience in recent years. The Korean case suggests that supervisors and boards should pay particular attention to peripheral systems, contractor-built applications and agent portals, and to the ability to detect automated, high-speed probing.

Fintech companies that integrate with banks through APIs face similar exposure. As AI-driven attacks become more common, security reviews that once took place annually may need to become continuous.

What comes next

South Korean authorities are expected to report on the results of the sector-wide inspection and may introduce new requirements for securing externally exposed systems. Banks are likely to face questions from lawmakers, and potentially penalties, depending on what investigators find about their controls.

For the global financial industry, the breaches are a warning that the use of AI in cyberattacks is no longer theoretical. Defences built for human-paced threats will need to adapt to adversaries that never tire.

TagsCybersecurityAI HackingSouth KoreaShinhan BankKB Kookmin BankHana BankData BreachBanking SecurityFinancial Supervisory ServiceAI AgentsFintechCyber RiskPersonal DataFinancial Regulation

Reader reviews

Sign in to rate and review this article.
Loading reviews…