A wave of cyberattacks on South Korean banks, in which investigators have found signs that AI-based automation tools were used, has exposed personal and financial data of tens of thousands of customers. The breaches have prompted the country's president to order a full investigation into the security of the financial system.
The attacks, which took place between late 27 September and early 2 October, hit some of the country's largest lenders. Shinhan Bank, a unit of Shinhan Financial Group, said information on about 25,000 customers had been exposed, including names, phone numbers, annual income, loan limits and, in some cases, resident registration numbers.
Further disclosures followed. KB Kookmin Bank said data on 119 people, 99 customers and 20 employees, had been leaked, including names, phone numbers, addresses and encrypted registration numbers. Hana Bank reported that information on 89 customers had been exposed, including registration numbers, addresses, email addresses, phone numbers and workplace names. BNK Busan Bank said data on 11 outsourced development staff had been compromised.
Reports also identified breaches at Yegaram Savings Bank, affecting tens of thousands of customers, and at Hyundai Capital, involving data on housing loan agents. Woori Bank and Nonghyup were attacked using similar methods, but no leakage was confirmed.
The back door, not the front door
The attackers did not break into core banking platforms used by customers. Instead, they targeted peripheral systems: web pages used by loan recruiters and agents, and mobile work and sales support systems used by employees and contractors.
That pattern is significant. Banks typically invest most heavily in securing their customer-facing apps and core ledgers. Systems built for intermediaries and internal staff, sometimes developed by outside contractors, can receive less attention, yet they often connect to sensitive data.
Signs of AI at work
What has drawn particular concern is evidence that the attackers used automated, AI-driven tools. Investigators found traces of an AI-based automation tool in the Shinhan incident and reported common IP addresses across attacks on several financial institutions, according to reports.
An information security professor told South Korean broadcaster SBS that the attackers appeared to keep "breaching and pushing through until they find a way," adding that the timeframes involved meant manual work "would have been completely impossible."
Mun Chong-hyun, a director at cybersecurity firm Genians, warned that "as AI-related technologies advance, source codes are being shared indiscriminately and used for malicious AI hacking attempts, so many people need to take caution."
Authorities have not yet established unified attribution for the attacks or confirmed that AI systems independently carried them out. But the episode is one of the most prominent public cases of suspected AI-assisted intrusions against major financial institutions.
A swift official response
The response has escalated quickly. The Financial Supervisory Service launched an emergency on-site inspection after the Shinhan breach was reported on 1 October. Financial authorities held an emergency meeting and ordered a comprehensive inspection of all systems exposed to the internet across the sector. Police launched an investigation on 2 October.
On 4 October, President Lee Jae Myung ordered a thorough investigation, directing officials to develop response measures with "a grave awareness of the seriousness of the matter."
The risk that follows a breach




