South Korea's financial regulators and police are investigating a chain of cyber intrusions at seven banks and lenders that exposed the personal data of more than 68,000 customers, an episode that President Lee Jae Myung said on October 6, 2026 shows signs that artificial intelligence was used to carry out the attacks. Officials describe the incidents, which first came to light on September 30, as the first known example of AI agents being used to hack the financial sector, a development that has alarmed regulators and pushed the government to order immediate defensive measures across the industry.
The breaches struck Shinhan Bank, KB Kookmin Bank, Hana Bank, BNK Busan Bank, Hyundai Capital, Yegaram Savings Bank and Welcome Savings Bank, according to the Financial Services Commission, which puts the total number of affected people at more than 68,000. The attackers did not go through customer facing mobile or internet banking, officials said. Instead they entered through side doors, including portals used by employees, outsourced developers and loan agents, which allowed them to reach sensitive files without triggering the identity checks that protect consumer accounts.
President Lee told a cabinet meeting on October 6 that signs have emerged suggesting AI agents were deployed in at least some of the attacks. It has now become possible to use AI to hack with ease even without specialized skills, Lee said, The Record reported on October 6. The National Office of Investigation responded the same day by creating a team of 28 investigators to pursue the case on suspicion of violations of the information and communications network law.
Regulators moved on a separate track. The Financial Services Commission ordered every financial firm in the country to shut off outside access to its systems unless that access is essential to the business, and it met industry chiefs on October 4, the same day President Lee ordered a thorough investigation. The Financial Supervisory Service said the investigation has so far identified 33 IP addresses used in the hacks, linked to at least 12 countries, including Japan, the United States, Thailand, Vietnam and Hong Kong.
Key Facts
The firm by firm toll illustrates how uneven the damage was. Shinhan Bank reported that personal data belonging to roughly 25,000 customers was exposed, while Korea JoongAng Daily put the figure at 25,727 records, including loan limits, 66 resident registration numbers and 97 connecting information values. Yegaram Savings Bank disclosed about 40,000 records, the largest total at a single firm. KB Kookmin lost data on 119 customers, Hana Bank on 89, BNK Busan Bank on 11 outsourced developers, Hyundai Capital on 146 mortgage loan agents, and Welcome Savings Bank on up to 2,200 corporate records, Global1 News reported on October 6.
Detection was slow across the board. Shinhan Bank took 15 hours 26 minutes to detect its intrusion, Hana Bank took 41 hours 44 minutes, and KB Kookmin Bank took 67 hours 41 minutes, according to Martin Cid Magazine, which reported on October 6 that the three banks together spent 124 billion won, or about 92 million dollars, on information security last year. Woori Bank and NH Nonghyup Bank were also targeted but managed to block access, the same account said.
The stolen files hold names, phone numbers, resident registration numbers, which serve as South Korea's lifelong national identifier, annual income, credit limits and loan application details. A regulator source said passwords and CVC numbers were not directly exposed, and authorities stressed that nothing taken can be used on its own to make payments. The warning instead concerns a second wave of voice phishing and fraudulent text messages that could use the leaked details to impersonate banks or loan officers. The Record reported on October 6 that the breached data included customers' borrowing history, incomes, phone numbers and names.
Investigators have pointed to ARTEX AI, a Chinese language open source security testing tool distributed through GitHub that uses a large language model to scan for weaknesses and plan a route into a network. Analysts at the Korea Financial Security Institute identified it through a data signature its traffic leaves behind, according to Herald Business, and officials caution that a human directed the attacks even if an AI tool helped plan them. A government official told AFP it was highly likely that ARTEX AI was involved.
Yonhap News Agency reported on October 6 that police formed the 28 member team and that officials are reviewing whether the case should be sent to the newly launched Serious Crime Investigation Agency, which handles cyber crimes against key state facilities and hacks into electronic financial infrastructure. The National Office of Investigation said it will carry out an investigation swiftly and strictly while closely cooperating with relevant agencies to ease the public's anxiety.
Analysis
What this really means is that the cost of mounting a credible attack on a bank has fallen far enough that open source tooling and a single operator can threaten institutions that spend tens of millions of dollars a year on defense. The tool at the center of this case, ARTEX AI, was built to test defenses, not to breach them, yet investigators say its traces appeared on an attack server used against seven lenders. When a defensive instrument can be turned into an offensive one with little more than a change of intent, the traditional advantage held by well funded security teams erodes quickly.
The bigger picture here is that the weakest link was not the core banking platform but the side doors that surround it. The attackers went after portals for employees, outsourced developers and loan agents, not the mobile and internet banking apps that customers use every day. That pattern fits a broader shift in financial cybercrime, where intruders hunt for third party access points that are less monitored and less protected by the layered controls applied to consumer channels. Shinhan Bank, for instance, saw an attacker get past identity checks on a service reserved for loan brokers.
The slow detection times reinforce the same judgment. Shinhan Bank needed more than 15 hours to notice its breach, Hana Bank nearly 42 hours and KB Kookmin almost 68 hours, despite the combined 124 billion won that the three institutions spent on information security last year. Spending on security tools does not automatically translate into visibility across every portal an institution operates, and the delays gave attackers time to extract records from systems that were not part of the main banking perimeter.
Attribution remains unsettled, and officials have been careful not to overstate what the evidence shows. The 33 IP addresses span at least 12 countries, including Japan, the United States, Thailand, Vietnam and Hong Kong, which complicates any simple story about a single national actor. The presence of a Chinese language tool does not by itself prove state involvement, and the Financial Services Commission chair, Lee Eog-weon, has said regulators cannot rule out AI involvement while stopping short of a definitive conclusion. What is clear is that a human directed the campaign, and that the technical barrier that once separated skilled intruders from opportunists has narrowed.
Why It Matters
The leaked records matter because they are the raw material for follow on fraud. South Korea's resident registration number is a lifelong identifier used across government and private services, and when it is combined with names, phone numbers, incomes and loan details, criminals gain a detailed profile that can make a phishing call or text far more convincing. Regulators have said the immediate risk is not unauthorized payments but a second wave of voice phishing and fraudulent messages that could target the same 68,000 people whose data was exposed.
The scale of the response also signals how seriously authorities view the precedent. The Financial Services Commission ordered every financial firm in the country, roughly 500 of them, to cut outside access unless it is essential, a sweeping measure that prioritizes containment over convenience. Yonhap News Agency reported on October 6 that police are treating the case as a test of whether existing laws and investigative bodies can keep pace with AI assisted attacks. If the case is referred to the Serious Crime Investigation Agency, it would mark an escalation in how South Korea classifies hacks against electronic financial infrastructure.
For the global financial industry, the episode offers an early warning. Banks in other markets rely on similar third party portals and loan agent systems, and the same open source tools are available to anyone with an internet connection. The first known case of AI agents being used to hack the financial sector is now a South Korean case study, and supervisors elsewhere are likely to ask whether their own institutions can detect an intrusion in hours rather than days.
Next Up
Investigators will continue to trace the 33 IP addresses and the server that carried the ARTEX AI signature, while the National Office of Investigation decides whether to hand the case to the Serious Crime Investigation Agency. The Financial Services Commission and the Financial Supervisory Service are expected to publish further findings, and the seven affected lenders face questions about why detection took so long and how much data left their systems before the breaches were contained.
Financial firms, meanwhile, are already adjusting. The order to shut off nonessential outside access is likely to remain in place while the probe continues, and institutions will be under pressure to map every portal used by employees, contractors and sales agents. The outcome will shape how South Korea regulates AI era security, and whether the tools that were meant to test defenses end up forcing a broader rethink of who gets access to sensitive financial systems.
Comments (0)
Log in or sign up to leave a comment.
No comments yet. Be the first to share your thoughts.