Security

South Korea President Orders Probe After AI Assisted Data Breaches Hit Seven Financial Firms

President Lee Jae Myung ordered a full investigation on October 4, 2026, after data leaks spread from Shinhan Bank to at least seven banks and financial firms, with regulators suspecting AI tools.

T
By TechQuire Daily Staff TechQuire Daily Staff
October 4, 2026 / 7 min read

South Korean President Lee Jae Myung ordered a thorough investigation on October 4, 2026, into a widening wave of customer data leaks that began at Shinhan Bank on September 30 and has since spread across at least seven banks and financial firms, according to the presidential office. The Financial Services Commission (FSC) convened an emergency meeting the same day, with Chairman Lee Eog-weon warning that the financial sector must respond with the highest level of vigilance.

Reuters reported on October 4 that Lee ordered a thorough investigation and response measures over recent personal data leak incidents at banks, finance companies and public agencies. The FSC chairman convened the emergency meeting with financial industry associations, regulators and executives from affected institutions, and said authorities could not rule out the possibility that artificial intelligence (AI) was used in the attacks.

The breaches have touched Shinhan Bank, KB Kookmin Bank, Hana Bank, BNK Busan Bank, Yegaram Savings Bank, Welcome Savings Bank and Hyundai Capital, regulators said. Lee Eog-weon called for an 'AI attacks defended by AI' approach, signalling broader upgrades to the financial sector's cybersecurity framework.

Yonhap news agency reported that attack traffic originated from IP addresses in several countries, including the United States, Japan, Singapore, Vietnam and Britain. By October 4, South Korean outlets including Seoul Economic Daily and ChosunBiz put the combined number of affected customer or corporate records at well over 60,000.

Key Facts

At Shinhan Bank, the breach exposed personal and credit information tied to about 25,000 loan applications. The leaked data included names, phone numbers, annual income and calculated loan limits, along with 66 resident registration numbers and 97 connecting-information (CI) records. The unauthorized outsider accessed services between September 29 and the early hours of September 30, bypassing normal authentication through abnormal methods. Shinhan Bank President Jung Sang-hyuk issued an apology on October 1, and the bank pledged to fully compensate any customer losses.

Other institutions disclosed smaller but still significant counts. KB Kookmin Bank said personal information of 119 customers had been leaked due to an external intrusion. Hana Bank said 89 customers were affected from its operations support system. At BNK Busan Bank, the names, phone numbers, dates of birth and email addresses of 11 outsourced development staff were exposed. Hyundai Capital reported that personal data for 146 mortgage loan brokers was leaked, including names, contact information, email addresses and resident registration numbers.

Yegaram Savings Bank said the names, birth dates and contact details of roughly 40,000 customers were believed to have been exposed. The attack was first detected on September 29 and was only partly contained, with intruders continuing to hit six separate services, including its mobile loan-status page, even after the bank blocked the initial IP address. Welcome Savings Bank was reported to be investigating a leak involving up to 2,200 corporate customer records. Seoul Economic Daily reported on October 4 that attacks had also reached mutual finance institutions, with the Korean Federation of Community Credit Cooperatives and NongHyup's mutual finance arm blocking intrusion attempts.

Regulators moved quickly. The FSC had originally planned an emergency review meeting for October 7, but brought it forward to October 4 after additional breaches were discovered at second-tier financial institutions, including savings banks and capital companies. ChosunBiz reported on October 4 that the meeting was chaired by Lee Eog-weon and attended by the heads of financial industry associations and the chief executives of affected firms. The FSC directed financial institutions to carry out comprehensive security inspections, tighten access controls, minimise external system access and strengthen consumer protection, and said attack methods, IP addresses and other threat information would be rapidly shared across the industry.

Security researchers later found traces of a Chinese-language, open-source AI penetration-testing tool on infrastructure believed to be linked to recent attacks, though whether it was used in the Shinhan breach has not been confirmed. Startup Fortune reported on October 4 that detection took Shinhan Bank over 15 hours, while KB Kookmin took nearly three days. Yonhap reported on October 2 that attackers probably used sophisticated AI agents to probe for vulnerabilities and gain unauthorized access to a service used by loan recruiters.

Analysis

What this really means is that South Korea's financial sector is confronting a new class of automated, AI-assisted attacks that exploit the weakest links at the edges of bank networks. The breaches did not target the core systems that handle deposits and transfers. Instead, they hit loan broker inquiry services, employee-facing business support systems and other externally exposed tools. That pattern suggests attackers are scanning broadly for vulnerabilities rather than carefully targeting a single institution, as Yonhap reported regulators believe.

The FSC's Lee Eog-weon has said authorities cannot rule out that AI was used in the attacks, and he has called for an 'AI attacks defended by AI' approach. That is a recognition that human-speed security operations may no longer keep pace with automated probing tools. The attackers appear to have used AI to find openings across many systems at once, which explains why so many institutions reported breaches within days.

The bigger picture here is that the line between defensive and offensive AI has blurred. Mun Chong-hyun, director at cybersecurity firm Genians, said several recent attacks in South Korea have featured AI tools developed and shared for defensive purposes, but they can be a 'double-edged sword' when used in hacking attempts. As AI-related technologies advance, source codes are being shared indiscriminately and used for malicious AI hacking attempts, he added. Sungho Hwang, Korea country manager at NordVPN, noted that the breach is worrying because it exposed both personal and financial information, which can be used to craft personalized scams that generative AI has made more convincing.

The response so far has been rapid but reactive. President Lee Jae Myung ordered a full investigation on October 4, according to presidential spokesperson Kang Yu-jung, who said Lee wanted officials to act with 'a grave awareness of the seriousness of the matter.' The FSC has directed institutions to share threat information rapidly, including attack methods and IP addresses. Whether that will be enough to stop a broad, automated campaign remains an open question.

Why It Matters

For South Korean consumers, the leaks represent a direct threat. The exposed data includes names, phone numbers, annual income, loan limits and, in some cases, resident registration numbers and connecting-information records. That combination of personal and financial data is exactly what criminals need to impersonate customers, open fraudulent accounts or craft convincing phishing messages. Shinhan Bank has set up a look-up function on its website so customers can check whether their information was leaked, and plans to add a similar menu to Shinhan Super SOL, its integrated financial app.

The incident also raises political and geopolitical questions. The main opposition People Power Party said authorities should also investigate possible North Korean involvement, citing past attacks attributed to Pyongyang against South Korean financial institutions. Regulators have not publicly linked the current wave to any state actor, but the breadth of the attacks and the involvement of IP addresses from multiple countries have heightened concerns.

South Korea has suffered far larger breaches, including one at Lotte Card that exposed information belonging to nearly 3 million customers, and a hack at Coupang's South Korean unit that hit more than 33 million accounts. But the current wave is notable for its speed, its spread across different tiers of the financial system, and the suspected use of AI. That combination could force a fundamental rethink of how financial institutions secure their external services.

Next Up

On-site investigations are continuing at the affected institutions, and regulators are not ruling out additional unreported damage. The FSC has said attack methods, IP addresses and other threat information will be rapidly shared across the industry. The Korean Federation of Community Credit Cooperatives and NongHyup's mutual finance arm both blocked intrusion attempts, but the breadth of the attacks has raised the possibility that further damage will surface.

The FSC is also signalling broader upgrades to the financial sector's cybersecurity framework, including tighter access controls and reduced external system access. Whether those measures can keep pace with AI-assisted attackers will be the central test for South Korea's financial regulators in the months ahead.

Tagged

Comments (0)

No comments yet. Be the first to share your thoughts.