South Korea's financial regulator has ordered an industry-wide security review after a string of suspected AI-assisted cyberattacks swept through the country's banking sector, exposing personal data of tens of thousands of customers across at least four institutions.
Shinhan Bank disclosed the largest breach: an attacker bypassed identity verification in a simplified inquiry service used by loan solicitors and extracted records on 25,729 customers, including names, phone numbers, annual income, loan limits and resident registration numbers. The bank's internet and mobile banking systems, which sit behind login authentication, were not compromised.
The attacks then spread. KB Kookmin Bank said on Friday that personal and credit information belonging to 119 customers leaked after an external intrusion into a mobile work-support system used by employees. Hana Bank confirmed that its sales support system, known internally as ODS, was breached and seven categories of data on 89 customers were taken, including resident registration numbers, addresses and employer names. BNK Busan Bank reported 11 outsourced development staff exposed, while Woori Bank and NH NongHyup Bank said they blocked similar attempts before any data left their networks. Hyundai Capital separately disclosed exposure of data belonging to 146 housing loan agents.
What sets this episode apart is the profile of the attacker. Korean financial authorities said they found signs the same actor was using AI tools to rotate IP addresses and automate attacks against multiple financial firms in parallel, probing employee-facing and support systems rather than core banking infrastructure. IP lists submitted to lawmakers included addresses in the United States, Japan, Singapore, Vietnam, the United Kingdom and Hong Kong, China. No financial transaction data has been reported stolen in any of the confirmed breaches.
The Financial Services Commission convened an emergency meeting chaired by Secretary General Shin Jin-chang, bringing together the Financial Supervisory Service, the Financial Security Institute, major banks, card companies and industry associations. FSC Chairman Lee Eog-weon, who met industry executives again on Sunday, said authorities could not rule out that AI was used in the attacks and called on the sector to adopt a "defend AI with AI" posture. Firms were ordered to inventory externally accessible IT assets — explicitly including AI systems — and to check for any path into internal data that skips authentication.
President Lee Jae-myung on Sunday ordered a thorough investigation and a full set of countermeasures, according to the presidential office. The National Police Agency's cyber terror investigation unit has opened a pre-indictment probe into the institutions that formally reported damage.
The breaches land awkwardly for an industry that was already on alert: nearly 240,000 hacking attempts targeted Korea's court network between January and August this year, more than double the figure for all of 2025. With the National Assembly audit approaching, lawmakers are expected to push for accountability — and the episode offers a concrete data point in a debate that has until now been mostly theoretical: automated, AI-driven reconnaissance has become cheap enough that even well-defended institutions bleed data through their least glamorous systems.
Comments (0)
Log in to join the discussion
Log InNo comments yet