South Korean President Lee Jae Myung on Sunday, October 4, 2026 ordered a thorough investigation into a string of data breaches at banks and other lenders, after Shinhan Bank, KB Kookmin Bank, Hana Bank and BNK Busan Bank disclosed intrusions within two days of each other. According to presidential spokesperson Kang Yu-jung, as reported by DataBreaches.net, the president directed officials to "conduct a thorough investigation and make every effort to devise measures, with a grave awareness of the seriousness of the matter."
What sets this South Korea bank breach apart from earlier incidents is the open question at its centre: whether an AI-based autonomous penetration testing tool helped the attackers. Traces of such a tool were found on infrastructure linked to the Shinhan intrusion, but as of this writing regulators say only that they cannot rule AI out. This piece sets out what is confirmed, what is suspected, and what the episode suggests about AI-assisted offensive tooling and financial-sector defence.
What Happened: A Timeline of the Breaches
Korea JoongAng Daily reports that the intrusions took place between September 27 and 30, 2026, and that they hit Shinhan Bank, KB Kookmin Bank, Hana Bank, BNK Busan Bank, Yegaram Savings Bank and Hyundai Capital. A later Korea JoongAng Daily analysis adds Welcome Savings Bank, whose internal review uncovered a leak on Saturday, October 3. The Korea Times puts the total at seven financial firms and more than 67,000 people.
The disclosures came in sequence:
- Thursday, October 1: Shinhan Bank disclosed a breach affecting about 25,000 customers, per DataBreaches.net. Korea JoongAng Daily later gave the precise count as 25,727.
- Friday, October 2: KB Kookmin, Hana and BNK Busan reported separate exposures. The National Police Agency's Cyber Terror Response Investigation Unit said the same day it had opened a preliminary inquiry, according to The Asia Business Daily.
- Friday to Saturday: Yegaram Savings Bank disclosed a leak involving about 40,000 customers, and Aju Press reports that Hyundai Capital said personal data of 146 housing-loan agents had been exposed.
- Sunday, October 4: The Financial Services Commission (FSC) convened an emergency meeting with industry executives, brought forward from October 7 because of the new breaches, per Aju Press. President Lee ordered the probe the same day.
Aju Press also reports that Woori Bank and NH NongHyup Bank were targeted but had no confirmed leaks.
Exposed records by institution, September 2026 intrusions
People or records reported exposed, as of October 4, 2026. Figures are preliminary and the categories differ (customers, agents, staff, corporate records).
Sources: Korea JoongAng Daily; Aju Press (Hyundai Capital). Hover a bar for what was counted.
What Data Was Exposed, and What Was Not
At Shinhan, the leaked fields included customer names, phone numbers, annual income and calculated loan limits, as well as some resident registration numbers, according to The Herald Business. Korea JoongAng Daily lists names, contact details, resident registration numbers, customer identification numbers, loan application details and credit limits across the affected firms.
Just as important is the entry point. Per Korea JoongAng Daily, the attackers did not go through the mobile apps or internet banking that customers use. They hit side doors: portals for employees, outsourced developers and the loan agents who sell credit on the banks' behalf. Shinhan's exposure came through a service used by loan recruiters, while KB Kookmin and Hana leaked data through employee business-support and sales-support systems, according to The Herald Business. At BNK Busan, the exposed records belonged to 11 outsourced development staff.
A regulatory source quoted by Korea JoongAng Daily said passwords and card verification codes were not directly exposed, so the likelihood of immediate unauthorized transactions is low. The risk analysts point to is secondary. Hwang Sung-ho of Nord Security told the Korea Times that "when criminals connect a phone number to someone's income or loan limit, they gain enough context to create convincing personalized scams." Voice phishing and smishing are the obvious follow-on threats.

The AI Question: What Investigators Found, and What They Have Not Proven
The AI angle traces back to an analysis published on October 2 by Moon Jong-hyun, head of the Genians Security Center, according to the Seoul Economic Daily. He found a Chinese-language string translating to "AI autonomous penetration testing console" on web servers believed to have been used in credential stuffing and API vulnerability attacks against multiple Korean sites. The string is associated with ARTEX AI, an open-source penetration testing framework.
What is publicly known about ARTEX comes from press reporting rather than a forensic report:
- It is described by the Seoul Economic Daily as an LLM-based system that combines large language models with multiple agents to automate vulnerability scanning, target identification, attack-path planning, tool execution and vulnerability verification.
- The Kyunghyang Shinmun reports it was released on GitHub on July 26, 2026 under the account "Autumn-27", with its latest version published on September 24, days before the intrusions began.
- Both outlets report that it won an offensive and defensive agent challenge run by Baidu's security response centre this year.
The caveat is significant. The Seoul Economic Daily notes that the string appeared in HTML page titles and that whether ARTEX AI was actually used in the Shinhan breach "has not been confirmed so far." FSC Chairman Lee Eog-weon framed it the same way at the emergency meeting, per Korea JoongAng Daily:
We cannot rule out the possibility that AI was used in the attacks.
FSC Chairman Lee Eog-weon, October 4, 2026
Aju Press quotes officials saying AI agents "may have been used to automate vulnerability searches and penetration attempts," while stressing that this is "not yet conclusively established." Several outlets have reported the AI link more definitively in their headlines. Until a forensic finding is published, the accurate summary is that AI involvement is suspected and under investigation, while the underlying technique, credential stuffing with previously leaked data, is a long-established one that does not require AI.
Why AI-Assisted Offensive Tooling Matters Here
Credential stuffing means replaying username and password pairs leaked elsewhere until some succeed. It works because people reuse passwords, and South Korea has a large pool of leaked personal data to draw on. Aju Press notes the country has been through a major breach wave since 2025, including a SK Telecom incident affecting 23.24 million people, and cites 447 breach reports in 2025, up 45.6% from the year before.
What an autonomous tool would change is not the technique but the economics around it. Korea University professor Lim Jong-in told the Korea Times that AI agents are "capable of automatically searching for vulnerabilities, choosing to target servers operated by partner companies rather than directly attacking banks' main systems." That description fits the pattern of entry through loan-agent, contractor and employee portals. Those systems are often less hardened than the core banking stack but still connect to customer data.
The concern is consistent with what the wider industry has been reporting. Our coverage of Microsoft's Digital Defense Report 2026 describes AI shortening the time from vulnerability to exploitation. The same tools that let a defender run continuous automated penetration tests let an attacker run the same loop across hundreds of targets. ARTEX was published as a penetration testing framework, which is a legitimate category of security software. Whether a given tool is used for testing or for intrusion depends on who points it at what.

Detection Gaps and the Financial-Sector Response
The detection times reported by Korea JoongAng Daily are a central part of the story. Shinhan took 15 hours and 26 minutes to detect its intrusion, Hana took 41 hours and 44 minutes, and KB Kookmin took 67 hours and 41 minutes. The Korea Times reports that Shinhan, KB Kookmin and Hana together spent 124 billion won (about $92 million) on information security in the previous year. The two figures together suggest the issue is less the size of the budget than where monitoring is pointed, though no regulator has published that conclusion.
The measures announced so far, per Korea JoongAng Daily, Aju Press and the Seoul Economic Daily:
- Shared indicators: the FSC identified malicious IP addresses tied to the same attacker across the affected firms and alerted roughly 500 financial firms.
- Emergency checks: firms were told to run emergency security inspections and submit findings by Thursday, October 8, with a warning of stern penalties for similar failures.
- Heightened alert: the Seoul Economic Daily reports the government raised its cyber threat level from "interest" to "caution."
- On-site work: the Kyunghyang Shinmun reports the Financial Security Institute has launched on-site investigations.
Hwang Suk-jin of Dongguk University told the Korea Times that "defenses cannot remain fragmented at the level of individual companies." The point is structural. If one actor uses one toolchain against many institutions, the defenders' advantage lies in pooling telemetry quickly, which is what the IP sharing exercise attempts.
Historical Context and Second-Order Implications
The October 4 response was sector-wide rather than firm-by-firm: shared indicators, a common deadline and a common penalty warning. Several second-order effects are worth tracking:
- Third-party and agent portals move up the risk register. The breaches exploited systems built for people adjacent to the bank rather than its customers. Expect scrutiny of how loan brokers, contractors and staff authenticate.
- Attribution standards for "AI attacks." If investigators confirm ARTEX use, it would be a publicly documented case of an open-source autonomous pentest tool linked to a financial-sector intrusion at several major banks at once. If they do not, the episode will still shape how quickly AI is blamed in future incidents.
- Open-source security tooling policy. Dual-use tools are common in security. Pressure to restrict them tends to rise after incidents like this, though the coverage reviewed for this piece reports no such proposal.
- Phishing aftermath. Income and loan-limit data is useful for targeted scams, so the customer-facing impact may arrive weeks later.
What to Watch
- The October 8 inspection results and whether the FSC publishes a consolidated finding.
- Forensic confirmation of whether ARTEX or any other AI tool was used, and in which stage of the attack.
- Penalties under South Korea's privacy and financial rules, once the scope is final.
- Further disclosures, since the shared IP list went to about 500 firms and more institutions may find traces.
FAQ
Which banks were breached in South Korea in 2026? Shinhan Bank, KB Kookmin Bank, Hana Bank and BNK Busan Bank, plus Yegaram Savings Bank, Welcome Savings Bank and Hyundai Capital, according to Korean press reports. Woori Bank and NH NongHyup Bank were targeted without confirmed leaks.
Was AI used in the Shinhan Bank hack? Not confirmed. Traces of the ARTEX AI penetration testing tool were found on a server believed to be linked to the attack, but the FSC chairman said only that AI involvement cannot be ruled out.
Were passwords or card details leaked? A regulatory source told Korea JoongAng Daily that passwords and card verification codes were not directly exposed, so immediate unauthorized transactions are considered unlikely. Names, phone numbers, income and loan data were exposed.
What is credential stuffing? An attack that replays username and password pairs leaked from other services until some work, exploiting password reuse.
Sources:
- South Korea's President Lee Jae Myung orders thorough probe into data breaches at local banks | DataBreaches.net
- AI hackers target Korea's banks, trigger industrywide security review | Korea JoongAng Daily
- From banks to lenders, suspected AI hacks expose cracks in Korea's financial defenses | Korea JoongAng Daily
- AI-linked cyberattacks spread across South Korean finance | Aju Press
- AI-powered attacks on banks expose technological lag in Korea's financial cyber defenses | The Korea Times
- Traces of Chinese AI Hacking Tool Found on Server Tied to Shinhan Bank Breach | Seoul Economic Daily
- Lee Orders Full Probe Into String of Bank Data Breaches | Seoul Economic Daily
- Korean finance breached by a two-month-old Chinese AI | The Kyunghyang Shinmun
- Shinhan, Kookmin, Hana banks breached in wave of cyberattacks ahead of parliamentary audit | The Herald Business
- Police Launch Preliminary Probe into Widespread Bank Hacking | The Asia Business Daily
- South Korea Orders Investigation Into AI-Powered Cyberattacks on Major Banks | GBHackers
Image credits
Header image: Cityscape of Yeouido skyscrapers and Hangang Railway Bridge, by TurnOnTheNight via Wikimedia Commons, licensed under CC BY-SA 4.0.
In-body image: Shinhan Bank branch at Wonju City Hall, by Choi Kwang-mo via Wikimedia Commons, released under CC0.