In brief
South Korea investigates bank breaches in which AI hacking tools are suspected
At least seven banks and lenders reported intrusions from late September 2026. Attackers took loan and income data through side systems rather than core banking networks.
- Event date
- Published
- Reading time
- 1 min
South Korean police set up a 28-member investigation team on 6 October 2026 after a series of intrusions at banks and lenders that officials suspect were carried out with the help of artificial intelligence tools.
“In some hacking incidents, signs have emerged of AI being used, causing considerable public concern and anxiety,” President Lee Jae Myung told a cabinet meeting the same day, according to Reuters. He did not name a tool or model.
The incidents came to light on 30 September. At least seven financial institutions had reported breaches by 6 October, and the personal data of at least 68,000 people was reported to have been exposed, the cybersecurity news site The Record said. Shinhan Bank said information on about 25,000 customers was taken, including names, phone numbers, incomes and borrowing limits. Yegaram Savings Bank reported about 40,000 affected customers. KB Kookmin Bank and Hana Bank reported 119 and 89 people affected respectively, the Korea JoongAng Daily reported.
The attackers did not reach the networks that hold account balances. They came in through internet-facing side systems: a lookup service Shinhan had built for outside loan recruiters, a mobile work system for staff at KB Kookmin and a sales-support system at Hana, the trade publication American Banker reported. Passwords and card security codes were not exposed, a regulatory source told the JoongAng Daily, but officials warned that detailed loan data could make phone fraud more convincing.
Evidence of AI involvement is partial. A researcher found a server thought to have been used against Shinhan that carried the name of ARTEX, an open-source penetration-testing tool driven by AI agents, and investigators at the Financial Security Institute traced Shinhan’s logs to similar evidence, American Banker reported. No regulator had publicly named the tool, and an official at the institute said the AI “did not act independently without human involvement”.
“We cannot rule out the possibility that AI was used in the attacks,” said Lee Eog-weon, chairman of the Financial Services Commission, on 4 October. Regulators ordered financial firms to check every internet-facing system, to stop storing credit data unnecessarily, and to report by 8 October.
Sources
- South Korean officials believe AI agents were used to hack several banks
- From banks to lenders, suspected AI hacks expose cracks in Korea's financial defenses
- AI-linked hacks hit Korean banks through loan-agent sites
Spotted an error? See how to request a correction.


