An intrusion campaign that began with the Shinhan Bank breach has spread across South Korea's financial sector. KB Kookmin Bank, Hana Bank, BNK Busan Bank, Yegaram Savings Bank, Hyundai Capital and Welcome Savings Bank have all confirmed data leaks. Financial authorities say they found related attacker IP addresses at seven firms. The Financial News puts the total at about 66,000 individuals plus up to 2,200 corporate records. Investigators and security researchers suspect the attacker used an AI-driven automated penetration tool. The attacks went after loan-broker lookup pages, employee work-support systems and other externally reachable systems with weak access controls, not core banking platforms. President Lee Jae-myung has ordered a full investigation. On October 4, a public holiday, the Financial Services Commission called an emergency meeting of the whole sector and moved it forward from October 7.
A note on sourcing: every source available for this brief is press reporting. Most of it quotes statements from the affected institutions and regulators directly, but none is a primary disclosure. Figures below are attributed where they differ.
What Happened
Most reports place the intrusions between September 27 and 30, 2026. Kyunghyang Shinmun gives that window for the core group of victims.
- Shinhan Bank (covered previously) said an unauthorized party bypassed authentication on the "M Shinhan" mobile loan-broker inquiry service between September 29 and the early hours of September 30. This was the first breach made public, on October 1.
- KB Kookmin Bank said it recognized possible leakage through abnormal external access on the night of September 30. The entry point was a mobile work-support system used by employees. KB blocked the server and the access route, and says the system is separate from internet and mobile banking.
- Hana Bank said "an external hacking agent gained abnormal access to our operations support system (ODS)." It blocked the affected servers and access routes.
- BNK Busan Bank said a mobile sales-support system was attacked, exposing personal details of 11 outsourced developers.
- Hyundai Capital told SBS that it found the attack on September 27 while checking overseas IP addresses that regulators had shared from the Shinhan investigation. The target was a page customers use to look up mortgage loan recruiters. It blocked the IP and the page on October 2 and set up a dedicated response task force. The company says ordinary customer data and its internal systems were not compromised.
- Yegaram Savings Bank, a Taekwang Group affiliate, posted a notice and an apology from CEO Moon Yoon-seok. It said that on September 30 it confirmed an unidentified hacker had accessed a server holding customer personal information. SBS reports the bank found no access to its internal systems.
- Welcome Savings Bank said an internal inspection on October 3 found an intrusion into a system related to corporate customers.
Several institutions blocked attempts. Woori Bank and NH NongHyup Bank were both targeted, and neither has confirmed a leak. SBS obtained a Woori internal report showing nine access attempts from three suspicious IP addresses, all stopped at the firewall. The Financial News reports that the Korean Federation of Community Credit Cooperatives (MG Saemaeul Geumgo) found access attempts from the same IP used against Shinhan and blocked them. It also reports that Nonghyup mutual finance, which shares a network with NH NongHyup Bank, blocked similar attempts.
The victim count varies by source. The Financial News and Digital Today count seven firms with confirmed leaks. Kyunghyang Shinmun adds two online investment-linked (P2P) finance companies, which would make the total higher. Kyunghyang also notes that analysts think the number of firms that faced attempted attacks may be much larger.
What Was Taken
Per-institution figures, as reported:
- Shinhan Bank: reports range from "about 25,000" (Seoul Economic Daily, Aju Press, Money Today) to 25,727 (Kyunghyang Shinmun) to 25,729 (Financial News). The data includes names, phone numbers, annual income and calculated loan limits. It also includes 66 resident registration numbers (RRNs) and 97 connecting information (CI) records, which are Korea's cross-service identity keys.
- Yegaram Savings Bank: about 40,000 customers (Aju Press, SBS, Financial News). The data includes names, dates of birth and contact details.
- Hyundai Capital: 146 mortgage loan recruiters. The data includes names, mobile numbers, email addresses, RRNs and internal recruiter numbers that are not otherwise public.
- KB Kookmin Bank: 119 customers. The data includes names, phone numbers, addresses and encrypted RRNs.
- Hana Bank: 89 customers. The data includes RRNs, names, addresses, email addresses, phone and mobile numbers, and employer names.
- BNK Busan Bank: 11 outsourced developers. The data includes names and phone numbers.
- Welcome Savings Bank: up to 2,200 corporate customer records (Digital Today and Financial News say "up to"; Kyunghyang says "about"). The data includes company names, names of account managers, email addresses and phone numbers.
The Financial News puts the total for individuals at about 66,000. Kyunghyang describes it more loosely as "tens of thousands" of records. The leaked fields that matter most are the RRNs and CI records, along with income and credit-limit data. Together they make convincing loan-fraud and impersonation phishing much easier, which is a known problem in Korea. No source reports stolen account credentials or fraudulent transactions. Shinhan, KB and Hana have all promised full compensation for any confirmed losses.
Why It Matters
Speed from public tool to exploitation. Kyunghyang Shinmun reports that the attacks used a Chinese-language AI penetration-testing tool released in July, a little over two months before the attacks. If that holds, open-source offensive AI tooling went from release to a campaign across a whole sector in roughly one quarter.
Peripheral systems are the attack surface. Every confirmed breach went through a secondary channel: loan-broker lookups, recruiter directories, employee mobile apps and sales-support systems. None went through core banking. Institutions often harden these systems less, yet they still query sensitive customer data.
Attribution is open. Kyunghyang reports that the attack traffic came from IP addresses in eight countries, including South Korea, the United States and Japan, and that identifying the attacker may take time. That detail is from a single outlet. Regulators have publicly confirmed only that IP addresses were shared across multiple firms. Using a Chinese-language tool does not make this a Chinese state operation, because the tool is open source.
Repeat exposure. The Financial News cites FSS data, obtained by lawmaker Park Jun-tae's office, showing 36 reported cyber intrusion incidents in finance and electronic finance between January 2024 and August 2026. Six of those were at banks.
The Attack Technique
The most specific technical detail so far comes from Moon Jong-hyun, head of the Genians Security Center. He wrote on LinkedIn that the string "ARTEX-自主渗透試控制台" (roughly "ARTEX autonomous penetration test console") appeared in HTML titles on a web server believed to have been used in the Shinhan attack. Seoul Economic Daily describes ARTEX AI as an open-source, Chinese-language system that automates vulnerability scanning and attack-path design. This points to the tooling but does not prove it: Moon himself says analysts "reasonably suspect" it, and he does not claim it is confirmed.
The reported methods differ somewhat:
- Shinhan: Seoul Economic Daily reports that the attacker manipulated the inquiry service's code to bypass authentication. It then fed random inquiry values to enumerate customer numbers and pull the records linked to them. Experts quoted call this AI-driven brute-forcing. In practice it looks like an insecure direct object reference (IDOR) or enumeration flaw, exploited automatically.
- Sector-wide: Money Today cites security-industry speculation that AI agents were used to automate credential stuffing. It says the exact method still needs investigation.
- Kyunghyang describes the attacks as "randomized" and aimed at loosely protected internal systems. Aju Press and the Financial News say externally accessible lookup and support portals were the common entry point.
All of these accounts fit an automated tool that scans for exposed web applications, finds endpoints with missing or weak authentication, and enumerates records. The sources do not agree on whether credential stuffing was part of it. In the FSC's October 2 guidance, regulators told firms to check for "paths where authentication is missing or insufficiently applied." That suggests broken authentication, not stolen credentials, is their main working theory.
What Organizations Should Do
- Inventory every externally reachable system that can query customer data. Include partner, broker, recruiter and employee-mobile portals, not just customer-facing banking. These portals were the entry point in every confirmed breach.
- Test those endpoints for authentication bypass and enumeration. Look for sequential or guessable identifiers, lookups with no authentication, and authorization checks done only on the client side. Require server-side authorization on every record fetch.
- Rate-limit and alert on high-volume lookups. Automated enumeration produces large numbers of requests with varying parameters. Set per-session and per-IP thresholds on inquiry endpoints and send alerts to the SOC, not just to logs.
- Check logs against shared indicators now. Hyundai Capital found its breach only after comparing logs against IPs that regulators had circulated. Pull the attacker IPs from the FSC, FSS and Financial Security Institute and search access logs from at least mid-September onward. Hunt for "ARTEX" strings and other automated-scanner fingerprints.
- Reduce what lookup pages return. Mask or drop RRNs, CI values, income and internal identifiers from any view that doesn't strictly need them. Regulators have explicitly asked firms to cut back unnecessary data exposure.
- Prepare for follow-on fraud. Warn affected customers about loan-fraud and impersonation phishing that uses the leaked income and credit-limit data, and tighten verification for account changes and new credit applications.
Sources: Korean finance breached by a two-month-old Chinese AI - The Kyunghy... | Financial sector hacking spreads, signs of same attacker at seven f... | AI Hacking Hits KB, Hana, Busan Banks After Shinhan Breach - Seoul... | AI-linked cyberattacks spread across South Korean finance Aju Press | 금융사 7곳 뚫렸다… 개인 6만6천명·법인 2200건 정보 유출 금융권 전방위 해킹 - 파이낸셜뉴스 | Realizing Too Late... Financial Sector Hit by Successive Hacks (Ful... | Data of 25,000 Leaked at Shinhan Bank; Full Compensation Pledged -... | 은행·저축은행 고객정보 줄줄이 유출…AI 해킹 공포에 금융권 초비상 - 머니투데이