Cyber & AI intelligence
Wasteland.
Briefs indexed3006
Issues30
Published Mondays07:30 CT
▣ Breach KOREAN-FINANCIAL-S 2026-10-04

Korean Financial Sector: AI-Assisted Intrusion Campaign Hits KB, Hana, Yegaram and Hyundai Capital

"An intrusion campaign that began with the Shinhan Bank breach has spread across South Korea's financial sector. KB Kookmin Bank, Hana Bank, BNK Busan Bank, Yegaram Savings Bank, Hyundai Capital and Welcome Savings Bank…"

An intrusion campaign that began with the Shinhan Bank breach has spread across South Korea's financial sector. KB Kookmin Bank, Hana Bank, BNK Busan Bank, Yegaram Savings Bank, Hyundai Capital and Welcome Savings Bank have all confirmed data leaks. Financial authorities say they found related attacker IP addresses at seven firms. The Financial News puts the total at about 66,000 individuals plus up to 2,200 corporate records. Investigators and security researchers suspect the attacker used an AI-driven automated penetration tool. The attacks went after loan-broker lookup pages, employee work-support systems and other externally reachable systems with weak access controls, not core banking platforms. President Lee Jae-myung has ordered a full investigation. On October 4, a public holiday, the Financial Services Commission called an emergency meeting of the whole sector and moved it forward from October 7.

A note on sourcing: every source available for this brief is press reporting. Most of it quotes statements from the affected institutions and regulators directly, but none is a primary disclosure. Figures below are attributed where they differ.

What Happened

Most reports place the intrusions between September 27 and 30, 2026. Kyunghyang Shinmun gives that window for the core group of victims.

Several institutions blocked attempts. Woori Bank and NH NongHyup Bank were both targeted, and neither has confirmed a leak. SBS obtained a Woori internal report showing nine access attempts from three suspicious IP addresses, all stopped at the firewall. The Financial News reports that the Korean Federation of Community Credit Cooperatives (MG Saemaeul Geumgo) found access attempts from the same IP used against Shinhan and blocked them. It also reports that Nonghyup mutual finance, which shares a network with NH NongHyup Bank, blocked similar attempts.

The victim count varies by source. The Financial News and Digital Today count seven firms with confirmed leaks. Kyunghyang Shinmun adds two online investment-linked (P2P) finance companies, which would make the total higher. Kyunghyang also notes that analysts think the number of firms that faced attempted attacks may be much larger.

What Was Taken

Per-institution figures, as reported:

The Financial News puts the total for individuals at about 66,000. Kyunghyang describes it more loosely as "tens of thousands" of records. The leaked fields that matter most are the RRNs and CI records, along with income and credit-limit data. Together they make convincing loan-fraud and impersonation phishing much easier, which is a known problem in Korea. No source reports stolen account credentials or fraudulent transactions. Shinhan, KB and Hana have all promised full compensation for any confirmed losses.

Why It Matters

Speed from public tool to exploitation. Kyunghyang Shinmun reports that the attacks used a Chinese-language AI penetration-testing tool released in July, a little over two months before the attacks. If that holds, open-source offensive AI tooling went from release to a campaign across a whole sector in roughly one quarter.

Peripheral systems are the attack surface. Every confirmed breach went through a secondary channel: loan-broker lookups, recruiter directories, employee mobile apps and sales-support systems. None went through core banking. Institutions often harden these systems less, yet they still query sensitive customer data.

Attribution is open. Kyunghyang reports that the attack traffic came from IP addresses in eight countries, including South Korea, the United States and Japan, and that identifying the attacker may take time. That detail is from a single outlet. Regulators have publicly confirmed only that IP addresses were shared across multiple firms. Using a Chinese-language tool does not make this a Chinese state operation, because the tool is open source.

Repeat exposure. The Financial News cites FSS data, obtained by lawmaker Park Jun-tae's office, showing 36 reported cyber intrusion incidents in finance and electronic finance between January 2024 and August 2026. Six of those were at banks.

The Attack Technique

The most specific technical detail so far comes from Moon Jong-hyun, head of the Genians Security Center. He wrote on LinkedIn that the string "ARTEX-自主渗透試控制台" (roughly "ARTEX autonomous penetration test console") appeared in HTML titles on a web server believed to have been used in the Shinhan attack. Seoul Economic Daily describes ARTEX AI as an open-source, Chinese-language system that automates vulnerability scanning and attack-path design. This points to the tooling but does not prove it: Moon himself says analysts "reasonably suspect" it, and he does not claim it is confirmed.

The reported methods differ somewhat:

All of these accounts fit an automated tool that scans for exposed web applications, finds endpoints with missing or weak authentication, and enumerates records. The sources do not agree on whether credential stuffing was part of it. In the FSC's October 2 guidance, regulators told firms to check for "paths where authentication is missing or insufficiently applied." That suggests broken authentication, not stolen credentials, is their main working theory.

What Organizations Should Do

  1. Inventory every externally reachable system that can query customer data. Include partner, broker, recruiter and employee-mobile portals, not just customer-facing banking. These portals were the entry point in every confirmed breach.
  2. Test those endpoints for authentication bypass and enumeration. Look for sequential or guessable identifiers, lookups with no authentication, and authorization checks done only on the client side. Require server-side authorization on every record fetch.
  3. Rate-limit and alert on high-volume lookups. Automated enumeration produces large numbers of requests with varying parameters. Set per-session and per-IP thresholds on inquiry endpoints and send alerts to the SOC, not just to logs.
  4. Check logs against shared indicators now. Hyundai Capital found its breach only after comparing logs against IPs that regulators had circulated. Pull the attacker IPs from the FSC, FSS and Financial Security Institute and search access logs from at least mid-September onward. Hunt for "ARTEX" strings and other automated-scanner fingerprints.
  5. Reduce what lookup pages return. Mask or drop RRNs, CI values, income and internal identifiers from any view that doesn't strictly need them. Regulators have explicitly asked firms to cut back unnecessary data exposure.
  6. Prepare for follow-on fraud. Warn affected customers about loan-fraud and impersonation phishing that uses the leaked income and credit-limit data, and tighten verification for account changes and new credit applications.

Sources: Korean finance breached by a two-month-old Chinese AI - The Kyunghy... | Financial sector hacking spreads, signs of same attacker at seven f... | AI Hacking Hits KB, Hana, Busan Banks After Shinhan Breach - Seoul... | AI-linked cyberattacks spread across South Korean finance Aju Press | 금융사 7곳 뚫렸다… 개인 6만6천명·법인 2200건 정보 유출 금융권 전방위 해킹 - 파이낸셜뉴스 | Realizing Too Late... Financial Sector Hit by Successive Hacks (Ful... | Data of 25,000 Leaked at Shinhan Bank; Full Compensation Pledged -... | 은행·저축은행 고객정보 줄줄이 유출…AI 해킹 공포에 금융권 초비상 - 머니투데이