Skip to main content

Police investigate suspected AI-assisted attacks on South Korean banks

3 OCTOBER 2026·2 MIN READ·5 SOURCES

South Korea’s National Police Agency has begun a preliminary investigation into suspected AI-driven attacks on major domestic banks. Reports describe incidents at five major banks, but confirmed data exposure varies by institution, and authorities have not confirmed that a particular AI tool was used.

Police investigate suspected AI-assisted attacks on South Korean banks

Key takeaways · 4

  • 01

    Shinhan reported that information belonging to about 25,000 customers was leaked, including names, phone numbers, annual income and loan limits.

  • 02

    KB said information belonging to 119 customers was exposed through an employee mobile work-support system, and said the incident was unrelated to internet and mobile banking transactions.

  • 03

    Hana reported 89 affected customers; Woori and NH Nonghyup said suspected attacks had not resulted in confirmed personal-information leaks.

  • 04

    Do not treat ARTEX AI as a confirmed attack tool: authorities and Shinhan had not confirmed its use.

What police are investigating

The National Police Agency began a preliminary investigation into suspected AI hacking attacks targeting major domestic banks.[2] Police suspect an automated method repeatedly exploited vulnerabilities in systems used by bank employees or in sales-support systems.[2] The banks confirmed as having suffered hacking damage are Shinhan, KB Kookmin, Hana and BNK Busan.[2] Woori Bank and NH Nonghyup reported suspected attempts but said no personal-information leak had been confirmed.[1] The reports therefore distinguish between confirmed damage and suspected attempts, rather than establishing that every institution had the same outcome.[2][1]

Customer data exposure differs

Shinhan reported a leak involving about 25,000 customers; the exposed information included names, phone numbers, annual income and loan limits.[3][1] An unauthorized outsider bypassed identity verification in Shinhan’s loan-recruiter service.[4] KB said information belonging to 119 customers leaked from an employee mobile work-support system, including names, phone numbers, addresses and encrypted resident registration numbers.[5] Hana reported 89 affected customers and said the exposed information may have included names and contact details, addresses, employer names and resident registration numbers.[5]

Systems and responses

KB said its incident was unrelated to customers’ internet and mobile banking transactions, and that it would fully compensate customers for any losses.[5] The bank said it blocked the affected server and access route after detecting possible leakage through abnormal external access on the night of September 30.[5] Hana said its operations-support system is separate from its internet and mobile banking transaction systems, and that customer financial transaction information was not compromised.[1] Hana said it would fully compensate customers if actual damage occurred.[5] Shinhan said it formed a response team, blocked external IP addresses and suspended affected services.[3]

AI attribution remains unconfirmed

Investigators found a Chinese-language phrase meaning “AI autonomous penetration” in web-server page titles thought to be linked to the Shinhan attack.[2] Authorities and Shinhan had not confirmed whether ARTEX AI was used.[4] ARTEX AI is an open-source, Chinese-language large-language-model-based autonomous penetration-testing system designed to automate information gathering, vulnerability discovery, attack-path planning, security-tool execution and vulnerability verification.[4] Threat analysts said AI-based attack-automation tools may have been used in attacks on financial companies, and attackers could misuse such tools to increase the automation and efficiency of attacks.[4]

For financial-services teams, the reports make a practical distinction between customer-data exposure, systems involved and whether transaction services were affected. The suspected automation is a reason to review employee-facing and support systems, while the available evidence does not establish that ARTEX AI was used.

Why it matters
Story quiz

Test yourself on this story — 1 question.

Create a free account to take the quiz, earn XP, and get a daily session built for your industry.

Take the quiz

How this developed

  1. 3 October 2026

    Police investigate suspected AI-assisted attacks on South Korean banks

Sources

AI fluency, one session a day, built for your work.