South Korea Investigates Possible Use of AI in Banking Data Breaches

South Korea has raised its national cyber alert level to “Watch” following a series of data breaches at multiple financial institutions that exposed the personal information of various customers. Investigators are examining whether attackers used AI-powered autonomous penetration-testing tools to exploit auxiliary banking systems, though officials have not yet confirmed the specific software involved.

Coordinated Breaches Across the Financial Sector

Rather than attacking consumer-facing apps or transaction-processing rails, the intruders focused on loan-agent portals, employee mobile support platforms, and sales databases. These auxiliary systems hold significant personal data but typically receive comparatively less scrutiny, lighter authentication requirements, and less real-time anomaly detection than the core banking systems they support. This architectural vulnerability is not unique to South Korean banks.

South Korea Investigates Possible Use of AI in Banking Data Breaches
Photo: claimsjournal.com

The scope of the incident expanded rapidly as multiple firms disclosed unauthorized access throughout early October. Shinhan Bank reported a breach on October 1 affecting about 25,000 customers. Exposed information included names, phone numbers, annual income, loan limits, and, for 66 individuals, national ID numbers. KB Kookmin Bank and Hana Bank disclosed further breaches on October 2. KB reported that personal and credit information belonging to 119 customers leaked through a mobile work-support system, while Hana Bank reported abnormal access to its operations support system, exposing 89 customers. Hana’s leaked records included names, resident registration numbers, addresses, email addresses, phone numbers, and employer details. BNK Busan Bank also reported that information belonging to 11 outsourced workers was exposed.

The Role of AI and Autonomous Tools

South Korean President Lee Jae Myung ordered a thorough investigation on October 4, 2026, after the breaches exposed customer and worker information. Reporting by Seoul Economic Daily indicated that traces of an AI-based automation tool were found in the Shinhan incident. Son Kyu-sik, a professor in the Department of Hacking and Security at Hanyang Cyber University, noted that systems connected to the internet with relatively weak authentication are now exposed to automated attacks using AI.

South Korean Banking Sector AI Hacking Incident… Why the Role of Security Firms Is Becoming Cruci…

Kim Myeong-ju, head of the Barun AI Research Center, stated that because hackers have begun using AI agents, the frequency and scale of attacks are bound to grow more severe. Mun Chong-hyun, director at Genians, explained that AI-related technologies can be a double-edged sword; while developed for defensive purposes, they are being shared indiscriminately and used for malicious hacking attempts. Mun warned that as these technologies advance, many people need to take caution.

The attack method in each confirmed breach was credential stuffing: feeding large volumes of username-and-password combinations from prior data breaches into login portals at high speed. South Korea’s National Cyber Security Center had previously warned in its National Information Security White Paper that groups are progressing toward “agentic AI,” or systems capable of executing cyberattacks autonomously.

Korean authorities are ‌yet ​to disclose what AI tools were used in the bank hacking ​incidents. Photo: AP PHOTO
Photo: northweststar.com.au

President Orders Investigation into AI Hacking Incidents

Presidential spokesperson Kang Yu-jung said the president ordered officials to investigate fully and develop measures with a grave awareness of the seriousness of the matter. During a cabinet meeting, President Lee emphasized that signs have emerged of AI being used in some hacking incidents, causing public concern and anxiety. The Financial Supervisory Service began an emergency on-site inspection to ascertain the nature and extent of the breaches.

KISA expanded surveillance of major corporate web properties and dispatched security advisories to 28,000 companies, urging immediate self-audits. The Financial Services Commission held meetings with local banks to discuss the breaches and mandated stronger authentication, tighter access controls, and faster threat intelligence sharing. Authorities also ordered broad checks of computer systems at banks and card companies, focusing on supporting business systems that handle sensitive records.

Korea's Banking Crisis: What Caused 25K Data Breach?

Investigators Struggle to Attribute Global Attacks

Attribution remains uncertain because the tools used are public and IP addresses are distributed globally. While South Korean police are investigating, officials have noted that attribution is murky. Investigators are currently examining whether AI tools helped attackers break into the systems, but they cautioned that describing these incidents as fully autonomous hacks would go beyond the available evidence, as public reports have not identified a confirmed software flaw or complete set of attack indicators.

However, the exposed identity and income data creates downstream risk that could persist for years. Authorities warn that convincing messages can turn a data leak into an opportunity to target affected people with carefully tailored scams, and they advise affected individuals to consider placing a fraud alert with credit bureaus.

Photo of author

Sophie Lin - Technology Editor

Sophie is a tech innovator and acclaimed tech writer recognized by the Online News Association. She translates the fast-paced world of technology, AI, and digital trends into compelling stories for readers of all backgrounds.

Beyond wiring diagrams: Inside a $19 million effort to expand access to connectome technology

California Families Face Deadline to Use $106 Million in SUN Bucks