South Korea probes bank data breaches as authorities suspect AI-powered attacks

Shinhan Bank, Kookmin Bank and Hana Bank affected; over 140,000 customer records reportedly leaked

By LineZotpaper
Published
Read Time2 min
South Korea's Financial Services Commission has launched on-site investigations into a series of cyberattacks on major financial institutions after confirming data breaches at Shinhan Bank and KB Kookmin Bank, with authorities suspecting the use of AI-powered attack automation tools.

The Financial Services Commission (FSC) held an emergency meeting following incidents at multiple South Korean banks. Officials confirmed a data breach at Shinhan Bank and said other cybersecurity incidents affected Kookmin Bank. Hana Bank also suffered a limited-scope breach after its sales-support system was compromised.

According to local media reports, Shinhan Bank leaked the details of 25,000 customers, while Kookmin Bank leaked credit card information of 119,000 clients. The FSC said it shared all actionable information with relevant agencies, including the Korea Internet & Security Agency (KISA).

Financial companies have been instructed to inspect externally accessible IT systems, reduce unnecessary information exposure, check for missing authentication and access controls, and coordinate threat responses. Authorities also pledged to oversee consumer protection and compensation.

While official channels provided no details about the perpetrators, South Korean news agency Yonhap reported that a server used in the attacks had an HTML page title containing a Chinese-language string associated with ARTEX AI, an open-source penetration-testing system that uses agents to automate information gathering, vulnerability discovery, and attack-path planning. The banks and financial authorities have not confirmed the use of ARTEX AI in the breaches. The Chinese-language string does not link the attacks to any particular threat actor.

Moon Jong-hyun, head of the Genian Security Center, posted on LinkedIn that several threat analysts believe the breaches involved AI-based attack automation tools. Separately, President Lee ordered a thorough investigation into personal data leaks at financial and public institutions.

§

Analysis

Why This Matters

  • The breaches affect hundreds of thousands of customers of major banks with combined assets over $800 billion.
  • The suspected use of AI-powered attack tools signals a potential escalation in cyber threats against financial infrastructure.
  • The incident could lead to stricter cybersecurity regulations for South Korea's financial sector and influence global banking security practices.

Background

South Korea's financial sector is highly digitized and a frequent target for cyberattacks. The affected banks — Shinhan Bank and KB Kookmin Bank — are among the country's largest commercial banks. The FSC regularly coordinates with KISA on incident response. ARTEX AI is an open-source penetration-testing framework that can automate multiple phases of an attack, but its use in criminal operations has not been widely documented prior to this incident.

Key Perspectives

[Financial Services Commission]: The regulator is conducting on-site investigations, requiring banks to inspect and secure all externally accessible IT systems, and overseeing consumer compensation. [Affected banks]: Shinhan, Kookmin, and Hana are dealing with data leaks and implementing security improvements while cooperating with authorities. [Customers and consumer advocates]: Over 140,000 individuals may have had personal or credit card data exposed, raising concerns about identity theft and financial fraud. [Cybersecurity analysts]: Some researchers suspect AI automation was used in the attacks, but attribution remains unconfirmed, and the Chinese-language string found on a server does not point to a specific group.

What to Watch

  • The results of the on-site investigations and any regulatory action against the banks.
  • Whether authorities attribute the attacks to a specific threat actor or state-sponsored group.
  • Potential new government mandates for AI security measures in financial institutions.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.