Key points
- Seven Korean lenders lost data to hackers
- The attackers skipped the banking apps
- Investigators are examining a possible AI link
Korean regulators say hackers have taken personal data from seven financial companies since late September, including three of the country's five biggest banks. They called an emergency meeting with financial companies on Sunday, October 4, and said AI may have been used in the attacks.
The seven are Shinhan Bank (신한은행), KB Kookmin Bank (KB국민은행), Hana Bank (하나은행), BNK Busan Bank (BNK부산은행), Yegaram Savings Bank (예가람저축은행), Welcome Savings Bank (웰컴저축은행) and Hyundai Capital (현대캐피탈). Information on about 66,000 people leaked in total, plus up to 2,200 records on Welcome's corporate clients.
Two online lending platforms, PFCT (피에프씨테크놀로지스) and MOUDA (모우다), also said outsiders got into their systems on September 27. PFCT said data on 302 customers leaked, and MOUDA said some customer data may have leaked. It hasn't been confirmed whether the same attackers were behind them.
In Seoul, shares of Shinhan Financial Group (055550), KB Financial Group (105560) and Hana Financial Group (086790) fell between 1.4 and 1.8 percent on October 1, the day Shinhan's breach became public. The Kospi rose 1.95 percent the same day.
The hackers went in through side systems, not banking apps
At the banks, the attackers targeted systems used by loan brokers and staff. At Shinhan, they entered random values into a service for checking loan applications until they found valid customer numbers, then pulled the information attached to them, Kyunghyang Shinmun (경향신문) reported. The attacks didn't go through the apps customers use for online or mobile banking.
"The main systems in the financial sector were fine because they have authentication beyond an ID and password, but this time it was the peripheral systems, so it seems that kind of attack was possible," Park Chan-am (박찬암), chief executive of the security company Stealien (스틸리언), told the paper.
More than 25,700 Shinhan customers had their names, phone numbers, annual incomes and loan limits stolen. For 66 of them, the stolen data also included resident registration numbers, South Korea's national identification numbers.
The scale and entry points varied across the other companies. KB Kookmin lost data on 119 customers through a mobile system used by employees, while Hana lost data on 89 customers through its sales support system. At BNK Busan Bank, the names and phone numbers of 11 outside developers leaked. Yegaram had the largest breach, affecting about 40,000 customers. Hyundai Capital's breach involved a page where customers look up its home-loan brokers. Woori Bank and NH NongHyup Bank, the other two of the country's five biggest banks, also faced attacks but blocked them.
Some breaches went undetected for days. Shinhan detected its breach 15 hours and 26 minutes after the first attack. Hana took 41 hours and 44 minutes, while KB Kookmin took 67 hours and 41 minutes.
A free AI hacking tool's name turned up on an attack server
On October 2, Moon Jong-hyun (문종현), who heads the security center at the Korean security company Genians (지니언스), posted that the string "ARTEX-autonomous penetration test console" showed up in HTML titles on a web server used in attacks on several Korean targets. The name on the server doesn't show whether the attackers actually used the tool, which AI model ran it, or how much of the attack was automated.
ARTEX is a free, open-source program that went up on GitHub on July 26. Penetration testing means attacking a system, with permission, to find weak spots before criminals do, and AI models have started doing that work on their own. ARTEX hands the job to an AI agent and can connect to Anthropic or OpenAI models through their APIs. Its GitHub page forbids using it on any live website or online service.
Park Sang-won (박상원), head of the Financial Security Institute (금융보안원), said on Sunday that the attack IP addresses at the four banks were almost identical. "Attack IPs can be used while moving between many places, so the attacker can't be identified by IP alone," he said. IP addresses from eight countries and territories, including Korea, the US, Japan and Hong Kong, were reportedly used.
Regulators ordered emergency checks across the industry
"It's hard to say definitively, but the possibility of a hacking attack using AI can't be ruled out," said Lee Eog-weon (이억원), chairman of the Financial Services Commission (금융위원회), who led Sunday's meeting in Seoul.
Banks and card companies have until October 6 to finish emergency self-inspections, and brokerages, insurers and savings banks have until October 8. Lee said a company that ignores attack information already shared, and then suffers a similar breach, will be held strictly responsible under the law. President Lee Jae-myung ordered a thorough investigation the same day, and police had already opened a preliminary investigation on October 2.
Regulators also worry about phishing. A scammer who knows someone's name, phone number, income and loan limit could call as if they already knew about that person's loan. Shinhan said it'll announce compensation after talking with regulators.
In a separate incident, Korea Electric Power Corp. (한국전력, 015760) said details on about 24,000 employees, nearly its whole staff, were exposed on an outside website for about 32 hours after it noticed on October 1. The state power company says no resident registration numbers or customer data were exposed, and it's still investigating how it happened.
The officials' and experts' comments are translated from Korean.




