South Korea financial-sector breach wave: Shinhan (~25,000), KB Kookmin, Hana, BNK Busan, Yegaram Savings (~40,000), Hyundai Capital — President Lee orders full probe (4 Oct)
A run of data breaches at South Korean financial institutions over 30 September to 2 October led President Lee Jae Myung on 4 October 2026 to order a thorough investigation and countermeasures, presidential spokesperson Kang Yu-jung said (Korea Times, 4 Oct). Reported so far: Shinhan Bank (1 Oct) about 25,000 customers, with names, phone numbers, annual income and loan limits, and some resident registration numbers; KB Kookmin Bank (2 Oct) personal and credit information of 119 customers via a mobile work-support system used by employees, after it spotted possible abnormal external access on the night of 30 Sep and blocked the server; Hana Bank (2 Oct) 89 customers after an external actor reached its operations support system, exposing resident registration numbers, names, addresses, email, phone numbers and employer names; BNK Busan Bank details of 11 outsourced workers; Yegaram Savings Bank about 40,000 customers; Hyundai Capital 146 housing-loan agents. These are separate affected groups, not one pool. KB and Hana say the affected systems are separate from internet and mobile banking and no transaction data leaked; KB says it will fully compensate losses. Seoul Economic Daily reported traces of an AI-based automation tool in the Shinhan incident and SBS reported common IP addresses across several attacks, but no single actor, flaw or malware family has been publicly confirmed. Police began examining the breaches on 2 Oct and financial authorities ordered system checks across banks and card companies. Wire: Cybersecurity News 4 Oct. UPDATE (5 Oct): South Korea's Financial Services Commission held an emergency meeting, confirmed the Shinhan Bank breach and incidents at other banks including KB Kookmin, launched on-site inspections and shared actionable information with agencies including KISA (the Korea Internet & Security Agency). Yonhap reported that a server used in the attacks carried an HTML page title with a Chinese-language string associated with ARTEX AI, an open-source agent-based penetration-testing framework; neither the banks nor regulators have confirmed it was used, and the string does not identify an actor. Genian Security Center head Moon Jong-hyun said several analysts believe AI-based attack automation was involved. BleepingComputer gives KB Kookmin's figure as credit card data of 119,000 clients, while earlier Korean reports said 119 customers; the official count is not yet settled.
- Product
- Bank back-office and support systems (loan-agent sites, employee mobile work-support, operations support systems) at Shinhan, KB Kookmin, Hana, BNK Busan, Yegaram Savings, Hyundai Capital
- Versions
- n/a — incident; no CVE or product flaw publicly confirmed
- Exploited in Australia?
- no
- Patch to
- AU banks and lenders: the reported entry points were loan-agent portals, employee mobile support apps and operations support systems, not customer banking apps. Inventory those back-office and broker-facing systems, put them behind MFA and the same monitoring as core banking, rate-limit and alert on bulk record reads, and test detection against fast automated (AI-assisted) intrusion. Treat leaked Korean resident registration numbers as identity-fraud feedstock if you onboard Korean customers.
Primary: Korea Times — Lee orders thorough probe into AI-powered cyberattacks in banks (4 Oct 2026) · Vendor: Seoul Economic Daily — KB and Hana statements after Shinhan breach (2 Oct 2026) · BleepingComputer — South Korea probes bank breaches amid suspected AI-powered attacks (5 Oct 2026)
