Cybersecurity

South Korea Investigates Bank Breaches Amid Suspicions of the Use of AI-Powered Offensive Tools

South Korea’s Financial Services Commission launched on-site investigations after confirming a breach at Shinhan Bank and receiving reports of incidents affecting other banks, including KB Kookmin Bank and Hana Bank. Authorities are examining the possibility that tools for automating attacks were used, without official confirmation of the responsible party or AI’s role.

2026-10-05
3 min read
8 views
certi.news Editorial Team
South Korea Investigates Bank Breaches Amid Suspicions of the Use of AI-Powered Offensive Tools

South Korea’s Financial Services Commission held an emergency meeting following a series of cyberattacks targeting financial institutions in the country. During the meeting, it confirmed that Shinhan Bank had suffered a data breach, along with security incidents affecting other banks, including KB Kookmin Bank. Authorities began on-site investigations after receiving incident reports, while sharing actionable information with relevant agencies, including the Korea Internet & Security Agency (KISA).

Local media reports indicate that the breaches may have affected the data of a large number of customers. Shinhan Bank was reportedly associated with the leak of details belonging to 25,000 customers, while KB Kookmin Bank was said to have leaked credit card information belonging to 119,000 customers. A limited breach of Hana Bank’s sales support system was also disclosed. The source did not provide enough technical details to determine the method of intrusion or how long the attackers remained inside the systems.

Immediate measures for financial institutions

Authorities asked financial companies to conduct an urgent review of all systems and services accessible from outside the network, including systems not directly intended for customers. The instructions include reducing unnecessarily exposed data and information, checking for vulnerabilities in authentication and access controls, accelerating the exchange of threat intelligence and coordination of response efforts, and submitting the results of internal security checks as soon as possible.

The Financial Services Commission also pledged to oversee consumer protection and compensation, and to analyze the incidents to identify the regulatory improvements required. This follows South Korean President Lee’s directive to conduct a comprehensive investigation into personal data leaks affecting financial and public institutions.

What do we know about the theory of AI-powered attacks?

Official channels have not identified the perpetrators of the attacks, nor have they confirmed the use of artificial intelligence in the breach of Shinhan Bank. However, Yonhap reported that a server used in the attacks had an HTML page title containing a phrase in Chinese associated with ARTEX AI, an open-source penetration-testing system that uses agents to automate information gathering, vulnerability discovery, attack-path planning, security-tool operation, and vulnerability verification.

The presence of this phrase does not link the attacks to a specific threat actor, nor does it prove that ARTEX AI was actually used against the banks. Moon Jong-hyun, head of the Genian Security Center, said that a number of threat analysts suspect the use of tools to automate attacks with the help of artificial intelligence, but this theory remains officially unconfirmed.

Why does this news matter?

The significance of the incidents lies in the combination of two factors: the size of the affected institutions and the possibility that automated attacks extended to systems not intended for customers, a point emphasized in the commission’s instructions. As for the AI theory, additional forensic evidence is needed before it can be considered an explanation for the incidents; the source does not yet establish whether the tools mentioned were used in the breach, nor does it identify the responsible party or the final extent of the damage. Therefore, according to the announced measures, the practical priority remains reducing the exposure surface, auditing access, and rapidly exchanging threat intelligence.

News source
BleepingComputer
Open original source ↗
c
Author

certi.news Editorial Team

In the same category

You may also like

View all news