
Data breaches from hacking attacks have hit KB Kookmin Bank, Hana Bank and Busan Bank following a similar incident at Shinhan Bank, putting South Korea's financial sector on alert over security. Woori Bank and NH NongHyup Bank were also targeted, adding to market unease.
KB Kookmin Bank said personal and credit information belonging to 119 customers leaked from a mobile work-support system used by employees. The exposed data included names, phone numbers, addresses and encrypted resident registration numbers.
KB said the breach was unrelated to customer banking transactions such as internet and mobile banking, and that it would fully compensate any losses. The bank blocked the affected server and access routes immediately after detecting on the night of the 30th that data may have leaked through abnormal external access.
At Hana Bank, an external hacking attempt exposed the personal information of 89 customers. "An external hacking agent gained abnormal access to our Operation Direct Support system," the bank said. "We believe resident registration numbers, names, addresses, email addresses, phone numbers, mobile numbers and employer names were exposed."
Hana Bank said it blocked the servers and access routes where the intrusion was confirmed, and that it will fully compensate customers if actual harm occurs.
In the earlier Shinhan Bank breach, which exposed information on about 25,000 customers, investigators found traces of an AI-based automation tool. Moon Jong-hyun, head of the Genians Security Center, wrote on LinkedIn that the string "ARTEX-自主渗透試控制台" was found in the HTML titles of some web servers believed to have been used in the attack. "Multiple threat analysts reasonably suspect that an AI-based attack automation tool was used in this attack," he said.
ARTEX AI is a Chinese-language system that automates vulnerability scanning and the design of attack paths. It is available as open source on the software development platform GitHub, and was showcased this year as the winning project at an "Agent+" offensive-defensive capability challenge led by China's Baidu. "It looks highly likely that ARTEX AI was used in the attack on Shinhan Bank," a senior financial industry official said. "We need to look into why these attacks are being concentrated like this."
The attacks were not limited to those banks. Woori Bank and NH NongHyup Bank also faced external hacking attempts but fended them off. In Woori Bank's case, the attempts ran from the 29th of last month through the 1st of this month.
At Busan Bank, an external hacking attempt using an AI agent took place at 9 p.m. on the 1st, but the main attacks were blocked. Still, the bank confirmed indications that the personal information of 11 outsourced development workers was exposed through some web pages.
Experts warn that South Korea's financial sector is exposed to hacking attacks that use AI agents. "At this point the evidence still looks circumstantial, so it is too early to conclude that a specific country was behind this incident," said Lee Sang-keun, a professor in the School of Smart Security at Korea University's Graduate School of Information Security. "Despite efforts by the government and the financial industry to counter AI security threats, AI technology and the attacks that use it are advancing far faster than expected."
What stands out is that the hacking attempts were concentrated in a single period. That has led to speculation within the industry that a single group may be responsible. "AI has made it possible to automate much of the work of preparing and operating attack tools," said Son Kyu-sik, a professor of hacking and security at Hanyang Cyber University. "Systems that are connected to the external internet and have relatively weak authentication procedures can be exposed to attacks like these."
Meanwhile, Shinhan Bank failed to prevent its data leak despite scoring full marks for five consecutive years in inspections of personal credit information protection. The bank received an S grade, or 100 points, for six straight years in the Financial Services Commission's review of personal credit information management and protection, and holds domestic and international certifications including ISMS, ISMS-P and ISO 27001.
The bank also carried out regular inspections of loan brokerage firms. Last year, while reviewing security at outside firms that handle personal data on its behalf, Shinhan Bank focused on high-risk sectors such as loan brokers. Even so, attackers bypassed authentication in a simplified inquiry service for loan brokers and leaked information on about 25,000 customers. That has prompted criticism that the problem may lie with the assessment system as a whole.






