KB, Hana, Busan Banks Hacked After Shinhan Breach

Data on 119 KB Customers, 89 Hana Customers Exposed Banks Pledge Full Compensation for Any Customer Losses Shinhan Failed to Stop Breach Despite Top "S" Security Rating Critics Point to Weaknesses Across Security Assessment System

Finance|
| Updated 2026.10.02. 18:43:45
|
By Shin Joong-seop and Jung Ji-wonjseop@sedaily.com, stopone@sedaily.com
||
Yonhap News - Seoul Economic Daily Finance News from South Korea
Yonhap News

Data breaches from hacking attacks have hit KB Kookmin Bank, Hana Bank and Busan Bank following a similar incident at Shinhan Bank, putting South Korea's financial sector on alert over security. Woori Bank and NH NongHyup Bank were also targeted, adding to market unease.

KB Kookmin Bank said personal and credit information belonging to 119 customers leaked from a mobile work-support system used by employees. The exposed data included names, phone numbers, addresses and encrypted resident registration numbers.

KB said the breach was unrelated to customer banking transactions such as internet and mobile banking, and that it would fully compensate any losses. The bank blocked the affected server and access routes immediately after detecting on the night of the 30th that data may have leaked through abnormal external access.

At Hana Bank, an external hacking attempt exposed the personal information of 89 customers. "An external hacking agent gained abnormal access to our Operation Direct Support system," the bank said. "We believe resident registration numbers, names, addresses, email addresses, phone numbers, mobile numbers and employer names were exposed."

Hana Bank said it blocked the servers and access routes where the intrusion was confirmed, and that it will fully compensate customers if actual harm occurs.

In the earlier Shinhan Bank breach, which exposed information on about 25,000 customers, investigators found traces of an AI-based automation tool. Moon Jong-hyun, head of the Genians Security Center, wrote on LinkedIn that the string "ARTEX-自主渗透試控制台" was found in the HTML titles of some web servers believed to have been used in the attack. "Multiple threat analysts reasonably suspect that an AI-based attack automation tool was used in this attack," he said.

ARTEX AI is a Chinese-language system that automates vulnerability scanning and the design of attack paths. It is available as open source on the software development platform GitHub, and was showcased this year as the winning project at an "Agent+" offensive-defensive capability challenge led by China's Baidu. "It looks highly likely that ARTEX AI was used in the attack on Shinhan Bank," a senior financial industry official said. "We need to look into why these attacks are being concentrated like this."

The attacks were not limited to those banks. Woori Bank and NH NongHyup Bank also faced external hacking attempts but fended them off. In Woori Bank's case, the attempts ran from the 29th of last month through the 1st of this month.

At Busan Bank, an external hacking attempt using an AI agent took place at 9 p.m. on the 1st, but the main attacks were blocked. Still, the bank confirmed indications that the personal information of 11 outsourced development workers was exposed through some web pages.

Experts warn that South Korea's financial sector is exposed to hacking attacks that use AI agents. "At this point the evidence still looks circumstantial, so it is too early to conclude that a specific country was behind this incident," said Lee Sang-keun, a professor in the School of Smart Security at Korea University's Graduate School of Information Security. "Despite efforts by the government and the financial industry to counter AI security threats, AI technology and the attacks that use it are advancing far faster than expected."

What stands out is that the hacking attempts were concentrated in a single period. That has led to speculation within the industry that a single group may be responsible. "AI has made it possible to automate much of the work of preparing and operating attack tools," said Son Kyu-sik, a professor of hacking and security at Hanyang Cyber University. "Systems that are connected to the external internet and have relatively weak authentication procedures can be exposed to attacks like these."

Meanwhile, Shinhan Bank failed to prevent its data leak despite scoring full marks for five consecutive years in inspections of personal credit information protection. The bank received an S grade, or 100 points, for six straight years in the Financial Services Commission's review of personal credit information management and protection, and holds domestic and international certifications including ISMS, ISMS-P and ISO 27001.

The bank also carried out regular inspections of loan brokerage firms. Last year, while reviewing security at outside firms that handle personal data on its behalf, Shinhan Bank focused on high-risk sectors such as loan brokers. Even so, attackers bypassed authentication in a simplified inquiry service for loan brokers and leaked information on about 25,000 customers. That has prompted criticism that the problem may lie with the assessment system as a whole.

Original reporting by Shin Joong-seop and Jung Ji-won for Seoul Economic Daily.

AI-translated from Korean. Quotes from foreign sources are based on Korean-language reports and may not reflect exact original wording.

Watch · Seoul Economic Daily

More →
1:05

AI KEY

Preview
Korean Corporate Intelligence HubKOSPI · KOSDAQ · 12 sectors

A live, cap-weighted view of every KOSPI and KOSDAQ sector, with same-day Korean reporting distilled by company — built for foreign investors, correspondents and analysts who need to scan Korea before the next session.

Korea Company Atlas

Preview
Market Ontology · The Feedback LoopKFTC 2025 · 92 groups · 121,954 articles

An English ontology of the Korean market — how companies, the media, the government and the National Assembly move each other in a loop. Korea's named controlling persons and designated business groups are a mechanism, not a risk to be priced blind.

SIGNAL

Now live
English Edition · Capital MarketsM&A · IPO · PE · Fund Flows

SIGNAL English Edition is live — Korea's deal desk reporting in English. M&A, IPOs, private equity and fund flows, covered daily for global institutional investors. Browse free; subscriber-only scoops at the 50% intro rate.