South Korea launches major probe into AI-assisted bank hacks affecting 66,000

Approximately 66,000 individuals had personal information exposed including names, phone numbers, resident registration numbers, annual income, and loan limits.
AI hacking tools will make attacks easier and more frequent
A cybersecurity expert warned that as artificial intelligence tools proliferate, non-experts will be able to conduct increasingly sophisticated attacks.
Mark

So 66,000 people had their information stolen. What exactly did the attackers get?

Mimi

Names, phone numbers—that's the baseline. But for many victims, it went deeper: resident registration numbers, which are like a national ID number in South Korea, annual income figures, and loan limits. That's the kind of data that opens doors for identity theft or targeted fraud.

Luke

How many of those 66,000 had the sensitive stuff versus just names and numbers?

Mimi

The reporting doesn't break that down. We know Shinhan had 25,729 affected customers and Yegaram had about 40,000, but the source doesn't specify how many in each category had the deeper data exposed.

Mark

And they used AI to do this? That's what makes it different?

Mimi

That's what a cybersecurity professor suggested—that they may have used a tool called ARTEX that uses AI to find vulnerabilities. But it's not confirmed who did this or exactly what tools they used.

Luke

Right. The police identified 28 IP addresses, but the regulators themselves said those don't tell you where the attackers actually are. They could be anywhere.

Mimi

Exactly. The attackers routed their connections through multiple countries. So we know the attack happened, we know the damage, but the origin is still obscure.

Mark

What happens now?

Mimi

Banks had to complete security audits by Thursday. Police are investigating. There's also this question of whether a new government agency needs to be brought in, but that's still being decided.

Luke

So the institutional response is still being sorted out. The investigation is live, but the framework for handling it isn't fully settled yet.

  • AI-assisted hacking tools swept through seven South Korean banks in under a week, exposing the personal and financial records of approximately 66,000 people — a breach notable less for its scale than for the sophistication of its method.
  • The exposed data — resident registration numbers, annual incomes, loan limits, and corporate records — represents exactly the kind of precision extraction that commands premium prices on underground markets.
  • Regulators scrambled to contain the damage, distributing 28 identified attacker IP addresses to financial firms while acknowledging those addresses offer little investigative traction, since attackers routinely route connections through multiple countries.
  • Twenty-eight police investigators organized into four cyberterrorism teams launched a formal probe, even as a newly restructured government created procedural uncertainty about which agency held jurisdiction.
  • President Lee Jae Myung called the attacks a watershed moment, ordering immediate security reviews across critical infrastructure and accelerated development of AI-based defenses — a recognition that the country's posture had been tested and found wanting.
  • Cybersecurity experts warn the harder truth lies ahead: AI hacking tools are lowering the barrier to entry for criminals, meaning more frequent and more varied attacks are not a possibility but a trajectory.

In the first week of October 2026, South Korea confronted a new chapter in the long contest between security and vulnerability, as artificial intelligence tools were turned against the country's banking system with unsettling precision. Seven financial institutions reported breaches affecting roughly 66,000 individuals, exposing not merely names and phone numbers but the intimate financial architecture of ordinary lives. The episode arrives as a warning written in data: the democratization of powerful technology does not discriminate between those who build and those who breach.

On October 7th, South Korean police opened a formal investigation into a coordinated wave of AI-assisted hacking attacks that had moved through the country's banking sector over the preceding week. The breaches were distinguished by their apparent use of artificial intelligence tools designed to identify security vulnerabilities — a detail that elevated the incident from a conventional data theft into something more consequential. By the time investigators mobilized, approximately 66,000 individuals across seven institutions had lost control of their most sensitive information: names, phone numbers, resident registration numbers, income figures, and loan limits.

Shinhan Bank was first to disclose, reporting around 25,700 affected customers on October 1st. Within seventy-two hours, six more institutions followed — KB Kookmin, Hana, BNK Busan, Yegaram and Welcome savings banks, and Hyundai Capital. Yegaram alone reported roughly 40,000 compromised records. Beyond individual customers, approximately 2,200 corporate records were also exposed. Two additional major banks faced similar intrusion attempts but had not confirmed actual data losses.

The Financial Supervisory Service identified 28 IP addresses linked to the attacks and ordered banks to complete internal security audits by Thursday, while cautioning that those addresses held limited investigative value — attackers had routed connections through multiple countries to mask their origins. The Korean National Police Agency assigned 28 investigators across four cyberterrorism teams to the case, though a newly restructured government created immediate procedural questions about jurisdictional authority.

President Lee Jae Myung addressed the breach at a Cabinet meeting, calling it a watershed for national security strategy. He ordered an immediate review of critical infrastructure protocols and pushed for accelerated AI-based defensive capabilities — language that conveyed not panic, but a clear-eyed recognition of institutional vulnerability.

Cybersecurity experts offered a sobering frame. Korea University professor Kim Seung-joo suggested the attacks may have involved ARTEX, an AI tool built to detect system weaknesses, and warned that as such tools proliferate, the technical expertise required to conduct sophisticated attacks will continue to fall. The barrier separating ordinary criminals from capable hackers is eroding — and financial institutions should expect that erosion to accelerate.

On Tuesday, October 7th, South Korean police opened a major investigation into a coordinated series of hacking attacks that had swept through the country's banking system over the preceding week. The breaches were notable for one detail: they appeared to have been carried out with the assistance of artificial intelligence tools designed to hunt for security vulnerabilities. By the time authorities began their formal probe, the damage was already substantial. Approximately 66,000 individuals across seven financial institutions had their personal information exposed—names, phone numbers, resident registration numbers, annual income figures, and loan limits all compromised.

The Korean National Police Agency deployed 28 investigators organized into four teams from its cyberterrorism unit to handle the case. The scope of the attack had become clear only days earlier. Shinhan Bank disclosed on October 1st that roughly 25,700 of its customers had been affected. Within the following seventy-two hours, six additional institutions reported similar breaches: KB Kookmin, Hana, and BNK Busan banks; Yegaram and Welcome savings banks; and Hyundai Capital. Yegaram Savings Bank alone reported approximately 40,000 compromised records. Beyond the individual customer data, roughly 2,200 corporate records had also been exposed. Two other major banks—Woori and NH NongHyup—had reportedly faced similar attacks, though neither had confirmed actual data leaks.

The Financial Supervisory Service moved quickly to contain the fallout. Regulators identified 28 distinct IP addresses associated with the hacking attempts and distributed this information to financial firms, ordering them to complete internal security audits and patch vulnerabilities by Thursday. Officials cautioned, however, that these IP addresses offered limited investigative value; attackers routinely route their connections through multiple countries to obscure their actual location. The exposed information suggested a sophisticated operation targeting financial infrastructure with precision—the attackers had not simply dumped databases but had selectively extracted customer records and corporate data that would be valuable on underground markets.

President Lee Jae Myung addressed the breach during a Cabinet meeting on Tuesday, framing it as a watershed moment for national security strategy. He called for accelerated development of AI-based cybersecurity defenses and warned that technological advancement was outpacing the nation's ability to defend against emerging threats. The president ordered an immediate review of security protocols across critical infrastructure systems and demanded protective measures be implemented without delay. His language suggested alarm—not panic, but the recognition that the country's security posture had been tested and found wanting.

Police faced an immediate procedural question: whether to notify the Serious Crimes Investigation Agency, a newly established body created just days earlier as part of a major government restructuring that had abolished the prosecution service and separated investigative and prosecutorial powers. The Financial Services Commission would need to determine whether the compromised banking systems qualified as "electronic financial infrastructure," a classification that would trigger mandatory notification. A police official told The Korea Herald that the determination would take time, given the newness of the institutional framework.

Experts warned that the attack signaled a troubling trend. Kim Seung-joo, a cybersecurity professor at Korea University, suggested the breaches may have involved ARTEX, an AI tool specifically designed to identify security weaknesses in systems. He told CBS radio that as AI hacking tools proliferated and became easier to use, attacks would accelerate. The barrier to entry for cybercriminals was collapsing. No longer would sophisticated attacks require deep technical expertise; AI tools were democratizing the ability to breach systems, meaning financial institutions and other targets should expect both more frequent and more varied attacks in the months ahead.

Speed is of the essence. We should accelerate the development and deployment of artificial intelligence technologies specialized in cybersecurity.
— President Lee Jae Myung
AI hacking tools will continue to emerge, making it easier for nonexperts to carry out attacks. As a result, these attacks will become more frequent.
— Kim Seung-joo, cybersecurity professor at Korea University
Contattaci Domande frequenti