AI hacking hits South Korean banks, leaks customer data; PM orders overhaul
Version 2: South Korea's prime minister chaired a government meeting on the leaks, ordering a full financial-sector security check, a police investigation and a review of personal data protection certification, while a new editorial reported that banks cut information security spending even as financial groups posted record profits.
In short
Simultaneous hacking attacks hit South Korea's financial sector, with customer information leaked at Shinhan, KB Kookmin, Hana, BNK Busan, Yegaram Savings Bank, Hyundai Capital and Welcome Savings Bank, according to Kyunghyang Shinmun and Chosun Ilbo. Financial Services Commission Chairman Lee Eok-won told an October 4 emergency meeting that an AI-based attack “cannot be ruled out”, and Prime Minister Han Sung-sook said on October 6 that existing security systems cannot cope and ordered a full financial-sector security check and a police investigation. The documents say the full scope of the breach is not yet known.
Read the full story 3 min read
Hacking attacks hit South Korea's financial sector simultaneously or in close succession, with customer information leaked at several companies, according to the financial industry as reported on October 4. Kyunghyang Shinmun named Shinhan, KB Kookmin, Hana and BNK Busan banks among the large commercial banks affected, and Yegaram Savings Bank, Hyundai Capital and Welcome Savings Bank in the second-tier financial sector. Chosun Ilbo said the breach was first confirmed at Shinhan Bank and then spread to other commercial banks, savings banks and capital companies. [ 2 , 3 , 4 , 5 ]
According to Chosun Ilbo and Kyunghyang Shinmun, the leaks at Shinhan, KB Kookmin, Hana, Yegaram and Welcome involved customer information, while BNK Busan Bank and Hyundai Capital lost outsourced staff and loan recruiter data. The Saemaul Geumgo Central Association and Nonghyup mutual finance were attacked without leaks being reported. Kyunghyang Shinmun added that Woori Bank and NH Nonghyup Bank were also attacked without leaks, and that the number of leaked records ranged from tens to tens of thousands for customers and outsourced staff. [ 2 , 4 ]
At an emergency inspection meeting at the Government Seoul Complex in Jongno, Seoul on the afternoon of October 4, Financial Services Commission Chairman Lee Eok-won said the possibility of an AI-based attack “cannot be ruled out”, Hankook Ilbo reported. The same attacker's IP address was found at multiple locations, the paper said, and some financial companies had not yet identified the intrusion, making the extent of the breach hard to gauge. [ 3 ]
The security industry believes a Chinese-language AI autonomous penetration-testing tool was used, Kyunghyang Shinmun reported, adding that AI agents can now run the whole chain from information gathering and vulnerability scanning to attack execution and adjustment without human input, while South Korea's defensive AI remains at an early stage. Seoul Economic Daily said a Chinese-developed AI hacking tool was used and warned that North Korea could also target financial systems and national infrastructure such as telecommunications, power and transport. [ 2 , 5 ]
On October 6, Prime Minister Han Sung-sook chaired a meeting at the Government Seoul Complex on personal data leaks at financial and public institutions. She said existing security awareness, security systems and the government's structures cannot respond to the new information environment, and that the financial sector's main computer systems were not the target — some external weak points were. She warned that similar hacking could spread to industry and the public sector and that AI used for phishing could cause secondary damage. She ordered the Financial Services Commission to determine the exact scope of leaked personal information, analyse the causes and inform the public, to supervise customer protection and compensation, and to have the whole financial sector carry out a swift and thorough security check; she ordered police to investigate the hacking group and told the science ministry and the Personal Information Protection Commission to review the personal data protection certification system. She also said false information and fake news about hacked deposit accounts were spreading on social media. [ 6 ]
Seoul Economic Daily reported that the five major financial groups posted record net profit of more than 20 trillion won last year while the five major banks' information protection spending fell 2.4 percent from a year earlier. It said securities, insurance and card companies were conducting their own investigations, and that the Bank of Korea has called for a cyber stress test covering the financial sector as a whole. [ 5 ]
Why it matters
The attacks struck banks that present themselves as having advanced security systems, and the documents say the full extent is not yet known, with some firms still to determine whether they were penetrated and further damage not excluded. The editorials argue that trust, which they call the basis of finance, is at stake, and that leaked data could feed phishing crimes. Seoul Economic Daily reported that bank information-security spending fell even as financial groups posted record profits, and Kyunghyang Shinmun said South Korea's defensive AI is at an early stage.
Key facts
- Hacking attacks hit multiple South Korean financial companies in close succession, with customer information leaked at several of them. [ 2 , 3 , 4 , 5 ]
- Leaks were confirmed at Shinhan Bank, KB Kookmin Bank, Hana Bank, Yegaram Savings Bank and Welcome Savings Bank. [ 2 , 4 ]
- BNK Busan Bank and Hyundai Capital lost outsourced staff and loan recruiter information. [ 2 , 4 ]
- Financial Services Commission Chairman Lee Eok-won said at an October 4 emergency meeting that the possibility of an AI-based attack “cannot be ruled out”. [ 3 ]
- Prime Minister Han Sung-sook said on October 6 that existing security awareness, systems and government structures cannot respond to the new information environment, and ordered a full financial-sector security check. [ 6 ]
- Seoul Economic Daily reported that the five major financial groups posted record net profit of more than 20 trillion won last year while the five major banks' information protection spending fell 2.4 percent from a year earlier. [ 5 ]
- The security industry believes a Chinese-language AI autonomous penetration-testing tool was used in the attacks. [ 2 ]
Confirmed by several sources
- Simultaneous or closely spaced hacking attacks hit multiple financial companies in South Korea. [ 2 , 3 , 4 , 5 ]
- Customer information was leaked at some financial companies. [ 2 , 4 , 5 ]
- Information was leaked at Shinhan Bank, KB Kookmin Bank, Hana Bank, Yegaram Savings Bank and Welcome Savings Bank. [ 2 , 4 ]
- Outsourced staff and loan recruiter information was taken at BNK Busan Bank and Hyundai Capital. [ 2 , 4 ]
- Saemaul Geumgo Central Association and Nonghyup mutual finance were attacked without leaks being reported. [ 2 , 4 ]
Still unclear
- Whether AI was actually used in the attacks. Hankook Ilbo quotes the FSC chairman saying it cannot be ruled out, CBS NoCut News quotes the prime minister calling it presumed, and Kyunghyang Shinmun attributes the assessment to the security industry; no document states it as established fact.
- The use of a Chinese-language or Chinese-developed AI hacking tool. Kyunghyang Shinmun attributes it to the security industry and Seoul Economic Daily reports it without naming a source.
- The full scope of the breach and how many companies were penetrated. Hankook Ilbo says some financial companies had not yet identified the intrusion, Seoul Economic Daily says further damage cannot be excluded, and the prime minister ordered the scope to be established.
- How many records were leaked. Single-source range from Kyunghyang Shinmun, from tens to tens of thousands, with no exact figures in any document.
- Whether Woori Bank and NH Nonghyup Bank were among the attacked institutions. Named only by Kyunghyang Shinmun; Chosun Ilbo's list of affected institutions does not include them.
- Who carried out the attacks. Seoul Economic Daily raises North Korea as a possibility, and the prime minister ordered police to investigate the hacking group; no document gives a confirmed attribution.
- Financial Services Commission Chairman Lee Eok-won said at an October 4 emergency meeting that the possibility of an AI-based attack could not be ruled out. Reported by a single source so far
- Prime Minister Han Sung-sook said on October 6 that existing security awareness, systems and government structure cannot cope with the new information environment, and ordered measures including a full financial-sector security check, a police investigation and a review of personal data protection certification. Reported by a single source so far
- The prime minister's meeting also covered a leak of employee information at a public institution. Reported by a single source so far
What local media are saying
Timeline, local time
- Financial Services Commission Chairman Lee Eok-won speaks at an emergency inspection meeting on the financial-sector breach at the Government Seoul Complex in Jongno, Seoul, saying the possibility of an AI-based attack cannot be ruled out. [ 3 ]
- Korea Economic Daily publishes an editorial calling for the financial sector's security system to be rebuilt after simultaneous AI hacking. [ 1 ]
- Kyunghyang Shinmun reports which banks, savings banks and capital firms were affected, the AI tool believed used, and the early stage of South Korea's defensive AI. [ 2 ]
- Seoul Economic Daily publishes an editorial reporting that bank information protection spending fell 2.4 percent while financial groups posted record profits, and calling for a joint financial-sector response and a cyber stress test. [ 5 ]
- Hankook Ilbo reports the emergency meeting, the FSC chairman's remarks and the same attacker IP found at multiple locations. [ 3 ]
- Chosun Ilbo publishes its editorial summary, saying the hacking was first confirmed at Shinhan Bank and calling it a serious national security matter. [ 4 ]
- Prime Minister Han Sung-sook chairs a meeting at the Government Seoul Complex on personal data leaks at financial and public institutions and orders a full financial-sector security check, a police investigation and a review of certification systems. [ 6 ]