Local Chorus
Local news from local sources, read in your language.
Settled
Verified

Shinhan, KB Kookmin, Hana and Busan banks report customer data leaks in hacking wave

🇰🇷 South Korea, Seoul 13:36 IT & software Business8 Tech2 Official updated 2 d ago first reported by 서울신문

In short

A wave of hacking attempts on South Korean banks has produced customer data leaks at Shinhan Bank (about 25,000 customers), KB Kookmin Bank (119), Hana Bank (89) and BNK Busan Bank (11 outsourced staff), while Woori and NH Nonghyup banks said attempts against them were blocked. KB Kookmin and Hana said the affected systems were employee and sales support channels separate from internet and mobile banking, and both pledged full compensation for any damage. The Financial Services Commission held an emergency meeting on Oct 2 and police opened a pre-indictment investigation, while security researchers suspect AI-based automated tools were used — a claim authorities say is not yet confirmed.

Read the full story 3 min read

Hacking attempts on South Korean banks have produced customer data leaks at four lenders. About 25,000 Shinhan Bank customers' personal credit information leaked through a service for loan recruiters, KB Kookmin Bank reported 119 customers affected through an employee mobile work support system, Hana Bank reported 89, and BNK Busan Bank said information on 11 outsourced development staff was exposed. Woori Bank and NH Nonghyup Bank said they faced intrusion attempts but that no leak has been identified so far. [ 4 , 6 , 9 ]

KB Kookmin said it first identified the possibility of a leak on the night of Sept 30, when it detected abnormal external access to its employee mobile work support system, and blocked the server and access paths immediately. Hankook Ilbo reported the attacker reached the system through a program that runs it and repeatedly tried to log in while changing passwords. The bank said the incident was unrelated to internet and mobile banking transaction systems, notified affected customers individually, and said it would fully compensate any damage, while warning customers about calls, texts and emails impersonating banks or delivery firms. [ 3 , 4 ]

Hana Bank said an external hacking agent attacked its sales support system (ODS), exposing names, addresses, email addresses, phone numbers and workplace names of 89 customers, and that ODS runs separately from internet and mobile banking. It reported the matter to the Financial Supervisory Service and other agencies on Oct 1, blocked suspicious IP addresses and formed a task force. Busan Bank said its employee mobile sales support system was attacked on the afternoon of Oct 1 and that information on 11 outsourced development staff was exposed. [ 4 , 6 ]

Shinhan Bank's leak came through a mobile web page used by loan recruiters, with names, phone numbers, annual income and calculated loan limits among the leaked items. Hankook Ilbo reported the attacker used stolen customer numbers to reach other services for additional data such as phone numbers and dates of birth. Shinhan said it blocked external access, suspended the service and would fully compensate confirmed damage. [ 3 , 4 , 9 ]

On Oct 2 the Financial Services Commission held an emergency response meeting chaired by Secretary-General Shin Jin-chang with the FSS, major banks and card companies, ordering checks on any path that reaches internal information without authentication and rapid sharing of threat information. Police began a pre-indictment investigation, and Electronic Times reported that a National Assembly committee audit is expected to take up the case. A Seoul Shinmun headline said Yegaram was also breached, without giving details. [ 4 , 6 , 7 , 9 ]

Researchers suspect AI-based automation was used. Electronic Times, citing the security industry, said a Chinese-language autonomous penetration testing system called ARTEX AI, which uses large language models and multiple agents and is distributed as open source on GitHub, was found on the server used in the Shinhan attack and was said to have hit other financial firms. Maeil Business reported that credential stuffing — the automated testing of leaked ID and password combinations on other sites — is accelerating with AI, and advised using different passwords per site and turning on multi-factor authentication. Authorities and the banks said the cause and method are not yet confirmed. [ 6 , 9 ]

Why it matters

The leaks expose security gaps in bank systems that customers never log into themselves, such as employee work-support and loan-recruiter channels, which officials ordered checked across the sector. With the Financial Supervisory Service investigating and a parliamentary audit expected to take up the case, the incidents put pressure on how banks control access outside their main transaction systems. If researchers' suspicion of AI-based automation is confirmed, it would point to a faster and more scalable attack method.

Key facts

  • About 25,000 Shinhan Bank customers' personal credit information leaked through a service used by loan recruiters. [ 3 , 4 , 6 , 9 ]
  • KB Kookmin Bank said 119 customers' information leaked through an employee mobile work support system after abnormal external access was detected on the night of Sept 30. [ 2 , 3 , 4 , 6 ]
  • Hana Bank said 89 customers' information leaked after an attack on its sales support system (ODS). [ 4 , 5 , 6 , 9 ]
  • BNK Busan Bank said information on 11 outsourced development staff was exposed in a web server attack on Oct 1. [ 4 , 6 ]
  • Woori Bank and NH Nonghyup Bank said they faced similar intrusion attempts but that no data leak has been identified so far. [ 4 , 6 , 9 ]
  • The banks said the affected systems were separate from internet and mobile banking, and pledged full compensation for any customer damage. [ 2 , 3 , 4 ]
  • The Financial Services Commission held an emergency response meeting on Oct 2 and ordered banks to check all paths that could reach internal information without authentication. [ 4 , 9 ]
  • Financial authorities and banks said the specific cause and attack method have not been confirmed, while security researchers suspect AI-based automation tools were used. [ 6 , 9 ]

Confirmed by several sources

  • About 25,000 Shinhan Bank customers' personal credit information was leaked after an attack on a mobile webpage used by loan recruiters. [ 3 , 4 , 6 , 9 ]
  • KB Kookmin Bank said 119 customers' personal information was leaked through an employee mobile work support system. [ 2 , 3 , 4 , 6 , 9 ]
  • Hana Bank said 89 customers' personal information was leaked through an attack on its sales support system (ODS). [ 4 , 5 , 6 , 9 ]
  • BNK Busan Bank said personal information of 11 outsourced development staff was exposed in a web server attack. [ 4 , 6 ]
  • Woori Bank and NH Nonghyup Bank said they faced similar intrusion attempts but that no data leak has been identified so far. [ 4 , 6 , 9 ]
  • The affected banks said the compromised systems were separate from internet and mobile banking transaction systems and that they would fully compensate any damage. [ 2 , 3 , 4 ]
  • The Financial Services Commission held an emergency response meeting on Oct 2 chaired by Secretary-General Shin Jin-chang with the Financial Supervisory Service, major banks and card companies. [ 4 , 9 ]
  • KB Kookmin Bank said it first identified the possibility of a leak on the night of Sept 30. [ 3 , 4 ]

Still unclear

  • Whether AI-based automated tools were actually used in the attacks. Financial authorities and the banks said the specific cause and method have not been confirmed and that all possibilities are under investigation; reports of AI involvement rest on security-industry claims and anonymous sources.
  • The role of the Chinese-language autonomous penetration testing system ARTEX AI, said to have been found on the server used in the Shinhan Bank attack and to have been used against other financial firms. This is a security-industry claim reported by a tech outlet; authorities have not confirmed the attackers' identity or the tool's role.
  • A Seoul Shinmun headline said Yegaram was also breached, extending the wave beyond Shinhan and Kookmin. Only a headline was available; the documents give no scope, customer numbers or institution details.
  • Police opened a pre-indictment investigation into the simultaneous hacking of banks. Reported by a single outlet; the documents contain no police statement on the investigation.

What local media are saying

Business mediaBusiness outlets focused on the sequence and scale of the leaks — roughly 25,000 Shinhan customers, then 119 at KB Kookmin, 89 at Hana and 11 outsourced staff at Busan Bank — on the banks' pledges of full compensation, and on the official emergency meetings. One business outlet devoted its coverage to password-reuse and multi-factor authentication advice, and one headline framed the crisis around banks that had promoted their own security systems. [ 1 , 2 , 4 , 5 , 7 , 8 , 9 ]
Technology mediaTech outlets emphasised that the breached systems were employee- and recruiter-facing channels outside banking transaction systems, and the suspected use of AI-based automated penetration tools, while noting that authorities have not confirmed the cause or method. [ 3 , 6 ]

Timeline, local time

  1. Woori Bank said it had faced continuous hacking attempts since Sept 29, but its own intrusion prevention system worked and no data leak was identified. [ 4 ]
  2. KB Kookmin Bank first identified the possibility of a data leak through abnormal external access to its employee mobile work support system. [ 3 , 4 ]
  3. Hana Bank reported hacking attempts against other financial institutions to the Financial Supervisory Service and blocked the internet protocol addresses involved. [ 4 ]
  4. Busan Bank's employee mobile sales support system was attacked through a web server, exposing personal information of 11 outsourced development staff. [ 4 , 6 ]
  5. The Financial Supervisory Service began an emergency on-site investigation after the leak of about 25,000 Shinhan Bank customers' records was disclosed. [ 6 ]
  6. The Financial Services Commission held an emergency response meeting chaired by Secretary-General Shin Jin-chang with the FSS, major banks and card companies. [ 4 , 9 ]
  7. KB Kookmin Bank announced that 119 customers' personal information had been leaked and Hana Bank announced 89 customers affected. [ 2 , 4 ]
  8. Police began a pre-indictment investigation into the simultaneous hacking incidents targeting banks. [ 6 ]
  9. Reports said an AI-based penetration testing system, ARTEX AI, was suspected in the attacks, and a National Assembly committee audit was expected to take up the case. [ 6 ]