AI-driven hacking has hit South Korea's banking sector at scale for the first time. On October 2, 2026, the Financial Services Commission held an emergency meeting with banks, card companies and supervisory agencies, directing institutions to inspect their defenses against unauthorized access. Over the previous two days, Shinhan Bank, KB Kookmin Bank, Hana Bank and BNK Financial Group had disclosed data leaks one after another, while Woori Bank and NH NongHyup Bank reported attack attempts with no data exposure found. Yonhap News reported that AI agents were involved in several of the attacks.
Four institutions breached in one week, Shinhan hit hardest
Shinhan Bank disclosed on October 1 that personal and credit information belonging to about 25,000 customers had been leaked, including names, phone numbers, annual income and borrowing limits submitted with loan applications. According to the Financial Services Commission, the attack on Shinhan took place on September 30, and regulators have opened an on-site inspection of the bank. On October 2, KB Kookmin Bank confirmed that information on 119 customers had been exposed, Hana Bank confirmed that the names, personal ID numbers and phone numbers of 89 clients had leaked, and BNK Financial Group reported that 11 items of personal information on an outsourced worker had been stolen. The banks said no financial transaction data was involved, and Shinhan and KB Kookmin pledged to compensate customers for losses linked to the breaches.
The method: credential stuffing first, then AI agents find the path
What sets this incident apart from earlier hacking cases is that AI appears in the attacker's toolkit. According to a report by the Seoul Economic Daily on October 3, investigators found traces of ARTEX AI, a Chinese-language open-source AI penetration testing tool, on a server used in the attack on Shinhan Bank. The attackers first used credential stuffing, automatically feeding leaked IDs and passwords into login systems to probe for an entry point. At Kookmin Bank, Hana Bank and BNK, AI agents reportedly automated the search for vulnerabilities and attack paths. In other words, the slow manual work of finding entrances, testing credentials and mapping routes is being automated.
The breach came through side doors, not the core systems
Notably, none of the entry points sat inside the heavily guarded core transaction systems. At Shinhan, the way in was a quick-inquiry service built for loan brokers; at Kookmin, it was a mobile work-support system for employees. These peripheral services were built for internal convenience, and their authentication is often weaker than that of customer-facing online banking, yet they hold real customer data. Most of the banks became aware of possible leaks on September 30, suggesting the attacks hit multiple institutions at nearly the same time and aimed at the loosest links in the defensive chain.
South Korean banks have long been considered among the most tightly secured institutions, yet the same class of technique broke through several of them in one week. For financial institutions elsewhere, the signal is direct: once attackers use AI agents to hunt for weaknesses in bulk, guarding only the core system is no longer enough. Peripheral services, employee systems and third-party entry points need to be re-audited to core-system standards. The Financial Services Commission has ordered an industry-wide inspection of defenses, and whether a unified standard for AI-driven attacks follows is worth watching.