Four of South Korea's largest banks disclose data breaches within days of each other
TLDR
- Shinhan Bank, KB Kookmin Bank, Hana Bank and BNK Financial Group each disclosed separate data breaches between 1 and 2 October, all involving loan-inquiry or employee-support systems rather than core banking platforms.
- Shinhan's breach, the largest, exposed data on about 25,000 customers after an attacker bypassed authentication in a mobile service used by loan agents.
- Hana and KB Kookmin each reported smaller breaches, affecting 89 and 119 customers respectively, both via internal support systems rather than customer-facing banking apps.
- Security analysts found traces of an AI penetration-testing tool, ARTEX AI, on a server suspected of being linked to the Shinhan breach, though neither the bank nor regulators have confirmed its use.
Shinhan Bank disclosed on 1 October that an unauthorised party had bypassed identity verification in a mobile inquiry service used by loan agents to check application progress, exposing customers' names, phone numbers, annual income, calculated loan limits, 66 resident registration numbers and 97 CI identifiers used for online identity verification.2 The bank said it blocked the external IP addresses involved and suspended the affected service.2
KB Kookmin Bank said on 2 October that personal information on 119 customers, including names, phone numbers, addresses and encrypted resident registration numbers, was leaked after abnormal external access to a mobile system used by employees; it detected the possible breach on Wednesday night and blocked the affected server and access routes.1 Hana Bank separately reported that personal information on 89 customers, including resident registration numbers, names, addresses, email addresses, phone numbers and employer names, was exposed through its sales support system (ODS) after an external hacking attempt; the bank said the system is separate from its internet and mobile banking transaction platforms.2 BNK Financial Group reported that 11 records containing outsourced employees' personal information were leaked in a separate incident, while Woori Bank and NH NongHyup Bank said they faced hacking attempts that did not result in exposed data.2
All four banks said customer banking-transaction information was not affected and pledged to compensate customers for any resulting losses.1 The Financial Services Commission convened an emergency meeting with the Financial Supervisory Service, security officials and industry representatives, ordering checks of externally accessible systems and calling for stronger authentication, tighter access controls and faster threat-intelligence sharing, while vowing to investigate the attacks and draft regulatory improvements.1 Security analysts found traces of an AI penetration-testing tool called ARTEX AI on a server suspected of being linked to the Shinhan attack, though neither Shinhan nor financial authorities have officially confirmed whether the tool was used.1
Why it matters: four of South Korea's largest banks disclosing separate breaches of internal, non-customer-facing systems within three days of each other, with regulators publicly scrutinising possible AI-assisted intrusion tooling, suggests either a shared vulnerability across the sector's back-office systems or a coordinated campaign working through them one bank at a time.