AI Tools Suspected in South Korea Bank Hacks That Exposed 67,000+ Customers

South Korea’s AI bank hacks have moved from a cybersecurity incident to a national policy issue. On Tuesday, President Lee Jae Myung told a cabinet meeting that artificial intelligence appears to have been used in a wave of intrusions that exposed the personal and financial data of tens of thousands of bank and lender customers, and police have opened a full-scale investigation. Investigators say they found traces of an open-source, AI-driven penetration-testing tool on a server linked to the attacks — one of the clearest real-world cases so far of AI tools being tied to a large financial-sector breach.

Here is what is confirmed, what officials and experts are saying, and what to watch next.

What Happened: The Key Facts

Verified facts, as reported by Reuters, AFP, The Korea Times and Korea JoongAng Daily:

  • When: The attacks began on Thursday, Oct. 2, 2026, according to The Korea Times. Breaches were disclosed over the following days.
  • Who was hit: Seven financial firms reported compromises — Shinhan Bank, KB Kookmin Bank, Hana Bank, BNK Busan Bank, Yegaram Savings Bank, Welcome Savings Bank and Hyundai Capital. Woori Bank and NH NongHyup Bank were also targeted but reported no confirmed damage, according to Korea JoongAng Daily.
  • How many people: More than 67,000 people were affected, according to The Korea Times; AFP, citing the Financial Services Commission (FSC), put the figure at more than 68,000.
  • What was exposed: Names, contact details, resident registration numbers, annual income and loan limits, per The Korea Times. Shinhan Bank confirmed that data from about 25,000 loan applications leaked; Yegaram Savings Bank’s breach involved roughly 40,000 customers.
  • The AI link: Investigators found traces of Artex AI — a Chinese-language, open-source autonomous penetration-testing tool published on GitHub — on a server associated with the attacks. A government official told AFP it was “highly likely” the tool was used.

Timeline at a Glance

Date (2026)Development
Thu., Oct. 2Attacks on financial institutions begin (The Korea Times)
Sun., Oct. 4President Lee orders an investigation; FSC Chairman Lee Eog-weon convenes an emergency meeting with regulators, industry associations and executives
Oct. 4–5Financial Supervisory Service and Financial Security Institute share 28 unique attack-linked IP addresses with the sector (Reuters)
Tue., Oct. 6Lee tells cabinet AI appears to have been used; Prime Minister Han Sung-sook orders “a complete overhaul of security systems”; police form a dedicated investigation team (SBS)

How AI Was Used in the South Korea Bank Hacks

According to The Korea Times, the attackers did not break into banks’ core systems. Instead they went after less-protected entry points — employee systems, contractor networks and loan-agent platforms — and used credential stuffing, in which usernames and passwords stolen in earlier breaches are tried automatically across many services.

That is where an AI-driven tool matters. Lim Jong-in of Korea University’s Graduate School of Information Security told The Korea Times that the tool is capable of automatically searching for vulnerabilities and targeting partner-company servers rather than banks’ main systems. In other words, automation lets attackers probe far more doors, far faster, and find the weakest one.

Important caveat (developing information): Officials have stressed that finding Artex AI traces does not mean the attackers were Chinese. Because the tool is public and attackers routed traffic through IP addresses in multiple countries, a government official told AFP the use of the tool does not indicate who is responsible. Police are seeking international cooperation to trace overseas IP addresses, Korea JoongAng Daily reported. No suspect has been publicly identified.

What Officials Are Saying

Government statements, attributed:

  • President Lee Jae Myung, at Tuesday’s cabinet meeting (via Reuters): “In some hacking incidents, signs have emerged of AI being used, causing considerable public concern and anxiety.” He also said, per AFP, “We have now reached a point where AI can make (hacking) easy for even those without special skills.”
  • FSC Chairman Lee Eog-weon said there was “no indication that sensitive information directly usable for unauthorized payments has been leaked,” but warned that secondary damage such as voice phishing and smishing remains possible (The Korea Times).
  • Prime Minister Han Sung-sook ordered a complete overhaul of financial-sector security systems, SBS reported.

What Experts Say

Expert commentary:

  • Hwang Sung-ho, Korea country manager for Nord Security, told The Korea Times that combining personal and financial information “gives criminals enough context to create highly convincing, personalized scams.”
  • Hwang Suk-jin of Dongguk University’s Graduate School of International Affairs and Information Security said defenses “cannot remain fragmented at individual company levels as attacks become more coordinated and automated.”
  • Korea University security professor Kim Seung-joo told Korea JoongAng Daily that “vulnerabilities were not properly managed.”

The Korea Times noted that Shinhan, KB Kookmin and Hana together spent about 124 billion won (roughly $92 million) on information security last year — a reminder that spending at the core does not protect weaker links in the supply chain.

Why It Matters Beyond Korea

Analysis: The incident lands amid growing evidence that AI is lowering the skill barrier for cyberattacks. AFP reported that Japan has seen a similar run of breaches, with at least three companies reporting leaks — including car-sharing service Times Car, which reported 6.6 million compromised accounts. Reuters also noted that Australia disclosed in September that an AI agent had breached a government health-data portal in June. Late last month, AI developer Anthropic published research warning that advanced cyber capabilities are spreading to openly available models.

For banks everywhere, the lesson is less about exotic AI and more about basics at scale: reused passwords, under-secured vendors and partner portals, and slow detection. AI-driven tools make it cheap to test all of them at once.

What Affected Customers Can Do

  • Be alert to calls, texts and messages that reference your loan or income details — these can be used to make scams look legitimate.
  • Change reused passwords and enable stronger sign-in methods. Our explainer What Are Passkeys? walks through one phishing-resistant option.
  • Contact your bank directly through official channels, not links in messages.

What to Watch Next

  • Police findings: Whether investigators can attribute the attacks, and how much of the work was automated.
  • Regulatory response: Details of the prime minister’s ordered security overhaul and any new rules for vendors and loan-agent platforms.
  • Parliament: South Korea’s month-long National Assembly audit began Tuesday, and financial-sector security is expected to be raised.
  • Legal action: At least one Shinhan Bank breach victim is organizing a class-action suit, Korea JoongAng Daily reported.
  • Further disclosures: Additional institutions or a higher victim count as audits continue.

Related Coverage on Vanderbiltreport.com

Sources

This is a developing story. Figures for affected customers differ slightly between sources and may change as investigations continue.

Publisher Disclaimer: Vanderbiltreport.com publishes news and information for general informational and educational purposes. Information is compiled from sources believed to be reliable, but Vanderbiltreport.com does not guarantee the accuracy, completeness, or timeliness of all information presented. Readers should independently verify information and conduct their own research before making financial, investment, business, or other decisions.

WordPress Ads