South Korea says traces of Chinese-language AI hacking tool found in bank data breaches

South Korea says traces of Chinese-language AI hacking tool found in bank data breaches

N
News Editor
2026-10-06 10:49:30
South Korea’s financial sector is dealing with a widening personal data breach that now spans seven financial companies, with Shinhan Bank accounting for roughly 25,000 affected individuals. According to local media reports citing the Korea Financial Security Institute, the attacks targeting Shinhan Bank, KB Kookmin Bank and Hana Bank came from nearly identical IP addresses, and investigators also found traces of an AI hacking tool developed in China and based on the Chinese language. The Financial Supervisory Service said on Oct. 6 that there were 33 attack-attempt IPs, or 28 after duplicates were removed, while cautioning that IP locations alone cannot identify the real origin because attackers may route traffic through multiple countries. On the same day, the regulator upgraded its probe into Shinhan Bank to a formal on-site inspection. Prime Minister Han Seong-sook also ordered government bodies and public institutions to immediately clean up dormant or unmanaged websites. The incident has drawn attention to exposed external systems, weak authentication controls and so-called shadow IT assets, as authorities and financial firms move into emergency inspections across the sector.

South Korea’s financial sector is facing a broader personal data breach that has now spread to seven financial companies. Since the case was disclosed on Oct. 1, the number of confirmed affected firms had reached seven by Oct. 6: Shinhan Bank, KB Kookmin Bank, Hana Bank, BNK Busan Bank, Yegaram Savings Bank, Welcome Savings Bank and Hyundai Capital.

Among the major banks, Shinhan Bank reported the largest breach, with about 25,000 people affected. KB Kookmin Bank reported 119 affected individuals, while Hana Bank reported 89.

Breaches hit externally exposed inquiry and support systems

The attacks were concentrated on externally accessible inquiry and business support systems. At Shinhan Bank, the compromised system was a simplified inquiry website used by loan brokers. At KB Kookmin Bank, the affected system was a mobile business support platform used by employees. Hana Bank said its sales support system, or ODS, was targeted.

Reports said core transaction systems, including internet banking and mobile banking, were not breached.

Authorities say three banks saw nearly identical attack IPs

According to South Korean media reports relaying a Herald Business editorial, the Korea Financial Security Institute said the IP addresses used in attacks on Shinhan Bank, KB Kookmin Bank and Hana Bank were nearly identical. The institute also found traces showing the use of an AI hacking tool developed in China and based on the Chinese language.

South Korea’s Financial Supervisory Service said on Oct. 6 that the attack attempts involved 33 IP addresses, or 28 after duplicates were removed. The regulator added that the attackers may have routed traffic through IPs in multiple countries to avoid tracking, making it difficult to determine the attackers’ actual location based only on IP geography.

Two developments on Oct. 6

There were two new developments on Oct. 6. First, the Financial Supervisory Service upgraded its investigation into Shinhan Bank to a formal on-site inspection. Second, Prime Minister Han Seong-sook ordered government agencies and public institutions to immediately clean up websites that are no longer operating or have been left unmanaged.

Shinhan breach crossed South Korea’s 10,000-person legal threshold

Shinhan Bank reported the loan-related personal data leak to the Financial Supervisory Service on Sept. 30 and disclosed it publicly on Oct. 1. The bank said it would fully compensate customers for losses resulting from the incident. Financial authorities held an emergency meeting on Oct. 2 and instructed banks and card companies to inspect their cybersecurity posture and report back.

According to Newsis, external actors entered some of Shinhan’s loan-related services by using an abnormal method that bypassed authentication. The leaked data included customer names, phone numbers, annual income and estimated loan limits. For some customers, resident registration numbers, which are comparable to national ID numbers, and CI, or connection information, were also exposed.

There are concerns that the data could be used to impersonate loan consultations and become a basis for secondary crimes such as voice phishing.

Under South Korea’s Personal Information Protection Act, a leak affecting 10,000 people is a key threshold. Once that level is exceeded, the response burden on regulators and the obligations imposed on financial companies increase sharply. Shinhan crossed that threshold, while the other major banks were around the 100-person level.

Emergency inspections spread across the financial sector

The Herald Business editorial said insurers, securities firms and internet-only banks also found traces of external access attempts, pushing the broader financial sector into emergency inspections. The editorial also said Shinhan Bank, KB Kookmin Bank and Hana Bank had spent more than KRW 123.9 billion on cybersecurity over the past year, yet the latest incident still exposed gaps in protection.

Woori and NH NongHyup have not confirmed leaks

Woori Bank and NH NongHyup Bank have not confirmed any data leaks so far. According to Bizwatch, Woori requires loan broker operations to be handled only on designated tablet devices and only after certificate-based and biometric authentication. The bank also uses two-step authentication and AI-based vulnerability checks, with tools including Xint Web from security firm Theori and in-house tools.

NH NongHyup operates external attack surface management, or ASM, to continuously identify externally exposed websites and apps and manage vulnerabilities. Abnormal external behavior is blocked in real time, and access to important systems requires secondary authentication such as one-time passwords, or OTPs. NongHyup also said allowing loan brokers to separately query customer data carries cybersecurity risk, so related work is handled mainly by internal staff.

Park Sang-won, head of the Korea Financial Security Institute, said one key difference between organizations that were breached and those that were not was whether multi-factor authentication, or MFA, had been deployed. Financial authorities also said whether vulnerabilities in external-facing systems had been patched in advance affected whether intrusions succeeded.

Internet-only banks also saw probing from the same IP group

According to Sisa Journal, the same batch of IPs also probed three internet-only banks. KakaoBank detected repeated access attempts from some of the attack IPs starting in January this year. K Bank also confirmed attempts from the same IPs. Toss Bank said it saw more than 10 access attempts between January and August this year. All three detected and blocked the activity, and none reported personal data leaks.

The publication quoted a financial industry source as saying attackers usually begin by probing a large number of unspecified institutions for weaknesses. If they find a vulnerability or are not blocked, they continue the attack.

On-site inspection to focus on scale, intrusion path and compliance

After receiving Shinhan’s report on Sept. 30, the Financial Supervisory Service first carried out an on-site check to establish the facts and trace the intrusion path. Newsis reported that the regulator upgraded the process to a formal on-site inspection starting Oct. 6, six days after the initial report. The inspection will focus on the exact scale of the leak, the intrusion route and whether Shinhan violated any laws.

Newsis said loan brokers are external personnel, yet they were able to access sensitive credit information such as annual income and estimated loan limits through Shinhan’s system. That has led to questions over whether Shinhan granted overly broad access permissions and failed to manage them properly.

Prime Minister orders cleanup of dormant websites

At a ministerial meeting on personal data leaks involving financial and public institutions on Oct. 6, Prime Minister Han Seong-sook gave an emergency instruction: 「Please immediately organize and clean up websites of government and public institutions that are not operating or have been left unattended.」 Han previously served as chief executive of Naver.

Newsis said the order was seen as a first step in responding to AI-driven automated hacking.

Experts said unused websites can become targets for automated AI hacking programs, part of what is often called shadow IT. Shadow IT refers to IT assets that are outside an organization’s formal security framework or assets that are no longer being managed. Common examples include websites with unclear ownership, APIs left behind by past projects and servers connected to partner companies.

South Korea currently has about 10,000 public websites and about 1,200 mobile apps operated by central government agencies, local governments and public institutions.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.