South Korea's Shinhan Bank disclosed a data breach affecting 25,000 customers, with cybersecurity experts suspecting AI tools were used in the attack. KB Kookmin Bank and Hana Bank also reported breaches on the same day, exposing data from 119 and 89 customers respectively. Investigators found traces of a Chinese-language AI penetration-testing tool linked to ARTEX AI, raising concerns about the growing risk of AI-enabled cyberattacks in the financial sector.

News article

AI Tools Suspected in Shinhan Bank Hack

South Korea's Shinhan Bank experienced a significant data breach affecting approximately 25,000 customers, with cybersecurity experts suspecting that AI-powered cyberattacks played a central role in the incident

1

. The attackers likely deployed sophisticated AI agents to probe for vulnerabilities and gain unauthorized access to a service used by loan recruiters, according to Yonhap News

1

. The exposed information included customer names, phone numbers, annual income, borrowing limits, and other personal and credit information submitted for loan applications

2

. Shinhan Bank, a unit of Shinhan Financial Group Co., acknowledged that an unauthorized external party bypassed authentication mechanisms to access these systems

1

.

Multiple Korean Banks Face Data Breaches

The Shinhan Bank incident was not isolated. KB Kookmin Bank reported that personal information belonging to 119 customers was leaked following abnormal external access to a mobile system used by employees

2

. The compromised data varied by customer and included names, phone numbers, addresses, and resident registration numbers in encrypted format

3

. Hana Bank disclosed that 89 customers had their personal information exposed, including resident registration numbers, names, addresses, email addresses, phone numbers, and workplace information

3

. Additionally, BNK Financial Group reported that personal information belonging to 11 outsourced workers had been leaked, while Woori Bank and NH NongHyup Bank faced hacking attempts but reported no data exposure

3

.

ARTEX AI and AI Penetration-Testing Tool Linked to Attack

Investigators discovered traces of a Chinese-language AI penetration-testing tool on a server believed to have been used in the attack against Shinhan Bank

2

. The server's HTML title reportedly contained a Chinese phrase meaning "AI autonomous penetration testing console," suggesting a possible connection to ARTEX AI, an open-source autonomous penetration-testing system built on a large language model

3

. The server is suspected of having been used in a credential stuffing attack, a technique that involves using stolen usernames and passwords to attempt access to accounts through large-scale automated login attempts

2

. Mun Chong-hyun, director at cybersecurity firm Genians, noted that several recent attacks in South Korea have featured AI tools initially developed and shared for defensive purposes, describing them as a "double-edged sword" when used maliciously

1

.

Growing Risk of AI-Enabled Cyberattacks in Financial Sector

Cybersecurity experts warn that advances in AI are lowering the technical barriers to cyberattacks in the financial sector

2

. The technology now moves beyond merely suggesting attack methods, with AI agents capable of combining disparate information to identify vulnerabilities, launch attacks, and refine their tactics based on results

3

. "As AI-related technologies advance, source codes are being shared indiscriminately and used for malicious AI hacking attempts, so many people need to take caution," Mun added

1

. Sungho Hwang, Korea country manager at NordVPN, emphasized that "this particular breach is worrying because it exposed both personal and financial information" and noted that "generative AI has made these attacks even more convincing"

1

. Financial institutions face heightened risks as customer information is increasingly handled by loan brokers, outsourced service providers, and digital platforms

3

.

Regulatory Response and Emergency Inspection

The Financial Supervisory Service launched an emergency inspection to determine the nature and extent of the data breaches

1

. The Financial Services Commission held an emergency response meeting and dispatched investigators to the affected institutions as soon as the breaches were reported

2

. Regulators shared details of the attacks, including IP addresses and intrusion methods, with relevant agencies to prevent further damage through threat intelligence sharing

3

. FSC Secretary General Shin Jin-chang stated, "Preventing data leaks requires financial institutions to maintain a high level of readiness. We will strengthen coordination by monitoring intrusion attempts and rapidly sharing threat intelligence, while examining the causes of the breaches and attack methods to identify and swiftly introduce necessary regulatory improvements"

2

. The affected banks pledged to fully compensate customers for any losses resulting from the data breaches

3

. Watch for potential regulatory changes as authorities examine whether current cybersecurity frameworks adequately address AI-driven cyber threats.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved