Security & AI news

Breaches and AI-driven attacks · By FireAI Security & Research Team · Published

South Korean banks report personal data leaks attributed to AI-driven attacks as regulators order a sector review

Shinhan, KB Kookmin, Hana and other South Korean lenders reported personal data leaks in early October 2026; officials suspect AI agents and warned of voice phishing.

A bank building and the FireAI protection mascot, next to the words “Korean banks leak client data after AI attacks.”

A series of data breaches at South Korean banks and other lenders in the first days of October 2026 is attributed by officials and industry sources to AI-driven attacks, according to the Korea JoongAng Daily and The Korea Times. President Lee Jae Myung ordered a thorough investigation on 4 October, and the Financial Services Commission (FSC) ordered an industrywide security review [1] [2]. The leaked records are personal data of bank clients, which makes the case relevant to anyone whose details are held by a financial institution.

Background

An AI agent, as the JoongAng Daily defines it, is an autonomous system capable of making decisions and taking action on its own [1]. The reports concern attackers who are believed to have used such tools to search a bank's systems for weak points, not a failure of the banks' payment systems.

What the reports describe

KB Kookmin Bank announced on 2 October that personal and credit information of 119 clients was leaked in an external breach. The JoongAng Daily reports that an AI agent is believed to have compromised a mobile work support system used by employees and reached names, phone numbers, addresses and encrypted resident registration numbers, without transaction data [1]. Hana Bank said an external hacking agent attempted to break into its sales support system, leaking personal information of 89 clients, including names, resident registration numbers, addresses, email addresses and phone numbers [1].

Shinhan Bank disclosed unauthorised access to a service used only by loan brokers, exposing data of more than 25,000 clients, and BNK Financial Group reported exposure in 11 cases. Woori Bank and NH Nonghyup Bank reported no leaks of client information [1]. The Korea Times adds that Yegaram Savings Bank reported a leak involving about 40,000 clients and that Hyundai Capital said some personal data of 146 housing loan agents had been exposed. It lists the leaked fields as names, phone numbers, annual income and loan limits, with resident registration numbers exposed for some clients [2].

On the attribution, The Korea Times reports that the hackers behind the Shinhan attack are suspected to be based overseas and are believed, according to industry officials, to have used advanced AI tools. Traces of a Chinese-language AI penetration-testing tool were reportedly found on a server believed to have been used, whose page title contained a phrase meaning "AI autonomous penetration testing console", which suggests a possible link to ARTEX AI, an open-source system built on a large language model [2]. The FSC chairman is quoted as not ruling out that AI was used in the attacks, and police have opened an investigation amid speculation that AI-powered tools were involved [2].

Implications for families and individuals

Regulators found no indication so far that information usable for unauthorised payments was leaked, but warned of secondary harm such as voice phishing that uses the leaked details [2]. The affected clients cannot repair the banks' systems; the practical risk is a convincing call or message that quotes accurate personal data.

The FSC told firms to inventory IT assets and services, including AI systems, that are reachable from outside, to check for paths that allow access to internal information without authentication, and to share the attackers' IP addresses and intrusion records with agencies such as the Korea Internet & Security Agency [1].

Recommendations

  1. Clients of an institution that announces a leak should read its notice and contact it through a number printed on its official site, not through a number in a message.
  2. Treat any call or text that quotes personal or loan details with suspicion, even when the details are correct, because leaked data makes such contacts convincing.
  3. Never give one-time codes or approve a transfer on request from a caller who claims to be a bank or an investigator.
  4. Change passwords for the affected accounts and use a different one for each service.
  5. Households with relatives who are likely targets of phone scams should agree on a call-back routine before the first attempt.

Relevance to FireAI

FireAI is a firewall for one Mac. It shows which apps connect to which services in Activity and where in the world on the world map, and it asks before an app contacts a destination for which no rule exists.

FireAI does not protect a bank's servers, cannot stop a leak at an institution that holds a person's data, does not block phone or text scams, and does not tell whether leaked details are being used against someone. Its scope is the connections that apps on a person's own Mac make.

Limitations

The attribution to AI agents is described as belief and suspicion by officials and industry sources, and the Korea Times quotes the FSC chairman as not ruling out AI use, not as confirming it [2]. Neither source names the attackers, and each lists a different set of affected institutions. The figures reflect early disclosures and may change as the investigation proceeds.

Try FireAI, by HisnLabs free for 17 days.

Sources

  1. Korea JoongAng Daily, 4 October 2026: AI hackers target Korea’s banks, trigger industrywide security review
  2. The Korea Times, 4 October 2026: Lee orders thorough probe into data breaches at local banks