Morning Edition · №
Cybersecurity SEOUL, SOUTH KOREA

South Korean Banks Probe Whether AI Tools Powered a Breach That Exposed 25,000 Shinhan Customers

Investigators are examining whether an automated, AI-assisted attack let hackers bypass identity checks and systematically mine a loan-agent portal before the intrusion was detected.

South Korean Banks Probe Whether AI Tools Powered a Breach That Exposed 25,000 Shinhan Customers
A padlock resting on a computer keyboard, an illustration of data security. — Photograph: FlyD / Unsplash
SHARE X f in ⧉

South Korean regulators are investigating whether artificial intelligence tools were used to pull off a data breach at Shinhan Bank that exposed personal and financial information belonging to roughly 25,000 customers, in one of the first cases regulators there have publicly tied to possible AI-assisted hacking of the financial sector.

Unauthorized access to Shinhan's systems ran from the early hours of September 29 into September 30, according to the Korea Herald, with the bank first detecting suspicious activity around 9:30 a.m. local time. The intrusion targeted a mobile inquiry portal used by loan-broker agents to track application progress — a peripheral system walled off from the core banking infrastructure that handles deposits and transfers, which the bank says was never touched.

Investigators believe the attacker bypassed the portal's identity verification, then systematically cycled through randomized customer identification numbers and query values to extract records at scale, according to reporting from the Korea Herald and the Korea Herald's business desk. The data taken included customer names, phone numbers, annual income figures and calculated loan limits, along with 66 resident registration numbers — South Korea's national-ID equivalent of a Social Security number — and 97 "connected information" records used for identity verification.

AI Suspected, Not Yet Confirmed

Security analysts examining the intrusion say the pattern of rapid, systematic probing is consistent with attacks that use AI tools to cycle through large volumes of input values automatically rather than relying on a human operator, a technique sometimes used to run credential-stuffing attacks that test usernames and passwords leaked from earlier, unrelated breaches against a new target. The Korea Herald reported that investigators found traces of an AI-driven penetration-testing tool on a server linked to the intrusion, though neither Shinhan nor financial authorities have officially confirmed that such a tool was used in the attack itself.

Shinhan Bank president Jung Sang-hyuk issued a public apology after the breach was disclosed, and the bank said it has blocked external connections to the affected portal, suspended the service altogether and pledged to compensate any customer who suffers financial losses as a result. Because Shinhan's shares trade in the U.S. as American depositary receipts, the bank also filed a disclosure with U.S. regulators.

The Korea Financial Security Institute, alongside the Financial Services Commission and Financial Supervisory Service, has opened an on-site inspection to determine the full scope of the leak, the precise attack vector and whether Shinhan's security systems functioned as intended. A separate, smaller breach disclosed days later at KB Kookmin Bank — which said the personal data of 119 customers leaked through an employee support system — has added to regulators' urgency, though officials have not linked the two incidents.

A Wider Worry for Financial Regulators

The case lands amid broader concern among South Korean officials about AI-enabled attacks on the financial system, after a string of incidents this year prompted the Financial Supervisory Service to step up scrutiny of bank cybersecurity practices generally. Security researchers have warned for much of 2026 that AI agents capable of autonomously probing for software vulnerabilities and automating reconnaissance could lower the technical bar for large-scale data theft, even when, as in Shinhan's case, the entry point is a comparatively obscure internal tool rather than a bank's main systems.

Shinhan has not said when the investigation will conclude. Until it does, the exact role AI tools played — if any — in one of South Korea's most closely watched breaches this year will remain unresolved.

SHARE THIS ARTICLE X Facebook LinkedIn Copy link
Claire Fontaine · Technology & Regulation Correspondent

Reports on technology and its regulation for UBStandard, with a focus on Brussels, AI policy and Europe's digital economy.

[email protected]
Related coverage Front page →