Skip to content
TEN Brief Ten verified stories a day 2026.10.07 KO

이 기사는 한국어로도 읽을 수 있습니다 →

Tech · 3 min read · Breaking

AI-assisted hack hits 7 Korean financial firms, 66,000 people — through back-office systems

Between late September and early October 2026, seven South Korean financial companies confirmed personal data leaks from attacks believed to have used AI. The banks are KB Kookmin, Shinhan, Hana and BNK Busan; the others are Yegaram and Welcome savings banks and Hyundai Capital. About 66,000 people were affected, mostly at Yegaram (about 40,000) and Shinhan (25,729). Servers linked to the attacks contained traces of ARTEX, a Chinese-language AI autonomous penetration-testing tool. The intruders reached peripheral systems used by loan agents and staff, not core banking. Woori Bank and NH Nonghyup Bank were also attacked but have found no leaks

Two analysts seen from behind in a sunlit bank security operations center

The three lines

  • Scale — seven firms, about 66,000 people; Yegaram ~40,000, Shinhan 25,729; incomes and loan limits exposed
  • Method — near-simultaneous attacks from one IP on four banks; traces of the AI pen-testing tool ARTEX
  • Response — regulators check ~500 firms by October 8; KISA monitoring raised to caution; police open formal probe

Key questions

Which Korean banks were hacked in October 2026
**Four banks and three non-bank lenders confirmed leaks.** (as of October 6, 2026) | Firm | People affected | System breached | |---|---|---| | Yegaram Savings Bank | ~40,000 | Not disclosed | | Shinhan Bank | 25,729 | Loan-agent service | | Welcome Savings Bank | ~2,200 corporate records | Not disclosed | | Hyundai Capital | 146 loan agents | Not disclosed | | KB Kookmin Bank | 119 | Staff mobile work app | | Hana Bank | 89 | Sales support system (ODS) | | BNK Busan Bank | 11 contract developers | Not disclosed |
What is ARTEX AI hacking tool
**Strings reading 'ARTEX AI' and 'AI autonomous penetration testing console' were found on attack servers.** | Item | Detail | |---|---| | Type | LLM-based autonomous penetration-testing system, Chinese-language | | Found on | Web servers tied to attacks on four major banks | | Pattern | Same IP for banks; different IPs, similar tactics for savings banks | | Targeting | Apparently scanning for weak spots rather than picking victims |
Why were Woori and Nonghyup not breached
**Basic access controls, not AI defences.** | Bank | Loan-agent access | |---|---| | Woori | Designated tablets only, separate certificate plus biometrics | | NH Nonghyup | No internal-network access for agents at all | | Breached banks | Missing identity checks, weak device controls, unpatched known web flaws |

All five of South Korea's largest banks were hit by the same campaign, and three of them were breached. From late September to early October 2026, attackers took personal data on about 66,000 people from seven financial firms — four banks and three non-bank lenders. Traces of an AI autonomous penetration-testing tool on attack servers have made this Korea's first widely reported "AI hacking" case in finance. But the weak points it found are much older than AI.

1. What happened — ten days from September 29

DateEvent
Sept 29–30Shinhan Bank detects intrusion
Sept 30KB Kookmin Bank confirms attack attempt
Oct 1Hana Bank detects intrusion attempt; police begin inquiry
Oct 2National police cyber-terror unit opens pre-investigation into four banks
Oct 4Financial Services Commission and FSS emergency meeting; President Lee Jae-myung orders a thorough probe
Oct 6Police open formal investigation; issue raised at parliamentary audit

The four banks were hit almost simultaneously from the same IP address; the savings banks saw different IPs but similar tactics. A server linked to the Shinhan attack held strings reading "ARTEX AI" and "AI autonomous penetration testing console" — reportedly a large-language-model system built on Chinese open-source tools. Regulators believe the tool was sweeping the internet for weak spots, not singling out particular firms.

2. Where and how much — the edges, not the core

FirmAffectedBreached system
Yegaram Savings Bank~40,000 peopleNot disclosed
Shinhan Bank25,729Loan-agent service
Welcome Savings Bank~2,200 corporate recordsNot disclosed
Hyundai Capital146 loan agentsNot disclosed
KB Kookmin Bank119Staff mobile work app
Hana Bank89Sales support system
BNK Busan Bank11 contract developersNot disclosed
Woori, NH NonghyupNo leaks found—

Deposits and transfer systems were not touched. The intruders came in through back-office tools that loan agents and employees reach from outside. What leaked still matters: at Shinhan, names and phone numbers came with annual income and loan limits, plus 66 resident registration numbers. That is exactly what a fraudster needs for a convincing "refinance your loan" phone scam.

3. Same attack, different outcome

Woori and NH Nonghyup were attacked too. The difference was not AI defence. Woori lets loan agents in only from designated tablets with a separate certificate and biometrics; Nonghyup never gives agents internal-network access at all. The breached banks, by contrast, had missing identity checks, weak mobile-device controls and known web vulnerabilities left unpatched.

In other words, the AI did not create new holes — it found existing ones faster and at greater scale than a human team, much like the OpenAI agent that opened non-public files on an Australian government site in September. The science ministry raised KISA's private-sector monitoring to "caution" on October 4 and moved to 24-hour response; the FSS sent attacker IPs to about 500 financial firms and wants inspection results by October 8. Korea's five-step cyber alert scale is explained in "Korea's cyber crisis alert levels."

4. What remains unconfirmed

  • AI involvement rests on server evidence; police have not given a formal finding.
  • The attackers' identity and nationality are unknown.
  • Breach routes at the savings banks and Hyundai Capital have not been disclosed.
  • Results from securities, insurance and fintech firms, due October 8, could add victims.

Sources

  1. The Economy Times (KET) — Financial sector breached by 'AI hacking'
  2. Businesskorea — 'AI hacking' that breached seven financial firms: simultaneous attacks from the same IP
  3. Financial News — All five major banks were attacked; security basics decided the damage
  4. News1 — Science ministry raises KISA monitoring to 'caution' after financial AI hacking
  5. Edaily — AI hacking sweeps banks: simultaneous leaks at Shinhan, Kookmin, Hana

Verification

Published
Last modified
Cross-check
Checked against 5 independent sources.
Unverified
  • The role of an AI agent rests on evidence such as strings on attack servers; investigators have not issued a formal conclusion.
  • How Yegaram, Welcome Savings Bank and Hyundai Capital were breached has not been disclosed.
  • Reported totals range from about 66,000 to 67,500 depending on whether agents and contractors are counted.
  • The attackers' identity and nationality are unknown; a Chinese-language tool does not establish nationality.
Authoring
Reviewed by a person before publication. The full process is described in the Editorial.

Ten stories, once each morning

We send the three-line summaries only; the full pieces stay on the site. One-click unsubscribe, any time.

Related