Skip to content
RegionAsia-Pacific

MediumII Cyber Warfare & Critical Infrastructure2 October 2026, Friday

Successive breaches expose customer data at four Korean banks

After income and loan data for around 25,000 Shinhan Bank customers was exposed, KB Kookmin and Hana Bank also reported breaches on 2 October. Attempts against Woori and NH NongHyup caused no data loss. The Financial Services Commission held an emergency meeting.

Location: SEOUL

According to the Korea Times, an outside actor at Shinhan bypassed authentication in a service used by loan brokers. The names, phone numbers, annual incomes and credit limits of around 25,000 customers were exposed; 66 records also contained ID numbers. The bank confirmed the breach on 30 September and apologised on 1 October. At KB Kookmin, data for 119 customers leaked from employees' mobile work system, and at Hana data for 89 customers leaked from a sales-support system. At BNK, 11 subcontracted staff were affected.

Two channels stand out in the method of attack. For Shinhan, experts point to credential stuffing, the mass testing of passwords stolen in other breaches. The Korea Times reported that the Chinese phrase 'AI autonomous penetration testing console' was found on a server. According to Insurance Journal, Yonhap also reported suspicions that AI agents were used to search for vulnerabilities. As of 2 October, this claim could not be officially verified.

The Commission and the Financial Supervisory Service sent inspectors to the banks immediately after the breach notifications. The attackers' IP addresses and methods were shared with the relevant institutions. Korea JoongAng Daily puts the number of affected customers at KB Kookmin at around 100, while the Korea Times and Insurance Journal use the figure of 119.

The incident also puts Korea's cyber insurance floor in the spotlight. According to Insurance Business, data breach insurance is the country's only mandatory cyber policy, with minimum cover of 1 billion won. The same source says the 624.7 billion won fine imposed on Coupang in June 2026 is more than 600 times that floor.

Talay assessment

Bottom line

Data leaking from 4 banks in 3 days shows the attack came not from a single software flaw but from banks' externally exposed side systems and reused passwords. The number of affected customers is only slightly above 25,000, yet income and credit-limit data is valuable for fraud. The most likely path is that inspections uncover new breaches and authentication rules are tightened.

Likely effects

  • Korean bankingNegativeWeeks

    Because all externally exposed IT assets must now be scanned, new breach notifications may follow after 2 October, and compliance costs will rise.

  • Cyber insuranceNegative1–6 months

    The floor for Korea's mandatory data breach insurance is 1 billion won. A wave of compensation claims from 25,000 people exposes how inadequate that floor is.

  • Regional financial sectorNegative1–6 months

    If the claim of an AI-assisted automated attack is confirmed, banks in Japan and Taiwan will also have to tighten their authentication rules.

Possibilities, ranked

  1. 1
    Inspections find new cases55%

    Self-assessments and on-site inspections uncover small-scale breaches at other banks or card companies as well.

    Watch: A new FSC/FSS statement naming additional institutions

  2. 2
    Wave stays at 4 banks35%

    Blocked IPs and new password rules stop the attack, and no new notifications arrive during October.

    Watch: No new bank breach notification for 30 days

  3. 3
    Large-scale second breach10%

    The same method exposes data on more than 100,000 customers, and the regulator moves towards heavy penalties.

    Watch: A breach notification covering more than 100,000 customers at once

Probabilities are calibrated judgement based on the sources, not measurement, and are revised as new information arrives. Not investment advice.

Market reaction

Indicators affected

  • Affected at Shinhan▼ ≈25,000
  • Banks with data leaked▼ 4
  • Failed attempts▲ 2 banks

Sources

  1. The Korea Times — Shinhan, Kookmin, Hana data breaches fuel concerns over AI-powered cyberattacks
  2. The Korea Times — Shinhan Bank hit by data breach affecting 25,000 customers
  3. Korea JoongAng Daily — KB Kookmin becomes latest bank to be hit by cyberattack
  4. Insurance Journal — AI tools suspected in Korea's Shinhan Bank hack, Yonhap reports
  5. Insurance Business — Coupang's record fine dwarfs Korea's cyber insurance floor