Skip to content
RegionAsia-Pacific

MediumII Cyber Warfare & Critical Infrastructure5 October 2026, Monday

Korean breach spreads to seven lenders, traces point to an AI tool

Data breaches that began at South Korean banks in early October had reached 7 financial institutions and about 68,000 customers as of 5 October. The Financial Services Commission suspects a single attacker may have used an open-source AI penetration testing tool.

Location: SEOUL

According to The Korea Herald on 5 October, the largest losses were at Yegaram Savings Bank, with about 40,000 people affected, and Shinhan Bank, with about 25,000. Welcome Savings Bank lost 2,200 records, Hyundai Capital 146, KB Kookmin 153 and Hana Bank 89. At BNK Busan Bank, data on 11 subcontractor employees was exposed. Woori and NH NongHyup stopped attacks without losing data. A figure of 119 had earlier been given for KB Kookmin; the discrepancy between sources has not been resolved.

The attackers went not for core banking systems but for less closely monitored external websites and sales support servers used by loan brokers and staff. A Yonhap report cited by Insurance Journal says traces of ARTEX, an open-source autonomous penetration testing system, were found on IP addresses used in the attack. The system is built on large language models. Officials say the perpetrator's identity is unclear because the tool is publicly available and the IP addresses are spread across several countries.

After an emergency meeting, Financial Services Commission Chairman Lee Eog-weon ordered all institutions to complete internal security audits quickly and report the results. According to The Korea Herald, they were told to finish by Thursday and shut down non-essential external access. BleepingComputer reports that President Lee Jae-myung also ordered a comprehensive investigation into personal data leaks at financial and public institutions.

The constraint shows up in budgets. According to The Korea Herald, Shinhan's security budget of 40.59 billion won is the lowest among the major banks, against 86.07 billion won at KB Kookmin. As AI-assisted tools cut the cost of attacks, poorly protected peripheral systems become the cheapest way into a bank.

Talay assessment

Bottom line

The spread of the breach from 4 banks to 7 institutions shows the attacker advanced by scanning weakly protected peripheral systems rather than core platforms. Traces of an open-source AI penetration tool suggest such scanning can be done cheaply and quickly, and the perpetrator remains unknown. The most likely direction is that the audits uncover further breaches and the regulator imposes lasting restrictions on external access.

Likely effects

  • Trust in Korean bankingNegativeWeeks

    Exposure of identity and contact data on about 68,000 customers raises the risk of phishing and identity fraud and could increase banks' compensation costs.

  • Regulation and costUncertain1–6 months

    The commission's order to shut external access, and fines of up to 10% of annual revenue for major breaches, will force banks to raise security budgets.

  • A lesson for Turkish banksUncertain1–6 months

    The attack targeted broker and sales portals rather than core systems. In Türkiye too, peripheral systems opened to outside partners should be an audit priority.

Possibilities, ranked

  1. 1
    Audits uncover new breaches55%

    Audits completed by Thursday reveal access or leaks at one or more additional institutions, and the number of people affected grows.

    Watch: The Financial Services Commission's audit findings and new breach notifications

  2. 2
    Incident stays at current scale30%

    The audits find no new leaks and the debate shifts to budgets and penalty rules.

    Watch: No new Korean financial institution reporting a breach during October

  3. 3
    Official attribution15%

    The investigation links the attack to a specific group or state, and the incident takes on a diplomatic dimension.

    Watch: Korean police or cybersecurity authorities naming a perpetrator

Probabilities are calibrated judgement based on the sources, not measurement, and are revised as new information arrives. Not investment advice.

Market reaction

Indicators affected

  • Financial institutions breached▼ 7
  • Customers affected (total)▼ ≈68,000
  • People affected at Yegaram▼ ≈40,000

Sources

  1. The Korea Herald — Korean banks on high alert after wave of cyberattacks
  2. Insurance Journal — South Korea Orders Security Checks After Finance-Sector Data Leaks
  3. BleepingComputer — South Korea probes bank breaches amid suspected AI-powered attacks
  4. KED Global — Seoul sounds alarm as suspected AI-assisted hacks sweep across lenders