< Back to situations

Monitor this situation.

[SITUATION] · [ACTIVE] · [BUSINESS]

2 clusters · 14 sources · 1 days · First seen · Last updated

South Korean bank data breaches

Overview

The cyberattack against Shinhan Bank has been further linked to traces of a Chinese-language, AI-based autonomous penetration testing tool identified as ‘ARTEX-自主渗透試控制台’ (AI Autonomous Penetration Test Console). The tool, an open-source system based on Large Language Models, was detected via Chinese strings in the HTML title of a suspected web server. While official confirmation of its use in the breach is pending, analysts suggest the attack may have employed ‘credential stuffing’ to bypass identity verification procedures in Shinhan’s loan solicitor service.

The scope of the security incidents has expanded, revealing a series of coordinated attacks targeting multiple South Korean financial institutions. Beyond Shinhan Bank’s leak of data for approximately 25,000 customers, additional breaches have been confirmed at KB Kookmin Bank (roughly 119 customers), Hana Bank (89 victims), and BNK Busan Bank (11 outsourced employees).

Experts note that attackers appear to be targeting secondary channels—such as loan recruitment services, employee mobile support systems, and sales support platforms—which may possess less stringent authentication protocols than core banking systems. In response, the Financial Services Commission has convened emergency meetings and ordered comprehensive security audits of all externally exposed IT assets. The National Police Agency has also launched an investigation into the incidents. Both Shinhan and KB Kookmin Bank have pledged to provide full compensation to customers if actual damages are confirmed.

Entities

ARTEX AI · Shinhan Bank · Hana Bank · Financial Supervisory Service · KB Kookmin Bank

Claims

What the coverage asserts, and how many sources carry each claim.

Timeline

  1. [BUSINESS] 11 sources
    South Korean banks hit by series of hacking attacks and data breaches

    Multiple South Korean banks, including Shinhan and KB Kookmin, suffered hacking attacks that leaked customer data. Authorities suspect the use of AI-driven tools and have ordered emergency security audits.

  2. [TECHNOLOGY] 5 sources
    Shinhan Bank cyberattack linked to Chinese AI penetration tool

    Traces of a Chinese-language AI penetration tool, ‘ARTEX AI’, were found on a server linked to a cyberattack on Shinhan Bank, raising concerns over automated credential stuffing attacks.

Sources

biz.heraldcorp.com · chosunonline.com · dailymagazine.co.kr · english.hani.co.kr · hidomin.com · imaeil.com · ithome.com · joseilbo.com · kyeonggi.com · mbn.mk.co.kr · sateconomy.co.kr · seoul.co.kr · sisajournal.com · tfmedia.co.kr

This summary has been updated 1 time: see revision history