# South Korean bank data breaches

> Live situation record from CLSTR: https://clstr.news/situations/south-korean-bank-data-breaches
> Updated: 2026-10-02T02:04:14.000Z. Sources: 14. Developments: 2.

The cyberattack against Shinhan Bank has been further linked to traces of a Chinese-language, AI-based autonomous penetration testing tool identified as ‘ARTEX-自主渗透試控制台’ (AI Autonomous Penetration Test Console). The tool, an open-source system based on Large Language Models, was detected via Chinese strings in the HTML title of a suspected web server. While official confirmation of its use in the breach is pending, analysts suggest the attack may have employed ‘credential stuffing’ to bypass identity verification procedures in Shinhan’s loan solicitor service.

The scope of the security incidents has expanded, revealing a series of coordinated attacks targeting multiple South Korean financial institutions. Beyond Shinhan Bank’s leak of data for approximately 25,000 customers, additional breaches have been confirmed at KB Kookmin Bank (roughly 119 customers), Hana Bank (89 victims), and BNK Busan Bank (11 outsourced employees). 

Experts note that attackers appear to be targeting secondary channels—such as loan recruitment services, employee mobile support systems, and sales support platforms—which may possess less stringent authentication protocols than core banking systems. In response, the Financial Services Commission has convened emergency meetings and ordered comprehensive security audits of all externally exposed IT assets. The National Police Agency has also launched an investigation into the incidents. Both Shinhan and KB Kookmin Bank have pledged to provide full compensation to customers if actual damages are confirmed.

## Claims

- Shinhan Bank confirmed that personal information for about 25,000 customers was leaked. (corroborated by 8 sources)
- KB Kookmin Bank confirmed a leak of approximately 100 to 119 customers' information via external intrusion. (corroborated by 6 sources)
- The Financial Services Commission held an emergency response meeting to address the series of banking sector data breaches. (corroborated by 3 sources)
- Shinhan Bank and KB Kookmin Bank have pledged to provide full compensation to customers if actual damages are confirmed. (corroborated by 3 sources)
- Security experts suggest the attacks may have utilized AI-based automated tools like ARTEX AI. (corroborated by 2 sources)
- Hana Bank confirmed the leak of information belonging to 89 customers. (single source)
- BNK Busan Bank confirmed the leak of personal information for 11 outsourced employees. (single source)
- The National Police Agency's Cyber Terror Response Investigation Unit has launched an investigation into the hacking incidents. (single source)

## Timeline

### 2026-10-02: South Korean banks hit by series of hacking attacks and data breaches

Multiple South Korean banks, including Shinhan and KB Kookmin, suffered hacking attacks that leaked customer data. Authorities suspect the use of AI-driven tools and have ordered emergency security audits.

12 sources. https://clstr.news/cluster/shinhan-and-kb-kookmin-bank-report-major-customer-data-breaches

### 2026-10-02: Shinhan Bank cyberattack linked to Chinese AI penetration tool

Traces of a Chinese-language AI penetration tool, ‘ARTEX AI’, were found on a server linked to a cyberattack on Shinhan Bank, raising concerns over automated credential stuffing attacks.

5 sources. https://clstr.news/cluster/shinhan-bank-cyberattack-linked-to-chinese-ai-penetration-tool

---
Cite as: South Korean bank data breaches. CLSTR, https://clstr.news/situations/south-korean-bank-data-breaches
