Seven South Korean financial companies have reported data breaches following a series of suspected AI-assisted cyberattacks, raising concerns among customers already affected by earlier leaks at telecom operators and online platforms.
Shinhan Bank, KB Kookmin Bank, Hana Bank, BNK Busan Bank, Yegaram Savings Bank, Welcome Savings Bank and Hyundai Capital have disclosed breaches, according to the financial industry.
Shinhan Bank said information belonging to about 25,700 customers was leaked, while Yegaram Savings Bank reported roughly 40,000 affected customers.
Some victims have formed online groups and are recruiting participants for class-action damages lawsuits. Customers are also sharing advice on preserving evidence, including screenshots of breach notifications and records of suspicious calls received after their information was exposed.
This incident is very concerning in that previously leaked personal information can be combined with financial information
Hwang Seong-ho, head of NordVPN’s Korea branch
The incidents follow several large data leaks in Korea, adding to concerns that information stolen from different companies could be combined. Financial records paired with previously exposed personal data would give attackers a more detailed profile of individual victims.
Police examine Artex AI connection
The National Police Agency’s Cyber Bureau is examining traces of Artex AI found at internet addresses used in attacks against the banks. Artex AI is a Chinese-language, open-source penetration-testing tool published on GitHub that uses AI to search systems for vulnerabilities.
Its availability to anyone means investigators cannot attribute the attacks to China based on the tool alone. Police also haven’t established whether Artex was the only software involved.
Authorities plan to seek international cooperation as they investigate overseas IP addresses used in the attacks. Identifying the people behind such incidents remains difficult when infrastructure and traffic are routed through multiple countries.
An earlier investigation into the April 2025 theft of USIM data from SK Telecom has traced more than 100 IP addresses and involved cooperation with 31 technology companies across 14 countries. Police have yet to identify a suspect.
Investigators did identify suspects in separate cases involving unauthorized mobile micropayments at KT and a personal data leak at Coupang. Those incidents differed from the external hacking under investigation in the financial sector, and police consider it unlikely the identified suspects will be taken into custody.
In data leak investigations, even when we manage to find traces of the crime, identifying a suspect is very difficult. Cross-border investigations also require authorities to consider possible diplomatic friction.
AI lowers barriers to cyberattacks
The attacks have renewed concern that AI tools are reducing the technical knowledge required to carry out cyberattacks. Software capable of automating password attempts and other attack methods is increasingly accessible to people without advanced security skills.
“There are cases where AI-based programs that plug in random passwords are openly traded on the market,” said a software developer at one of Korea’s five largest brokerages. “Even without the skills, anyone who pays can use attack tools.”
Some analysts have raised the possibility that an individual rather than an organized hacking group was responsible for the attacks. Investigators have not identified the perpetrators.
Security specialists said the use of AI should not distract from weaknesses in the affected companies’ defenses. Kim said the larger issue was whether vulnerabilities had been properly managed across financial institutions.
“Whether AI was used is not the point,” police said. “The problem is that vulnerabilities were not properly managed. Each company’s level of security needs to be examined across the board.”
Woori Bank and NH NongHyup Bank were also targeted during the hacking activity, although no damage has been confirmed at either institution.









