South Korea's Financial Services Commission held an emergency meeting following a series of cyberattacks targeting financial institutions in the country. During the meeting, officials confirmed a data breach at Shinhan Bank and said other cybersecurity incidents affected other South Korean banks, including Kookmin Bank.
Shinhan Bank and KB Kookmin Bank are large private South Korean commercial banks, each holding more than $400 billion in assets. Authorities said they launched on-site investigations after receiving incident reports and shared all actionable information with relevant agencies, including KISA, which is Korea's data protection agency.
Authorities also pledged to oversee consumer protection and compensation, and analyze the incidents to identify necessary regulatory improvements. Yesterday, local media outlets reported that South Korea's President Lee ordered a thorough investigation into personal data leaks at financial and public institutions.
Read nextCohere Launches North 2 Platform with Updated ControlsHana Bank suffered a limited-scope breach
At the same time, Hana Bank was also found to have suffered a limited-scope breach after its sales-support system was compromised. According to the same reports, Shinhan Bank leaked the details of 25,000 customers, while Kookmin Bank leaked credit card information of 119,000 clients.
While official channels provided no details about the perpetrators, Korean news agency Yonhap reported that a server used in the attacks had an HTML page title containing a Chinese-language string associated with ARTEX AI. ARTEX AI is an open-source penetration-testing system that uses agents to automate information gathering, vulnerability discovery, attack-path planning, security-tool execution, and vulnerability verification.

Security experts suspect AI automation tools
The bank and financial authorities have not confirmed its use in the Shinhan breach, and the Chinese-language string doesn't link the attacks to any particular threat actor. However, Moon Jong-hyun, the head of the Genian Security Center, posted on LinkedIn that several threat analysts believe that the breaches involved AI-based attack automation tools.
Financial authorities are continuing their analysis of the incidents to determine the full scope of the compromises and identify necessary regulatory improvements.



